Skip to content

added force definitions - #29

Merged
pete-gov merged 1 commit into
mainfrom
pwx-09132
Sep 13, 2026
Merged

pete-gov merged 1 commit into
mainfrom
pwx-09132

Conversation

@pete-gov

Copy link
Copy Markdown
Member

Rules Content Changes

  • Add FRD-MST (MUST): an absolute requirement that must be met and documented, with failure potentially requiring corrective action or denial of initial or ongoing certification.
  • Add FRD-MNT (MUST NOT): an absolute prohibition that must be observed and documented, with the same potential consequences for failure.
  • Add FRD-SHD (SHOULD): departures may have valid reasons, but parties must carefully weigh the implications and document their decisions.
  • Add FRD-SNT (SHOULD NOT): the discouraged action may be justified in particular circumstances, but parties must carefully weigh the implications and document their decisions.
  • Add FRD-MAY (MAY): the rule is optional, and parties should explain their decisions in security documentation.
  • Store FRD-MST, FRD-MNT, FRD-SHD, FRD-SNT, and FRD-MAY under FRD.data.all, tagged “Force of the Rule,” with uppercase-only applicability, do_not_link: true, and ignore_in_terms: true.
  • Set ignore_in_terms: true for FRD-ADV (Advisor), FRD-AGY (Agency), FRD-ASR (Assessor), and FRD-PRV (Provider).
  • Synchronize terms metadata across 236 FRR requirements and six KSI indicators by removing references to the excluded stakeholder terms (FRD-ADV, FRD-AGY, FRD-ASR, and FRD-PRV); this is mechanical metadata cleanup with no changes to their statements.

Schema And Structure Changes

  • Breaking: FRD definitions now emit ignore_in_terms, supported as an optional boolean at $defs.frd_definition.properties.ignore_in_terms in schemas/fedramp-consolidated-rules.schema.json; the previous schema rejected this property, so consumers validating the new dataset against the old schema must update.
  • The revised schema continues to accept the previous dataset; required fields, existing property types, and controlled vocabularies are unchanged.

Tooling And Test Changes

  • Update tools/src/terms.ts to exclude flagged definitions and their aliases from FRR and KSI term matching, allowing checks to detect existing excluded terms and fixers to remove them; absent or false flags preserve normal matching.
  • Add ignore_in_terms?: boolean to DefinitionEntry in tools/src/types.ts.
  • Expand tools/tests/terms.test.ts to cover absent, false, and true flags; aliases; FRR and class-specific KSI statements; all definition applicability buckets; read-only analysis; and repeatable fixes.
  • Update tools/tests/fix.test.ts to verify that automatic fixes remove an ignored force term.
  • Document term-exclusion behavior in tools/README.md.

@pete-gov
pete-gov merged commit 58487bd into main Sep 13, 2026
1 check passed
@pete-gov
pete-gov deleted the pwx-09132 branch September 13, 2026 22:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant