{
  "node_id": "guide-for-developing-security-plans",
  "title": "Guide for Developing Security Plans for Federal Information Systems",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2006-02-01",
  "bluf": "The objective of system security planning is to improve protection of information system resources. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. It should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and reflect input from various managers, including information owners, the system owner, and the senior agency information security officer (SAISO).\n\nThis guidance is for federal agencies and is intended for program managers, system owners, and security personnel. The system security plan establishes and documents the security controls and forms the basis for the authorization to operate, granted by a management official who accepts the associated risk. A senior management official must authorize a system to operate based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization",
    "fips-200-minimum-security-requirements",
    "nist-sp-800-30-risk-assessment"
  ],
  "primary_citations_count": 8
}