What Guide for Developing Security Plans for Federal Information Systems requires
The objective of system security planning is to improve protection of information system resources. The protection of a system must be documented in a system security plan, a requirement of the Office of Management and Budget (OMB) Circular A-130 and the Federal Information Security Management Act (FISMA). The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. It should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system and reflect input from various managers, including information owners, the system owner, and the senior agency information security officer (SAISO). This guidance is for federal agencies and is intended for program managers, system owners, and security personnel. The system security plan establishes and documents the security controls and forms the basis for the authorization to operate, granted by a management official who accepts the associated risk. A senior management official must authorize a system to operate based on an assessment of management, operational, and technical controls. Re-authorization should occur whenever there is a significant change in processing, but at least every three years.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
SHA-256 integrity: 22933bfd133d3903e592fb4e85b6d2ffc5e53a181e28436b1e32e513be0a8d5a
Primary Citations — 8 traced to source
- {"citation":"Executive Summary: The protection of a system must be documented in a system security plan."}
- {"citation":"Executive Summary: The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements."}
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access