home/dictionary/System Security Plan

System Security Plan

nounverified·updated May 18, 2026

A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.

Framework senses

NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
§2 · sense_2_pending_review
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
NIST SP 800-531 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-53A1 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-371 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
FIPS PUB 2001 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-181 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-172r31 senseview framework →
§1 · glossary
A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.
Attribution from the CKI glossary mapping stage (glossary)
NIST SP 800-171r31 senseview framework →
§1 · glossary
A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
DR-088 backfill from the noun definition column