System Security Plan Template Nist 800 53
The completion of system security plans is a requirement of the office of management and budget omb circular a.
System security plan template nist 800 53. Nist sp 800 53 contains the management operational and technical safeguards or countermeasures prescribed for an information system. Recommended security controls for federal information systems. This nist sp 800 53 database represents the security controls and associated assessment procedures defined in nist sp 800 53 revision 4 recommended security controls for federal information systems and organizations. The protection of a system must be documented in a system security plan. Any discrepancies noted in the content between this nist sp 800 53 database and the latest published nist special publication.
It is prohibited to disclose this document to third parties page 3 of 133 without an executed non disclosure agreement nda instruction on filling out the ssp template. It is important to understand that there is no officially sanctioned format for a system security plan ssp to meet nist 800 171. Nist computer security resource center csrc. The controls selected or planned must be documented in a system security plan. In other words that means that dod contracts will be assessed on the ability of the contractor to provide proof of compliance with nist 800 171.
Select the appropriate minimum security control baseline low moderate high impact from nist sp 800 53 then provide a thorough description of how all the minimum security controls in the applicable baseline are being implemented or planned to be implemented. The good thing for folks with little system security plan experience is that nist 800 171 outlines a nice framework around which to construct our system security plan. The department of defense s final guidance requires the review of a system security plan ssp in the assessment of contract solicitation during the awards process. Supplemental guidance security plans relate security requirements to a set of security controls and control enhancements. All federal systems have some level of sensitivity and require protection as part of good management practice.
In regard to building an system security plan to align with the dfars those codes and regulations are the nist sp 800 171 controls. This document provides guidance for federal. The following table provides a high level summary by control family of how insert system name complies with the security controls articulated in nist 800 53.
work for hire agreement music template ytd profit and loss statement template what is llc operating agreement template windows 10 migration end user communication template work plan template excel free downloads your order has shipped email template you are receiving this email because template