All federal systems have some level of sensitivity and require protection as part of good management practice.
Nist sp 800 171 system security plan template.
Recommended security controls for federal information systems.
However organizations ensure that the required information in sp 800 171 requirement 3 12 4 is conveyed in those plans.
However organizations ensure that the required information in sp 800 171 requirement 3 12 4 is conveyed in those plans.
In december of 2016 when nist released the first revision of nist sp 800 171 they included information about what was supposed to be done with all of the plans and procedures that were created to secure your facility.
The guidance is designed to help the program.
The controls selected or planned must be documented in a system security plan.
Nist computer security resource center csrc.
Documentation supplemental material cui ssp template.
Nist sp 800 53 contains the management operational and technical safeguards or countermeasures prescribed for an information system.
The completion of system security plans is a requirement of the office of management and budget omb circular a.
In this revision they included information about a required system security plan ssp.
The ssp toolkit also comes with a poam and waiver document that are required to document corrective action plans and capture deviations from nist sp 800 171 rev.
The objective of system security planning is to improve protection of information system resources.
There is no prescribed format or specified level of detail for system security plans.
1 system security requirements and describes controls in place or planned to meet those requirements.
1 has been superseded by sp 800 171 rev.
Documentation supplemental material cui ssp template.
Documentation supplemental material cui ssp template.
There is no prescribed format or specified level of detail for system security plans.
This is a nist 800 171 system security plan ssp template which is a comprehensive document that provides an overview of nist sp 800 171 rev.
This document provides guidance for federal.
1 06 07 2018 planning note 2 21 2020.
1 system security requirements and describes controls in place or planned to meet those requirements.
There is no prescribed format or specified level of detail for system security plans.
The protection of a system must be documented in a system security plan.