Generate and download Open Security Controls Assessment Language (OSCAL) JSON formatted System Security Plan (SSP) files containing authorization package data including controls, boundaries, and system implementation details
from the Authorization package overview record page. The authorization package must be in Implement state or later to generate OSCAL System Security Plan (SSP) files.
Before you begin
Role required: sn_irm_cont_auth.admin, sn_irm_cont_auth.system_owner, sn_irm_cont_auth.authorization_official, sn_irm_cont_auth.info_system_sec_manager, or sn_irm_cont_auth.info_system_sec_officer
Procedure
Navigate to Workspaces > CAM Workspace.
In the CAMWorkspace, select the List icon ().
Select Authorization packages from the RMF list.
From the list view, select the authorization package record for SSP generation.
Note:
The authorization package must be in the Implement, Assess, Authorize, or Monitor state to generate OSCAL SSP.
To export OSCAL SSP, select Generate OSCAL SSP from the Generate OSCAL drop-down.
A message appears indicating file generation is in progress. The system generates files containing JSON data and associated diagrams. Refresh the page before downloading the JSON files.
To download the SSP zip file, select the Download OSCAL SSP from the Download OSCAL drop-down list.
Important:
Verify that the pop-up blocker is disabled for the URL so that the SSP zip file is automatically downloaded to your local repository.
The downloaded zip file contains catalog.json, overlay-catalog.json, profile.json, ssp.json, and poam.json files. If diagrams attach to relevant fields or link to the package boundary, they appear in the zip file
contents. Available diagrams include dataflow diagrams, network architecture diagrams, authorization boundary diagrams, and enterprise architecture diagrams.
Note:
If no POA&M is linked to the Authorization Package, the poam.json file will not be generated.
The overlay-catalog.json file contains only the policies linked to the Authorization Package. If no catalog overlay is linked to the Authorization Package, the overlay-catalog.json file will not be generated.
Multiple overlay-catalog files will be generated one for each overlay.