From 707954c24997627cf13fc5fdaa5fbf787f796850 Mon Sep 17 00:00:00 2001 From: Gabeblis Date: Wed, 5 Feb 2025 16:40:15 +0000 Subject: [PATCH] Revert "Update help url for allowed values (#1146)" This reverts commit bd8eacb4cbba0ac6c4c9819cd2bfc0e0fb68af64. --- .../fedramp-external-allowed-values.xml | 40 +++++-------------- 1 file changed, 11 insertions(+), 29 deletions(-) diff --git a/src/validations/constraints/fedramp-external-allowed-values.xml b/src/validations/constraints/fedramp-external-allowed-values.xml index 9c2b6f8c8..d10bcdd9b 100644 --- a/src/validations/constraints/fedramp-external-allowed-values.xml +++ b/src/validations/constraints/fedramp-external-allowed-values.xml @@ -18,7 +18,6 @@ Address Type The type of address for the party - Work @@ -29,7 +28,6 @@ Attachment Type Identifies the type of attachment. - Law or Statute Regulation or Directive Industry Standard @@ -72,7 +70,6 @@ Authorization Type The FedRAMP Authorization Type - FedRAMP JAB P-ATO FedRAMP Agency ATO FedRAMP Tailored for LI-SaaS @@ -81,7 +78,6 @@ Cloud Service Model The cloud service model used by the system. - Infrastructure as a Service Platform as a Service Software as a Service @@ -91,7 +87,6 @@ Component Type Identifies the component type. - A connection to something outside this system. Any software, operating system, or firmware. A physical device. @@ -113,7 +108,7 @@ Connection Security Identifies connection security value. - + Internet Protocol Security (IPSec) Internet Key Exchange (IKE) Version 1 Internet Protocol Security (IPSec) Internet Key Exchange (IKE) Version 2 Internet Protocol Security (IPSec) @@ -132,7 +127,6 @@ Control Implementation Status The implementation status of the control. - The control is fully implemented. The control is partially implemented. There is a plan for implementing the control as explained in the remarks. @@ -143,7 +137,6 @@ Deployment Model The cloud deployment model. - Public Cloud Private Cloud U.S. Government Only @@ -154,7 +147,7 @@ Nature of Agreement for External Systems Identifies nature of agreement for external systems. - + A contract between the CSP and the organization that owns the external system. An end-user license agreement between the CSP and the organization that owns the external system. An interconnection security agreement between the CSP and the organization that owns the external system. @@ -167,7 +160,6 @@ FedRAMP Version Identifies the FedRAMP version of the document. - FedRAMP Version @@ -175,7 +167,7 @@ Information Type The class of an information type property categorizes the direction of the data flow relative to the system described in the SSP. - + An incoming data flow to the system for this information type An outgoing data flow from the system for this information type @@ -183,7 +175,6 @@ NIST SP 800-60 Volume 2 Revision 1 Information Types Contains a list of all supported information types from NIST SP 800-60 Volume 2 Revision 1. - Controls and Oversight: Corrective Action Information Type as defined by NIST.SP.800-60v2r1 Controls and Oversight: Program Evaluation as defined by NIST.SP.800-60v2r1 @@ -527,14 +518,12 @@ Information Type Categorization System The system used for categorizing information types. - NIST SP 800-60 Volume 2 Revision 1 Interconnection Direction Identifies the direction of information flow for the interconnection. - Incoming Outgoing Bi-Directional @@ -543,7 +532,6 @@ Interconnection Security Identifies the type of security applied to the interconnection. - IPsec Virtual Private Network Transport-Layer Security @@ -556,7 +544,6 @@ Allows Authenticated Scan Indicates if the asset is capable of having an authenticated scan. - Yes No @@ -564,7 +551,6 @@ Public Indicates if the asset is exposed to the public Internet. - Yes No @@ -572,7 +558,6 @@ Virtual Indicates if the asset is virtual. - Yes No @@ -580,7 +565,7 @@ Nature of Agreement for Leveraged Authorizations Identifies nature of agreement for leveraged authorizations. - + A contract between the CSP and the organization that owns the leveraged system. An end-user license agreement between the CSP and the organization that owns the leveraged system. An application license agreement between the CSP and the organization that owns the leveraged system. @@ -592,14 +577,13 @@ FedRAMP Data Sensitivity Classification Identifies the FedRAMP data sensitivity classification of the document. - Controlled Unclassified Information Privilege Level The privilege level of the user. - + Read Read-Write Write @@ -609,7 +593,6 @@ Scan Type Identifies the type of scan. - Infrastructure and Operating System Scan Database Scan Web Scan @@ -619,7 +602,7 @@ User Authentication Identifies if user authentication is required. - + Yes No Not-Applicable @@ -633,7 +616,7 @@ Privilege Level The privilege level of the user. - + Read Read-Write Write @@ -643,7 +626,7 @@ User Sensitvity Level Sensitivity level of the user. - + High Risk Severe Moderate @@ -654,7 +637,7 @@ User Type The type of user. - + Internal External Privileged @@ -669,12 +652,11 @@ - Security Impact Level - The security objective level as defined by NIST SP 800-60. - + The security objective level as defined by NIST SP 800-60. + Low Moderate High