System Security Plan
The System Security Plan (SSP) page provides a structured interface for documenting the security posture of an information system. This page guides users through each section required to build a comprehensive SSP, which can then be exported in Microsoft Word or OSCAL (JSON) formats.
Each section plays a key role in compiling a complete and compliant security plan. Use the interface to enter, manage, and review critical system details. Below is a guide to each section.
You reach the builder from the left navigation under SSP by selecting Builder. The builder has eight steps:
- Getting Started
- System Identification
- System Responsibilities
- System Summary
- Network Diagrams
- Data Flow Diagrams
- System Components
- Review
1. Getting Started
An overview of what a System Security Plan contains and why each section matters. No information is entered on this step.
2. System Identification
This section captures core information that defines the system, such as:
- Name – The name of the system.
- Description – A short summary of the system.
- Identifier – A unique name or reference code for the system.
- Risk Categorization – The system’s categorization under relevant security frameworks.
- CAGE Codes – If applicable, the system’s Commercial and Government Entity Codes.
- Sensitivity Label – The sensitivity classification applied to the system.
This foundational section helps establish the scope of the SSP and identifies the responsible organization.
3. System Responsibilities
This section defines the key roles associated with the system’s security, management, and oversight.
Tabs
Assign Responsibilities
Assign key personnel to roles critical to the system’s operation and security. Available roles include:
- Responsible Person – Primary contact for overall system oversight.
- Information Owner – Oversees the protection and classification of system data.
- System Owner – Manages day-to-day operations and security of the system.
- System Security Officer – Ensures implementation and enforcement of security controls.
- System Security Support – Assists in maintaining system security under the Security Officer.
- Authorizing Official – Accepts the residual risk of operating the system.
These roles are included in the final SSP output and help ensure clear accountability across the organization.
Users
View and manage user entries relevant to the SSP. While you can create and delete local users here, global users (from the tenant-level directory) are visible but cannot be modified. However, global users can be assigned as responsible parties.
4. System Summary
Provide a high-level overview of your information system. This summary helps contextualize the system’s purpose and architecture for reviewers.
You’ll be prompted to describe:
- System name, purpose, and location
- System boundaries
- System components
- Security requirements
- Implemented security controls
Use this section to define what the system does, who it serves, and how it meets its security obligations.
5. Network Diagrams
Select the network diagrams to include in the SSP. Use Create Network Diagram to add one that does not exist yet. Diagrams are also managed from the Network Diagrams page under SSP in the left navigation.
Until a diagram is selected, the Review step shows this section as None selected.
6. Data Flow Diagrams
Select the data flow diagrams to include in the SSP. Use Create Data Flow Diagram to add one that does not exist yet. Diagrams are also managed from the Data Flow Diagrams page under SSP in the left navigation.
Until a diagram is selected, the Review step shows this section as None selected.
7. System Components
List and manage the individual components that make up your system, including hardware, software, and network elements.
You can:
- Add new components
- Edit existing entries
- Delete obsolete components
Common examples include servers, workstations, routers, firewalls, applications, and databases.
Accurately documenting each component ensures that all parts of your system are covered by appropriate security controls.
8. Review
The final step before generating your SSP. Review all previously entered information in one place. The Review step restates each section, including System Identification, System Responsibilities, Network Diagrams, Data Flow Diagrams, System Summary, and System Components.
-
Generate SSP – Once the review is complete, generate the System Security Plan in either:
- Microsoft Word format (for human-readable documentation)
- OSCAL (JSON) format (for machine-readable compliance tools)
Review is the only step where the Generate SSP button is available.
Next Steps
After generating the SSP, you can share the document with auditors, stakeholders, or compliance tools as needed. To make future updates easier, maintain accurate and up-to-date records across all sections.