home/glossary/System Security Plan

System Security Plan

nounid 4340·updated May 18, 2026
verified

A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.

polysemousMWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems13 citations · 13 defined by this document · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.20.c.103.04.04.b ¶ 103.12.02.b.3 ¶ 103.15.01.b ¶ 103.15.0203.15.02.a03.15.02.b03.15.02.c03.15.02.c ¶ 103.15.02.c ¶ 103.17.01.c ¶ 23.2.2 ¶ 1623.2.2 ¶ 163

Classifications

Entity Type

Artifact92%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated88%llm-generatedllm:claude-haiku-4-5

Information Class

Cui75%llm-generatedllm:claude-haiku-4-5

Variants

plural
System Security Plans
possessive
System Security Plan's
pluralpossessive
System Security Plans'

Framework definitions

NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
§2 · sense_2_pending_review
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
NIST SP 800-531 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-53A1 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-371 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
FIPS PUB 2001 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-181 senseview framework →
§1
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
NIST SP 800-172r31 senseview framework →
§1 · glossary
A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.
Attribution from the CKI glossary mapping stage (glossary)
NIST SP 800-171r31 senseview framework →
§1 · glossary
A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The formal document prepared by the information system owner (or common security controls owner for inherited controls) that provides an overview of the security requirements for the system and describes the security controls in place or planned for meeting those requirements. The plan can also contain as supporting appendices or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.