You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As a security practicioner using OSCAL-enabled tools or software developer that programs them, in order to be sure I give required information in accordance with government, GSA, and FedRAMP policies with sufficient clarity and the most minimal risk, I would like clear documentation as to whether FedRAMP's requirements around OSCAL for contact information and party for certain parties and roles in a Digital Authorization Package are PII or not.
Goals
Clarify how FedRAMP use of OSCAL requires, in some cases, collection information about persons, but it is not PII.
User Story
As a security practicioner using OSCAL-enabled tools or software developer that programs them, in order to be sure I give required information in accordance with government, GSA, and FedRAMP policies with sufficient clarity and the most minimal risk, I would like clear documentation as to whether FedRAMP's requirements around OSCAL for contact information and party for certain parties and roles in a Digital Authorization Package are PII or not.
Goals
Dependencies
N/A
Acceptance Criteria
Other information
No response
The text was updated successfully, but these errors were encountered: