Date: 2023-02-27
Accepted
Compliance documentation is an essential component of working in the open while providing clear and obvious evidence of security considerations, concerns, and mitigations.
The prior decision to use OSCAL with Trestle isn’t practical given personnel considerations.
We will use spreadsheets and other documentation to track the compliance work.
We will continue to generate diagrams with PlantUML.
- Lack of familiarity of team personnel with OSCAL/Trestle.
- Reduction of technical maintenance—existing code in
compliance
was generatingdependabot
issues. - Concerns that OSCAL/Trestle does not fully match GSA’s ATO processes.
- ATO documentation will need to be tracked using documents/spreadsheets, requiring manual coordination.
- We will remove the
/compliance
directory frommain
.
Was previously ADR 0016; renamed/renumbered when PDRs and ADRs were merged.