FedRAMP OSCAL SAR
The following guidelines describe how to apply the OSCAL models, along with some FedRAMP-specific data requirements and extensions, to express a FedRAMP Security Assessment Results (SAR) in OSCAL. This includes:
- An overview of using the OSCAL SAR model to represent a FedRAMP SAR.
- Guidance on representing FedRAMP SAR template information in OSCAL.
- Using the OSCAL SAR for generating other content artifacts.
FedRAMP extensions and allowed values are cited in relevant portions of this documentation.