SecBaseline
About
render

OSCAL → human-readable

Deterministic transformation of OSCAL into a view an auditor can read. No AI in this path.

OSCAL source

system-security-plan · paste or upload json / xml / yaml

system-security-plan

Rendered view

deterministic transformation

no AI
System Security Plan

Acme Federal System — System Security Plan

oscal 1.1.2 · uuid 11111111-2222-3333-4444-555555555555

System Characteristics

system-name
Acme Federal System
sensitivity
moderate
status
operational
system-id
ACME-FED-001

Multi-tenant SaaS providing case-management workflows to federal agencies.

Authorization boundary

All Acme-managed components in AWS GovCloud (us-gov-west-1).

Components (2)

Acme API Gatewaysoftware
c-1

Edge API gateway terminating TLS and enforcing authn/authz.

AWS RDS (PostgreSQL)service
c-2

Encrypted-at-rest managed PostgreSQL instance for case data.

Implemented Requirements (1)

ac-2ir-ac-2
ac-2_smt.a
component c-1

Account types (privileged, service, end-user) are defined in the IAM policy and enforced at the API gateway.