FedRAMP Test Case Procedure Export (.xlsx)
FedRAMP Test Case Procedure Export Feature
This page contains information to assist our customers with utilizing the FedRAMP Test Case Procedure Excel Export feature in RegScale. It describes what it is, why you would use it, the benefits, and provides instructions on getting started.
What is it?
The FedRAMP Test Case Procedure Export feature is a useful way of extracting data from a Security Plan in RegScale to perform external analysis using Microsoft Excel or to upload the data into FedRAMP.
Why would you use it?
There are many reasons to use this feature which include:
- Exporting data for external sharing
- Custom graphing and visualization in Excel
- Data analysis and transformation in Excel
- Uploading information into FedRAMP
What are the benefits?
This feature has multiple benefits for an organization; to include:
- Allows migrating data from RegScale into FedRAMP
- Avoids locking you into our system for data analysis
- Leverages commonly used skill sets found in most businesses
- Allows for easy custom reporting and analysis
How do I use it?
The Security Plan has to have controls assigned to it along with assessments for at least one control in order for the export button to display.
Instructions for using this feature are provided below:
- In the RegScale main menu, select Modules
- Select Security Plans from the drop down list
- Conduct any searching/filtering of the results to select the Security Plan of interest
- Click on the View button to open the Security Plan
- At the top of the page, click the export button:
- Clicking the button will create a pop up of the available export options
- Click export button labeled
FedRAMP Test Case Procedure Export (.xlsx)
- Open the Excel file to conduct any relevant data analysis or visualization
NOTE: The Excel download is a raw pull of the issues associated with the Security Plan. The data contains limited transforms and will highlight any fields that should be populated along with comments on how to populate them in RegScale.
Mappings
These mappings are for the worksheets with the control data. The System and CtrlSummary worksheets are populated via formulas on the mappings below.
Column | Column Header | RegScale Mapping |
---|---|---|
H | Observations and Evidence | Assessment -> Tests -> Observations & Gaps |
I | Implementation Status | Control.Status |
J | Assessment Result | Assessment -> Tests -> Result |
K | Identified Risk | Risk.Title Associated with the Assessment |
L | Likelihood Level | Risk.Probability Associated with the Assessment |
M | Impact Level | Risk.Consequence Associated with the Assessment |
N | Risk Exposure Level | Populated by a formula using Column L & M |
O | Risk Statement | Risk.RiskStatement Associated with the Assessment |
P | Recommendation for Mitigation | Risk.Mitigation Associated with the Assessment |
Q | SSP Implementation Statement Differential | Assessment -> Tests -> Gaps Populated on any Tests |
R | Assessor POC | Assessment.CreatedBy |
T | Prior Assessment Result | Previous Assessment.Result |
U | Prior Risk Exposure Level | Previous Risk.Probability Associated with the Assessment |
Updated 11 months ago