Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Security Plan Manager

Overview

Security Plan Manager (SPM) is a django app for automating tasks associated FedRAMP documentation. It was created with the idea that the system security plan (SSP) is the source of truth for most organizations and that most edits are done manually due to the cumbersome nature of FedRAMP's templates and word document automation in general.

Features

Currently the backend logic behind importing/exporting is the focus of development, so the UI is extremely lacking, although most everything is at least exposed in the UI. Features available today are:

  • Importing a FedRAMP SSP word document (strict formatting requirements below)
  • Exporting FedRAMP SSP word document
  • Exporting a Customer Implementation Summary (CIS) excel workbook
  • In UI editing of CIS details or implementation details

Setup

  1. Install Django and start a new project
  2. Run python manage.py migrate
  3. Clone this repo into the project folder
  4. Edit yourproject/settings.py:
    • Add the following to INSTALLED_APPS:
      • securityplanmanager.apps.SecurityPlanManagerConfig
      • django.contrib.humanize
    • You can also configure your database selection here
    • Do not commit this file to source control
    • Do not run in production with Debug on.
  5. Edit yourproject/urls.py:
    • Add the following import:
      • from django.urls import path, include
    • Add the following urlpatterns:
      • path('', include('securityplanmanager.urls'))
  6. Run python manage.py makemigrations securityplanmanager then python manage.py migrate
  7. Start the server with python manage.py runserver and make sure you can connect on localhost:8000, then shut the server down.
  8. Now run python manage.py populate_db to import controls, currently this imports all controls from the NIST's 800-53-controls.xml which includes withdrawn controls and controls not selected in any FedRAMP baseline. This also deletes all existing controls, it's meant for first time setup only and may take a few minutes.
  9. Add an SSP with the first half filled out, but with blank control implementations into static\fedramp_templates and rename it high.docx (right now everything is assumed to be for FedRAMP High, this will be configurable eventually). This is what will be used as a template when exporting an SSP.
  10. Now the server is set up and ready for an SSP to be imported.

SSP Import and Formatting Requirements

The goal of this project was to support uploading a word document to fill out SSP data into a database, which has a lot of upside, but some tradeoffs as well. One of the major downsides is that in order to reliably upload the level of detail needed, the SSP must be formatted pretty strictly. This includes typos in FedRAMP's own templates, which are very difficult to get them to resolve.

Define your teams

Teams should be defined in SPM before uploading an SSP. Team names should match how they are referred to in the SSP (see implementation table example below).

Control Summary Information table:

Parameters

For most controls, you can just include your parameter in the box and it will work fine. The major exception is when there are two parameters in one control. For example, AC-2 (2) has two parameters, so in the Control Summary Information parameter boxes they must say: Parameter AC-2 (2)-1: and Parameter AC-2 (2)-2: in order for parameters to be correctly imported.

For parameters like AC-1(a)(1), where the parameter is defined as AC-1(a), a good solution has not been implemented yet, so those parameters are not uploaded.

Implementation table:

The general flow of an implementation should look something like this example for AC-1:

alt text

Customer responsibilities are put at the top of the implementation box, but are captured for all subsequent control parts. So AC-1(a)(1) and AC-1(a)(2) will have the same customer responsibility in SPM.

For part a, all service teams operate in the same way, so they are all included together with a single implementation beneath. In SPM in the backend this is a single Implementation object tied to a control with a many-to-many relationship with team objects.

For part b, Team C does things differently so they are put on their own line under the Part 2: header. In SPM this will show up as AC-1(b)(1) and AC-1(b)(2) as having 2 Implementation objects tied to each control. One implementation will have a many-to-many relationship with Team A and Team B, the other with just Team C.

About

FedRAMP SSP Automation

Topics

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages