Nist 800 171 System Security Plan Template

The requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations.
Nist 800 171 system security plan template. The department of defenses final guidance requires the review of a system security plan ssp in the assessment of contract solicitation during the awards process. The organization develops and implements a security plan for the information system that provides an overview of the security requirements for the system and a description of the security controls in place or planned for meeting those requirements. The nist sp 800 171 system security plan ssptemplate is a comprehensive document that provides an overview of nist sp 800 171 rev. In december of 2016 when nist released the first revision of nist sp 800 171 they included information about what was supposed to be done with all of the plans and procedures that were created to secure your facility.
This publication provides federal and nonfederal organizations with assessment procedures and a methodology that can be employed to conduct assessments of the cui security requirements in nist special publication 800 171 protecting controlled unclassified information in nonfederal systems and organizations. The protection of a system must be documented in a system security plan. Example nist 800 171 system security plan ssp template for contolled unclassified information cui author. The security requirements apply to all components of nonfederal systems and organizations that process store or transmit cui or that provide security protection for such components.
The assessment procedures are flexible and can be customized to the needs of the organizations and the assessors conducting the assessments. This is a nist 800 171 system security plan ssp template which is a comprehensive document that provides an overview of nist sp 800 171 rev. In this revision they included information about a required system security plan ssp. The completion of system security plans is a requirement of the office of management and budget omb circular a 130 management of federal information resources appendix iii security of federal automated information resources and title iii of the e government act entitled the federal information security management act fisma the purpose of the system security plan is to provide an overview of the security.
1 system security requirements and describes controls in place or planned to meet those requirements.