System Security Plan
nounverified·updated May 18, 2026
A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.
Framework senses
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §2 · sense_2_pending_review
- The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
- §1
- The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §1
- Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
- §1 · glossary
- A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.Attribution from the CKI glossary mapping stage (glossary)
- §1 · glossary
- A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems.Attribution from the CKI glossary mapping stage (glossary)
- §1 · legacy_primary
- The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.DR-088 backfill from the noun definition column