diff --git a/resources/validations/src/ssp.sch b/resources/validations/src/ssp.sch index 19df31458..f34a6b10e 100644 --- a/resources/validations/src/ssp.sch +++ b/resources/validations/src/ssp.sch @@ -230,7 +230,7 @@ [Section C Check 3] This SSP has not implemented the most important core: [Section C Check 2] This SSP has not implemented overall: [Section C Check 2] This SSP has implemented extraneous not needed given the selected profile: - + @@ -240,7 +240,7 @@ - + diff --git a/resources/validations/test/ssp.xspec b/resources/validations/test/ssp.xspec index 7e865cc02..a0fb68e94 100644 --- a/resources/validations/test/ssp.xspec +++ b/resources/validations/test/ssp.xspec @@ -65,9 +65,9 @@ - + - + @@ -82,9 +82,9 @@ - + - + @@ -101,9 +101,9 @@ 2020-11-27Z - + - + @@ -210,7 +210,7 @@ - + @@ -249,7 +249,7 @@ - + @@ -442,190 +442,190 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -646,9 +646,9 @@ - + - + @@ -668,9 +668,9 @@ - + - + diff --git a/resources/xml/FedRAMP_extensions.xml b/resources/xml/FedRAMP_extensions.xml index 4f65a4814..867dcaefd 100644 --- a/resources/xml/FedRAMP_extensions.xml +++ b/resources/xml/FedRAMP_extensions.xml @@ -384,7 +384,7 @@ connection-security Connection Security Identifies the mechanisms/protocol(s) used to secure the communication. - + @@ -603,11 +603,11 @@ implementation-status Control Implementation Status Indicates the implementation status of the control. - + -

When an annotation is defined as an extension, a separate constraint assembly is needed to specify datatype and allowed values on the @value flag.

+

When a prop is defined as an extension, a separate constraint assembly is needed to specify datatype and allowed values on the @value flag.

@@ -630,11 +630,11 @@ control-origination Control Origination The point(s) from which the control satisfaction originates. - + -

When an annotation is defined as an extension, a separate constraint assembly is needed to specify datatype and allowed values on the @value flag.

+

When a prop is defined as an extension, a separate constraint assembly is needed to specify datatype and allowed values on the @value flag.

@@ -934,7 +934,7 @@ Control Origination The point(s) from which the control satisfaction originates. - + Service Provider (Corporate) @@ -948,7 +948,7 @@ Control Implementation Status Constraints Defines the data type and allowed values for the Control Implementation Status - + The assessor finds sufficient evidence to agree the control objective is fully implemented. @@ -958,7 +958,7 @@ The assessor finds this control objective does not apply to this system. -

When an extension is an annotation, the data type and allowed values must be defined in a separate constraint.

+

When an extension is a prop, the data type and allowed values must be defined in a separate constraint.

@@ -967,7 +967,7 @@ Remarks are required for certain Control Implementation Status values. - +
@@ -984,13 +984,13 @@ Planned Implementation Date Exists If the control implementation status is "Planned" a "Planned Implementation Date" must be provided. 3.1 - + -

In the SSP, if implemented-requirement includes annotation[@name='implementation-status'] with value='planned', a planned-completion-date extension must be provided.

+

In the SSP, if implemented-requirement includes prop[@name='implementation-status'] with value='planned', a planned-completion-date extension must be provided.

@@ -1133,7 +1133,7 @@ Service Model The cloud service model. - + Software as a Service Platform as a Service @@ -1145,7 +1145,7 @@ Deployment Model The cloud deployment model. - + Public Cloud Private Cloud @@ -1168,4 +1168,4 @@ - \ No newline at end of file + diff --git a/resources/xml/fedramp_values.xml b/resources/xml/fedramp_values.xml index 3479af871..59d96180d 100644 --- a/resources/xml/fedramp_values.xml +++ b/resources/xml/fedramp_values.xml @@ -113,7 +113,7 @@ Service Model The cloud service model. - + Software as a Service Platform as a Service @@ -125,7 +125,7 @@ Deployment Model The cloud deployment model. - + Public Cloud Private Cloud @@ -289,7 +289,7 @@ User Type Identifies the user type. - + Internal External @@ -300,7 +300,7 @@ User Privilege Identifies the privilege level of the user. - + Privileged Non-Privileged @@ -335,7 +335,7 @@ Interconnection Security Identifies the type of security applied to the interconnection. - + IPsec Virtual Private Network @@ -434,31 +434,31 @@ Allows Authenticated Scan Indicates if the asset is capable of having an authenticated scan. - - + + Yes No - if the value is "no", the annotation remarks must contain the reason why. + if the value is "no", the prop remarks must contain the reason why. Is Scanned Indicates if the asset is scan. - - + + Yes No - if the value is "no", the annotation remarks must contain the reason why. + if the value is "no", the prop remarks must contain the reason why. Control Implementation Status The implementation status of the control. - + Implemented Partially Implemented @@ -471,7 +471,7 @@ Control Origination The point(s) from which the control satisfaction originates. - + Service Provider (Corporate) Service Provider (System Specific)