This document will be frequently updated. This update was produced {format-dateTime($UTC-datetime, '[F] [MNn] [D1] [Y] at
56 | [H01]:[m01]:[s01]Z')}. The transform used to produce the report was {static-base-uri() ! tokenize(.,
57 | '/')[last()]}
.
The version of the ARS OSCAL catalog used is {//metadata/version}.
60 |The version of the {$ODP-low//metadata/title} used is {$ODP-low//metadata/version}.
61 |The version of the {$ODP-moderate//metadata/title} used is {$ODP-moderate//metadata/version}.
62 |The version of the {$ODP-high//metadata/title} used is {$ODP-high//metadata/version}.
63 |The version of the {$ODP-hva//metadata/title} used is {$ODP-hva//metadata/version}.
64 | 65 |Revised
The following table shows ODP values for Low {$BL}, Moderate {$BM}, High {$BH}, and HVA {$BV} baselines.
84 | 85 |ODPs with missing values appear as ❓.
86 | 87 |Control details are here.
88 | 89 |NIST SP 800-53rev5 OSCAL Catalog Origin | 106 |Defined Baseline Values | 107 |||||||
---|---|---|---|---|---|---|---|
Control Label |
110 | Baselines | 111 |ODP ID | 112 |ODP "Label" | 113 |Low | 114 |Moderate | 115 |High | 116 |HVA | 117 |
134 | {$control/prop[@name eq 'label'][not(@class)]/@value} 135 | | 136 |
137 |
138 |
143 | |
144 | 145 | {@id} 146 | | 147 |
148 | |
150 |
151 |
156 | |
172 |
173 | |||
180 | {@id} 181 | | 182 |
183 | |
185 |
186 |
191 | |
207 |
208 |
209 |
The following table shows ARS OSCAL catalog controls which appear in baselines (there are {count(//control[@id = $ODP-hva//with-id])} 229 | controls and control enhancements).
230 | 231 |The Low {$BL}, Moderate {$BM}, High {$BH}, and HVA {$BV} baselines have {count(//control[@id = $ODP-low//with-id])}, {count(//control[@id = 232 | $ODP-moderate//with-id])}, {count(//control[@id = $ODP-high//with-id])}, and {count(//control[@id = $ODP-hva//with-id])} controls 233 | respectively.
234 | 235 |The ⬇ symbol appears when ODPs lack definition or vary by baseline. Click on the ODP too see the baseline values.
236 | 237 |A single value is displayed when all baseline values are 238 | identical.
239 | 240 |➤ denotes a top-level control statement (element) - one for which an individual control implementation response is required. The Low 241 | {$BL}, Moderate {$BM}, High {$BH}, and HVA {$BV} baselines have {count(//control[@id = $ODP-low//with-id]/part[@name eq 242 | 'statement']//prop[@class eq 'ARS' and @name eq 'label'])}, {count(//control[@id = $ODP-moderate//with-id]/part[@name eq 243 | 'statement']//prop[@class eq 'ARS' and @name eq 'label'])}, {count(//control[@id = $ODP-high//with-id]/part[@name eq 244 | 'statement']//prop[@class eq 'ARS' and @name eq 'label'])}, and {count(//control[@id = $ODP-hva//with-id]/part[@name eq 245 | 'statement']//prop[@class eq 'ARS' and @name eq 'label'])} elements respectively.
246 | 247 |Control | 260 |NIST 800-53 Statements | 261 |
---|---|
275 |
276 |
278 |
279 |
284 | |
285 |
286 |
287 |
288 |
289 |
295 |
296 |
297 |
301 |
302 | |
303 |
304 |
This document was produced {format-dateTime($UTC-datetime, '[F] [MNn] [D1] [Y] at [H01]:[m01]:[s01]Z')}.
55 |The transform used to produce the report was {static-base-uri() ! tokenize(., '/')[last()]}
.
Input to the transform was {base-uri()}
.
This is a comparison of control and control enhancement titles found in
72 |The OSCAL control enhancement titles are synthesized to match those found in the spreadsheets.
82 |Control | 86 |Various 800-53 Titles | 87 |||||||
---|---|---|---|---|---|---|---|
{prop[@name eq 'label' and not(@class)]/@value} | 111 |
112 |
|
132 |
The following table shows ARS controls in "spreadsheet" fashion. Row numbers correspond to those in the ARS 5.01 xlsx document.
143 |Control titles which do not match those in NIST SP 800-53 rev5 OSCAL catalog are highlighted thus.
144 |There is no need to apply manual corrections to the ARS 5.01 spreadsheet! Such errors will be removed during ARS OSCAL 145 | content generation.
146 |NB: There are some NIST OSCAL catalog which are patently incorrect. SR-2(1) is an example. These errors have been reported 147 | here.
148 |ARS Control | 159 |NIST | 160 ||||
---|---|---|---|---|
Row | 163 |Family | 164 |Number | 165 |Name | 166 |Title | 167 |
{2 + position()} | 175 |{Control_Family} | 176 |{Control_Number} | 177 |
178 | {Control_Name}
182 |
185 | {Control_Name}
186 |
199 | |
202 | {$nc/*:title} | 203 |
Control title mismatches are highlighted thus.
211 |800-53 Control ID |
215 | Title | 216 |ARS Control ID |
217 | Responsibility | 218 |Statement IDs |
219 |
223 |
---|---|---|---|---|
{@id} | 231 |
232 | {title}
233 |
236 | ARS mismatch «
237 | {$ars-xref/*:Control_Name}
238 | »
239 |
251 | |
254 |
255 | |
262 |
263 | {.}
271 | |
278 |
279 | {@id}
286 | |
290 |
Control ID |
304 | 800-53 Label |
305 | 800-53A Label |
306 | Title | 307 |Baselines | 308 |
---|