Compliance Profile (Pro)

The Compliance Profile enrolls an Asset as a system and holds the facts that appear on every deliverable it produces. Open the Asset that represents your system boundary, go to the Compliance tab, then Profile.

The Compliance Profile form

Profile fields

FieldWhat it does
EnabledTurns compliance tracking on for this product.
Automatic SyncKeeps POA&M items in sync with findings.
POA&M ID PrefixItem numbering. Required. Items are numbered V-1, V-2, and so on by default.
Impact LevelLI-SaaS, Low, Moderate, or High.
Cloud Service ProviderThe CSP name, as it should appear on the POA&M cover data.
System / Offering NameThe system name, as it should appear on the POA&M cover data.
FedRAMP System IdentifierYour system’s identifier, for example F00000042.
Default Point of ContactThe POC applied to items that do not carry their own.
Scan Item PolicyEither include all open items, or only past-due scan items.
OSCAL SSP ReferenceOptional. When set, generated OSCAL POA&Ms reference it through import-ssp.

Choosing a scan item policy

Past-due-only is the FedRAMP ConMon minimum. Include all open items is the more conservative choice, and is the default.

Saving and syncing

Save Compliance Profile enrolls the Asset. The POA&M ledger then populates from the Asset’s existing findings, and the rest of the Compliance tab becomes available.

With Automatic Sync on, the ledger keeps itself current — see The POA&M Ledger. Sync POA&M Now runs a sync immediately, which is useful right after you change the profile or import a new scan.

Settings available through the API only

Two profile settings are not on the form and are set through the compliance API:

  • Default scan controls — the controls attributed to scanner findings that carry no control mapping of their own. RA-5 is the common choice for vulnerability scan results. Findings that do carry their own control references are mapped from those instead; see Control Coverage.
  • Configuration test types — the test types whose findings are treated as configuration items, which is what drives CM-6 consolidation in the ledger.

Auditability

Compliance profiles are under audit history: every change records who changed what, and when.