-
Notifications
You must be signed in to change notification settings - Fork 106
Expand file tree
/
Copy pathssp_example.json
More file actions
257 lines (257 loc) · 11.1 KB
/
Copy pathssp_example.json
File metadata and controls
257 lines (257 loc) · 11.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
{
"system-security-plan": {
"uuid": "d197545f-353f-407b-9166-ebf959774c5a",
"metadata": {
"title": "CSP IaaS System Security Plan",
"last-modified": "2021-06-08T13:57:35.068496-04:00",
"version": "0.1",
"oscal-version": "1.0.0",
"roles": [
{
"id": "admin",
"title": "Administrator"
},
{
"id": "customer",
"title": "External Customer"
},
{
"id": "poc-for-customers",
"title": "Internal POC for Customers"
}
],
"parties": [
{
"uuid": "11111111-0000-4000-9000-100000000001",
"type": "person"
}
]
},
"import-profile": {
"href": "../../../nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_LOW-baseline_profile.json"
},
"system-characteristics": {
"system-ids": [
{
"id": "csp_iaas_system"
}
],
"system-name": "Leveraged IaaS System",
"description": "An example of three customers leveraging an authorized SaaS, which is running on an authorized IaaS.\n\n```\n\nCust-A Cust-B Cust-C\n | | |\n +---------+---------+\n |\n +-------------------+\n | Leveraging SaaS |\n +-------------------+\n |\n |\n +-------------------+\n | Leveraged IaaS |\n | this file |\n +-------------------+\n \n```\n\nIn this example, the IaaS SSP specifies customer responsibilities for certain controls.\n\nThe SaaS must address these for the control to be fully satisfied.\n\nThe SaaS provider may either implement these directly or pass the responsibility on to their customers. Both may be necessary.\n\nFor any given control, the Leveraged IaaS SSP must describe:\n\n1. HOW the IaaS is directly satisfying the control\n1. WHAT responsibilities are left for the Leveraging SaaS (or their customers) to implement.\n\n\nFor any given control, the Leveraging SaaS SSP must describe:\n\n1. WHAT is being inherited from the underlying IaaS\n1. HOW the SaaS is directly satisfying the control.\n1. WHAT responsibilities are left for the SaaS customers to implement. (The SaaS customers are Cust-A, B and C)\n",
"security-sensitivity-level": "low",
"system-information": {
"information-types": [
{
"title": "System and Network Monitoring",
"description": "This IaaS system handles information pertaining to audit events.",
"categorizations": [
{
"system": "https://doi.org/10.6028/NIST.SP.800-60v2r1",
"information-type-ids": [
"C.3.5.8"
]
}
],
"confidentiality-impact": {
"base": "fips-199-moderate",
"selected": "fips-199-low",
"adjustment-justification": "This impact has been adjusted to low as an example of how to perform this type of adjustment."
},
"integrity-impact": {
"base": "fips-199-moderate",
"selected": "fips-199-low",
"adjustment-justification": "This impact has been adjusted to low as an example of how to perform this type of adjustment."
},
"availability-impact": {
"base": "fips-199-moderate",
"selected": "fips-199-low",
"adjustment-justification": "This impact has been adjusted to low as an example of how to perform this type of adjustment."
}
}
]
},
"security-impact-level": {
"security-objective-confidentiality": "fips-199-low",
"security-objective-integrity": "fips-199-low",
"security-objective-availability": "fips-199-low"
},
"status": {
"state": "operational"
},
"authorization-boundary": {
"description": "The hardware and software supporting the virtualized infrastructure supporting the IaaS."
},
"remarks": "Most system-characteristics content does not support the example, and is included to meet the minimum SSP syntax requirements."
},
"system-implementation": {
"users": [
{
"uuid": "11111111-0000-4000-9000-200000000001",
"role-ids": [
"admin"
],
"authorized-privileges": [
{
"title": "Administrator",
"functions-performed": [
"Manages the components within the IaaS."
