Skip to content

Identification of Framework Satisfaction with cDefs #2

@brian-ruf

Description

@brian-ruf

Author Use Case: As a cloud service provider, I want to enable my customers to select cloud services based on preexisting framework validation assessments of those components.

Consumer Use Case: As a consumer of cloud services that needs to deploy a system in compliance with a specific framework, I want select cloud services that have already been audited/assessed and found to satisfy that framework.

Example: if a customer wants to only select/utilize cloud services that have been subject to - and passed - a SOC 2 Type 2 assessment, the CSP should be able to expose that fact within OSCAL content.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions