{
  "node_id": "developing-security-plans-federal-systems",
  "title": "Guide for Developing Security Plans for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2006-02-01",
  "bluf": "The objective of system security planning is to improve the protection of information system resources. This guide provides an overview of the security requirements for a system and describes the controls, either in place or planned, for meeting those requirements. The completion of system security plans is a requirement under the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA), applicable to all federal systems which have some level of sensitivity and require protection. The system security plan delineates responsibilities and expected behavior of all individuals who access the system, and should reflect input from managers with system responsibilities, including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nManagement authorization to operate a system is based on an assessment of management, operational, and technical controls, for which the system security plan forms the basis. By authorizing a system, a manager accepts its associated risk. This authorization must be periodically reviewed and re-authorization should occur whenever there is a significant change in processing, and at a minimum of every three years. The plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and is a living document that requires periodic review and modification.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization",
    "nist-sp-800-53-r5",
    "nist-sp-800-30-risk-assessment"
  ],
  "primary_citations_count": 8
}