]
}
]
}
],
"components": [
{
"uuid": "cfbc1d9d-e772-47a4-aed5-1b902339eab2",
"type": "this-system",
"title": "This System",
"description": "The system described by this SSP.\n\nThis text was auto-generated by the OSCAL M3-RC1 data upgrade converter.",
"status": {
"state": "operational"
}
},
{
"uuid": "11111111-0000-4000-9001-000000000001",
"type": "this-system",
"title": "This System",
"description": "This Leveraged IaaS.\n\nThe entire system as depicted in the system authorization boundary",
"status": {
"state": "operational"
}
},
{
"uuid": "11111111-0000-4000-9001-000000000002",
"type": "software",
"title": "Application",
"description": "An application within the IaaS, exposed to SaaS customers and their downstream customers.\n\nThis Leveraged IaaS maintains aspects of the application.\n\nThe Leveraging SaaS maintains aspects of their assigned portion of the application.\n\nThe customers of the Leveraging SaaS maintain aspects of their sub-assigned portions of the application.",
"props": [
{
"name": "implementation-point",
"value": "system"
}
],
"status": {
"state": "operational"
},
"responsible-roles": [
{
"role-id": "admin",
"party-uuids": [
"11111111-0000-4000-9000-100000000001"
]
},
{
"role-id": "customer",
"party-uuids": [
"11111111-0000-4000-9000-100000000001"
]
}
]
}
]
},
"control-implementation": {
"description": "This is a collection of control responses.",
"implemented-requirements": [
{
"uuid": "11111111-0000-4000-9009-002000000000",
"control-id": "ac-2",
"set-parameters": [
{
"param-id": "ac-2_prm_1",
"values": [
"privileged and non-privileged"
]
}
],
"responsible-roles": [
{
"role-id": "admin",
"party-uuids": [
"11111111-0000-4000-9000-100000000001"
]
},
{
"role-id": "customer",
"party-uuids": [
"11111111-0000-4000-9000-100000000001"
]
}
],
"statements": [
{
"statement-id": "ac-2_stmt.a",
"uuid": "11111111-0000-4000-9009-002001000000",
"by-components": [
{
"component-uuid": "11111111-0000-4000-9001-000000000001",
"uuid": "11111111-0000-4000-9009-002001001000",
"description": "Response for the \\\"This System\\\" component.\n\nOverall description of how \\\"This System\\\" satisfies AC-2, Part a.\n\nResponse for the \\\"This System\\\" component.\n\nOverall description of how \\\"This System\\\" satisfies AC-2, Part a.\n\nResponse for the \\\"This System\\\" component.\n\nOverall description of how \\\"This System\\\" satisfies AC-2, Part a.\n\nResponse for the \\\"This System\\\" component.\n\nOverall description of how \\\"This System\\\" satisfies AC-2, Part a.",
"export": {
"description": "Optional description about what is being exported.",
"responsibilities": [
{
"uuid": "11111111-0000-4000-9009-002001001001",
"description": "Leveraging system's responsibilities with respect to inheriting this capability.\n\nIn the context of the application component in satisfaction of AC-2, part a.",
"responsible-roles": [
{
"role-id": "customer"
}
]
}
]
}
},
{
"component-uuid": "11111111-0000-4000-9001-000000000002",
"uuid": "11111111-0000-4000-9009-002001002000",
"description": "Describes how the application satisfies AC-2, Part a.",
"export": {
"description": "Optional description about what is being exported.",
"provided": [
{
"uuid": "11111111-0000-4000-9009-002001002001",
"description": "Consumer-appropriate description of what may be inherited.\n\nIn the context of the application component in satisfaction of AC-2, part a.",
"responsible-roles": [
{
"role-id": "poc-for-customers"
}
]
}
],
"responsibilities": [
{
"uuid": "11111111-0000-4000-9009-002001002002",
"provided-uuid": "11111111-0000-4000-9009-002001002001",
"description": "Leveraging system's responsibilities with respect to inheriting this capability.\n\nIn the context of the application component in satisfaction of AC-2, part a.",
"responsible-roles": [
{
"role-id": "customer"
}
]
}
]
}
}
],
"remarks": "a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: privileged and non-privileged];"
}
],
"remarks": "The organization:\n\na. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: organization-defined information system account types];\n\nb. Assigns account managers for information system accounts;\n\nc. Establishes conditions for group and role membership;\n\nd. through j. omitted"
}
]
},
"back-matter": {
"resources": [
{
"uuid": "11111111-0000-4000-9999-000000000001",
"rlinks": [
{
"href": "./attachments/IaaS_ac_proc.docx"
}
]
}
]
}
}
}