| ___________________________________________________________________
System Security Plan Template
[Download Sample Chapters]
What is it?
The System Security Plan provides guidelines to establish system security and privacy
requirements. It identifies the current security environment, establishes scope and
objectives, and outlines the activities required for security implementation. The System
Security Plan describes the systems security requirements, the controls in place or
planned, and roles/responsibilities of all authorized individuals who use the system.
Who uses it?
Development Manager, Project Manager, IT Manager, Security Administrator, Test Manager,
Documentation Manager, System Administrator.
When is it used?
The System Security Plan is used to describe how to plan adequate, cost-effective security
protection for a system with input from managers with responsibilities concerning the
system, such as information owners, system admins, and the system security manager.
Table of Contents
1 Overview
1.1 Objectives
1.2 Document Structure
1.3 Scope
1.4 System Overview
1.5 Key Stakeholders
1.6 References
1.7 Relationship to Other Plans
1.8 Points of Contact
1.9 Policies, Directives and Procedures
2 System Security Plan
2.1 Information Sensitivity
2.1.1 Applicable Laws
2.1.2 Protective Measures
2.1.3 Sensitivity
2.2 Risk Assessment
2.3 Security Measures
2.3.1 Control Measures
2.3.2 Security Training
2.3.3 System Security
3 Project Management
3.1 Schedule
3.2 Constraints
3.3 Issues
3.4 Assumptions
3.5 Dependencies
3.6 Sign-Off Criteria
4 Project Team
4.1 Roles
4.2 Responsibilities
4.3 Resources
4.4 Software Tools
4.5 Training
5 Appendix A
5.1 Glossary of Terms
5.2 Acronyms and Abbreviations
Index of Tables
Table 1 - Risks
Table 2 - Control Measures
Table 3 - Schedule
Table 4 Constraints
Table 5 Issues
Table 6 - Assumptions
Table 7 Dependencies
Table 8 - Sign-off Criteria
Table 9 - Roles and Responsibilities
Table 9 - Glossary of Terms
Table 10 - Acronyms and Abbreviations
Page Count:
Related Documents
|