What Guide for Developing Security Plans for Federal Information Systems requires
The objective of system security planning is to improve protection of information system resources. This guidance is a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). All federal systems have some level of sensitivity and require protection as part of good management practice, and the protection of a system must be documented in a system security plan. The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. It should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. The plan establishes and documents security controls, forming the basis for authorization by a senior management official, who accepts the associated risk by authorizing the system to operate. This authorization should be based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
SHA-256 integrity: 62b8318a55a7f6b37036d9cc0f63f7dad299d3400c8ab6dfcce25a9a46298616
Primary Citations — 9 traced to source
- Executive Summary: The protection of a system must be documented in a system security plan.
- Executive Summary: Re-authorization should occur whenever there is a significant change in processing, but at least every three years.
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/guide-developing-security-plans-federal.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/guide-developing-security-plans-federal.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/guide-developing-security-plans-federal
- Back to registry: Browse all 10,085 compliance nodes