Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

Guide for Developing Security Plans for Federal Information Systems

The objective of system security planning is to improve the protection of information system resources. This guide provides an overview of the security…

What Guide for Developing Security Plans for Federal Information Systems requires

The objective of system security planning is to improve the protection of information system resources. This guide provides an overview of the security requirements for a system and describes the controls, either in place or planned, for meeting those requirements. The completion of system security plans is a requirement under the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA), applicable to all federal systems which have some level of sensitivity and require protection. The system security plan delineates responsibilities and expected behavior of all individuals who access the system, and should reflect input from managers with system responsibilities, including information owners, the system owner, and the senior agency information security officer (SAISO). Management authorization to operate a system is based on an assessment of management, operational, and technical controls, for which the system security plan forms the basis. By authorizing a system, a manager accepts its associated risk. This authorization must be periodically reviewed and re-authorization should occur whenever there is a significant change in processing, and at a minimum of every three years. The plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and is a living document that requires periodic review and modification.

Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:

Primary source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf

SHA-256 integrity: b69ac8344550ddef99cb14fc4133fe5dbcd750a29fe1089d0291d82ba4dac381

Primary Citations — 8 traced to source

  • Executive Summary: The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements.
  • Executive Summary: Re-authorization should occur whenever there is a significant change in processing, but at least every three years.

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.