diff --git a/features/fedramp_extensions.feature b/features/fedramp_extensions.feature
index fe1a667b3..37b6a35c6 100644
--- a/features/fedramp_extensions.feature
+++ b/features/fedramp_extensions.feature
@@ -36,6 +36,7 @@ Examples:
| cia-impact-has-adjustment-justification |
| cia-impact-has-selected |
| cloud-service-model |
+ | component-has-authenticated-scan |
| component-has-authentication-method |
| component-has-non-provider-responsible-role |
| component-has-provider-responsible-role |
@@ -115,6 +116,7 @@ Examples:
| interconnection-direction |
| interconnection-security |
| inventory-item-allows-authenticated-scan |
+ | inventory-item-has-authenticated-scan |
| inventory-item-has-vendor-name |
| inventory-item-public |
| inventory-item-virtual |
@@ -198,6 +200,8 @@ Examples:
| cia-impact-has-selected-PASS.yaml |
| cloud-service-model-FAIL.yaml |
| cloud-service-model-PASS.yaml |
+ | component-has-authenticated-scan-FAIL.yaml |
+ | component-has-authenticated-scan-PASS.yaml |
| component-has-authentication-method-FAIL.yaml |
| component-has-authentication-method-PASS.yaml |
| component-has-non-provider-responsible-role-FAIL.yaml |
@@ -356,6 +360,8 @@ Examples:
| interconnection-security-PASS.yaml |
| inventory-item-allows-authenticated-scan-FAIL.yaml |
| inventory-item-allows-authenticated-scan-PASS.yaml |
+ | inventory-item-has-authenticated-scan-FAIL.yaml |
+ | inventory-item-has-authenticated-scan-PASS.yaml |
| inventory-item-has-vendor-name-FAIL.yaml |
| inventory-item-has-vendor-name-PASS.yaml |
| inventory-item-public-FAIL.yaml |
diff --git a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
index 86f58016a..c894ffcfe 100644
--- a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
+++ b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
@@ -1518,6 +1518,7 @@ leveraged-authorization assembly:
+
@@ -1649,6 +1650,7 @@ property.
Describe the service and what it is used for.
+
@@ -2355,6 +2357,7 @@ preferable to the link[rel='validation'] example above.
+
@@ -2370,6 +2373,7 @@ preferable to the link[rel='validation'] example above.
+
@@ -2385,6 +2389,7 @@ preferable to the link[rel='validation'] example above.
+
@@ -2405,6 +2410,7 @@ preferable to the link[rel='validation'] example above.
Asset wasn't running at time of scan.
+
@@ -2418,6 +2424,7 @@ preferable to the link[rel='validation'] example above.
+
@@ -2438,6 +2445,7 @@ preferable to the link[rel='validation'] example above.
Asset wasn't running at time of scan.
+
@@ -2451,6 +2459,7 @@ preferable to the link[rel='validation'] example above.
+
diff --git a/src/validations/constraints/content/ssp-component-has-authenticated-scan-INVALID.xml b/src/validations/constraints/content/ssp-component-has-authenticated-scan-INVALID.xml
new file mode 100644
index 000000000..d831bef9c
--- /dev/null
+++ b/src/validations/constraints/content/ssp-component-has-authenticated-scan-INVALID.xml
@@ -0,0 +1,8 @@
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-inventory-item-has-authenticated-scan-INVALID.xml b/src/validations/constraints/content/ssp-inventory-item-has-authenticated-scan-INVALID.xml
new file mode 100644
index 000000000..8f5a1b05c
--- /dev/null
+++ b/src/validations/constraints/content/ssp-inventory-item-has-authenticated-scan-INVALID.xml
@@ -0,0 +1,12 @@
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/src/validations/constraints/fedramp-external-constraints.xml b/src/validations/constraints/fedramp-external-constraints.xml
index 82fc00ca6..d79e98228 100644
--- a/src/validations/constraints/fedramp-external-constraints.xml
+++ b/src/validations/constraints/fedramp-external-constraints.xml
@@ -637,10 +637,26 @@
+
+
+
+
+ Component Has Authenticated Scan
+
+ In a FedRAMP SSP, each internal service component MUST state whether it allows authenticated scans.
+
+
+
+
+
+ Inventory Item Has Authenticated Scan
+
+ In a FedRAMP SSP, each inventory item MUST state whether it allows authenticated scans in the inventory item itself or within the linked component.
+
Inventory Item Has Vendor Name
diff --git a/src/validations/constraints/unit-tests/component-has-authenticated-scan-FAIL.yaml b/src/validations/constraints/unit-tests/component-has-authenticated-scan-FAIL.yaml
new file mode 100644
index 000000000..9640ee3c6
--- /dev/null
+++ b/src/validations/constraints/unit-tests/component-has-authenticated-scan-FAIL.yaml
@@ -0,0 +1,9 @@
+test-case:
+ name: Negative Test for component-has-authenticated-scan
+ description: >-
+ This test case validates the behavior of constraint
+ component-has-authenticated-scan
+ content: ../content/ssp-component-has-authenticated-scan-INVALID.xml
+ expectations:
+ - constraint-id: component-has-authenticated-scan
+ result: fail
diff --git a/src/validations/constraints/unit-tests/component-has-authenticated-scan-PASS.yaml b/src/validations/constraints/unit-tests/component-has-authenticated-scan-PASS.yaml
new file mode 100644
index 000000000..489f96149
--- /dev/null
+++ b/src/validations/constraints/unit-tests/component-has-authenticated-scan-PASS.yaml
@@ -0,0 +1,9 @@
+test-case:
+ name: Positive Test for component-has-authenticated-scan
+ description: >-
+ This test case validates the behavior of constraint
+ component-has-authenticated-scan
+ content: ../../../content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
+ expectations:
+ - constraint-id: component-has-authenticated-scan
+ result: pass
diff --git a/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-FAIL.yaml b/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-FAIL.yaml
new file mode 100644
index 000000000..218802efc
--- /dev/null
+++ b/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-FAIL.yaml
@@ -0,0 +1,9 @@
+test-case:
+ name: Negative Test for inventory-item-has-authenticated-scan
+ description: >-
+ This test case validates the behavior of constraint
+ inventory-item-has-authenticated-scan
+ content: ../content/ssp-inventory-item-has-authenticated-scan-INVALID.xml
+ expectations:
+ - constraint-id: inventory-item-has-authenticated-scan
+ result: fail
diff --git a/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-PASS.yaml b/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-PASS.yaml
new file mode 100644
index 000000000..13a912a94
--- /dev/null
+++ b/src/validations/constraints/unit-tests/inventory-item-has-authenticated-scan-PASS.yaml
@@ -0,0 +1,9 @@
+test-case:
+ name: Positive Test for inventory-item-has-authenticated-scan
+ description: >-
+ This test case validates the behavior of constraint
+ inventory-item-has-authenticated-scan
+ content: ../../../content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
+ expectations:
+ - constraint-id: inventory-item-has-authenticated-scan
+ result: pass