[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-173109-105":53,"doc-detail-173109-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","system-security-plan-outline-example-june-2025","System Security Plan Outline Example - June 2025","","This document outlines a practical structure for a System Security Plan aligned with an organization’s security program and risk management approach. It describes how system owners and senior security officials identify applicable security requirements, document them early in the SDLC, and obtain approval from the authorizing official prior to control implementation and assessment. The example includes review/change recordkeeping, role identification with business contact details, operational status tracking, approval signatures and authorization decisions, and system descriptions with information types and categorization.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/system-security-plan-outline-example-june-2025/173109/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/system-security-plan-outline-example-june-2025/173109.png","ImageObject",442,249,{"name":88,"@type":89},"Đào","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-10-02","2026-09-01",true,{"@type":98,"interactionType":99,"userInteractionCount":47},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What is the purpose of a System Security Plan in this outline example?","Question",{"text":108,"@type":109},"The plan documents applicable security requirements and ensures they are integrated into system design and development early in the SDLC, with approval before control implementation and assessment.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"Which records must be maintained for reviews and changes?",{"text":113,"@type":109},"The outline requires review logs (review date, reviewer, notes) and change logs (revision identifiers, descriptions, affected sections/pages, and who made the changes).",{"name":115,"@type":106,"acceptedAnswer":116},"How should the authorization boundary and system environment be documented?",{"text":117,"@type":109},"The plan should define the scope of protections within the authorization boundary and reference or include up-to-date system, network, and data flow diagrams, with sensitive information redacted as needed.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},173109,1788299984,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":47,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":76},1374402968488,"https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0","NIST Special Publication 800\nNIST SP 800-18r2 ipd\nSupplemental Material\nSystem Security Plan Outline Example\nJune 2025\nThe system security plan is informed by the organization’s security program and risk management strategy, including risk assessments and analyses. System owners and senior security officials collaborate to identify security requirements that are applicable to the system based on the type of data processed, the operational context, legal requirements, and mission objectives. These requirements are documented in the system security plan and integrated into design and development processes early in the system development life cycle (SDLC) to ensure that security is embedded into the system architecture rather than retrofitted as an afterthought. The authorizing official approves the plan before control implementation and/or assessment.\nThis example provides a potential structure for a security plan. Organizations have the flexibility to develop and implement a security plan based on their unique needs and requirements. Automated tools can help document security plan information (e.g., individuals filling roles, control implementation information, system diagrams) and related artifacts (e.g., network diagrams, component inventory).\nInclude any distribution limitations, handling requirements, and applicable security markings as part of the security plan development and maintenance processes.\nSystem Name and Identifier\nDesignate a unique system name and identifier and include applicable historical names.\nSystem Security Plan Review and Change Records\nMaintain records of reviews and changes to the system security plan. Review and change logs may be combined or logged separately. The review log includes the review date, the individual or team who completed the review, and associated notes. The change log may include additional information, such as:\nDate of review and revision\nPlan revision or version identifier\nDescription of change or revision\nThe section or pages affected\nChanges made by name, title, and/or organization\nRole Identification and Responsible Personnel\nIdentify authorizing officials, system owners, and other key roles with system responsibilities. Include the individual’s name; system-specific and organizational role; organizational unit, department, or division; primary and alternate business phone numbers; and email address for the following key points of contact:\nAuthorizing official and authorizing official designated representative\nSystem owner or common control provider\nInformation owner or steward\nSenior agency information security officer\nSystem security officer\nList other personnel or designated contacts (e.g., vendors, facility personnel, on-site security) as well as their roles, names, addresses, primary and alternate business phone numbers, and email addresses.\nRestrict contact information to business information to avoid exposing personal information. Using personal information (e.g., a home phone or personal cell phone number as the “alternate business phone number”) may create unnecessary privacy risks for individuals.\nSystem Operational Status\nIndicate the operational status of the system:\nUnder development — The system is being designed or developed and is not fully functioning in an operational environment.\nOperational — The authorized system is operating in the operational environment.\nUndergoing a major modification — The authorized operational system is undergoing a major change to the operational environment.\nDisposal — The system is no longer authorized, operational, or under development.\nIf more than one status is selected, list which part of the system is covered under each status.\nSystem Security Plan Approval\nInclude an electronic, digital, or handwritten signature and the date when the system security plan was reviewed and approved.\nSystem Authorization Decision\nIdentify the current authorization decision for the system. Include the date when the decision was issued, the effe","cbCaiv9upMxQAHBE","https://ap.wps.com/l/cbCaiv9upMxQAHBE","docx",2286200,8,"English","# System Security Plan Overview\n## Security requirements integration and approval\n# Security Plan Governance and Records\n## Distribution limits and markings\n## Review and change logs\n# Roles and Responsible Personnel\n## Contact identification and privacy restrictions\n# System Operational Status and Approval\n## Operational state selection\n## Signature and approval details\n# System Authorization and Description\n## Authorization decision and dates\n## System purpose and additional risks\n# Information Types and Categorization\n## Impact levels and system categorization\n# Authorization Boundary and Environment\n## Diagrams and redaction requirements\n# System Component Inventory","[{\"question\":\"What is the purpose of a System Security Plan in this outline example?\",\"answer\":\"The plan documents applicable security requirements and ensures they are integrated into system design and development early in the SDLC, with approval before control implementation and assessment.\"},{\"question\":\"Which records must be maintained for reviews and changes?\",\"answer\":\"The outline requires review logs (review date, reviewer, notes) and change logs (revision identifiers, descriptions, affected sections/pages, and who made the changes).\"},{\"question\":\"How should the authorization boundary and system environment be documented?\",\"answer\":\"The plan should define the scope of protections within the authorization boundary and reference or include up-to-date system, network, and data flow diagrams, with sensitive information redacted as needed.\"}]","System Security Plan Outline Example - June 2025 | DOCX"]