From 47cfda6da7e616880c87010f1482d0a19fd364ea Mon Sep 17 00:00:00 2001 From: Rene Tshiteya Date: Thu, 23 Jan 2025 15:48:44 -0500 Subject: [PATCH] Update lisaas profile - replace aggregate params --- .../FedRAMP_rev5_LI-SaaS-baseline_profile.xml | 109 ++++++++++++++++-- 1 file changed, 97 insertions(+), 12 deletions(-) diff --git a/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml b/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml index b79438b8b..971e1b142 100644 --- a/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml +++ b/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml @@ -1,10 +1,10 @@ - + FedRAMP Rev 5 Tailored Low Impact Software as a Service (LI-SaaS) Baseline 2024-09-24T02:24:00Z - 2025-01-15T00:00:00Z + 2025-01-23T00:00:00Z fedramp-3.0.0rc1-oscal-1.1.2 1.1.2 @@ -304,7 +304,14 @@ - + + + +

at least annually

+
+
+
+

at least annually

@@ -366,8 +373,15 @@

successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. For Web applications: all administrator activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes

+
+ + + +

organization-defined subset of the auditable events defined in AU-2a to be audited continually for each identified event.

+
+
- +

organization-defined subset of the auditable events defined in AU-2a to be audited continually for each identified event.

@@ -472,7 +486,14 @@
- + + + +

to include JAB/AO

+
+
+
+

to include JAB/AO

@@ -593,7 +614,14 @@
- + + + +

classroom exercise/table top written tests

+
+
+
+

classroom exercise/table top written tests

@@ -720,7 +748,21 @@
- + + + +

see additional FedRAMP Requirements and Guidance

+
+
+
+ + + +

see additional FedRAMP Requirements and Guidance

+
+
+
+

see additional FedRAMP Requirements and Guidance

@@ -769,7 +811,21 @@
- + + + +

techniques and procedures IAW NIST SP 800-88 Section 4: Reuse and Disposal of Storage Media and Hardware

+
+
+
+ + + +

techniques and procedures IAW NIST SP 800-88 Section 4: Reuse and Disposal of Storage Media and Hardware

+
+
+
+

techniques and procedures IAW NIST SP 800-88 Section 4: Reuse and Disposal of Storage Media and Hardware

@@ -825,7 +881,14 @@
- + + + +

at least annually

+
+
+
+

at least annually

@@ -867,7 +930,14 @@
- + + + +

all information system components

+
+
+
+

all information system components

@@ -951,7 +1021,15 @@
- + + + +

for national security clearances; a reinvestigation is required during the fifth (5th) year for top secret security clearance, the tenth (10th) year for secret security clearance, and fifteenth (15th) year for confidential security clearance.

+

For moderate risk law enforcement and high impact public trust level, a reinvestigation is required during the fifth (5th) year. There is no reinvestigation for other moderate risk positions or any low risk positions

+
+
+
+

for national security clearances; a reinvestigation is required during the fifth (5th) year for top secret security clearance, the tenth (10th) year for secret security clearance, and fifteenth (15th) year for confidential security clearance.

@@ -1057,7 +1135,14 @@
- + + + +

monthly operating system/infrastructure; monthly web applications (including APIs) and databases

+
+
+
+

monthly operating system/infrastructure; monthly web applications (including APIs) and databases