Dfars Ssp Template
What are your options for writing an ssp.
Dfars ssp template. Example nist 800 171 system security plan ssp template for contolled unclassified information cui author. The errata update includes minor editorial changes to selected cui security requirements some additional references and definitions and a new appendix that contains an expanded discussion about each cui requirement the protection of controlled unclassified information cui resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly. Dfars system security plan ssp templates. To download the ssp template click here.
Nist supplies a template to help contractors create an ssp. The nist sp 800 171 system security plan ssptemplate is a comprehensive document that provides an overview of nist sp 800 171 rev. Ckss has compiled a suite of dfars 252204 7012 compliance templates to help dod contractors get a jumpstart on their remediation activities as well as ensure continued compliance. Dfars 7012 compliance is an expensive laborious process.
The ssp toolkit also comes with a poam and waiver document that are required to document corrective action plans and capture deviations from nist sp 800 171 rev. An important component of dfars reporting is having a detailed well written system security plan ssp in place that provides an overview of the security requirements of the system and describes the controls in place or planned for meeting those requirements. The system security plan ssp template is. Some companies have their internal it staff fill in this template to create a system.
These pp are structured to help you achieve compliance with all defense federal acquisition regulation supplement dfars 252204 7012 and nist sp 800 171 requirements and are organized into sections each representing one of the 14 requirements families documented within nist sp 800 171. A managed security service provider who provides nist 800 171 compliance services can develop the ssp for you for a fee. The dod has a ssp template available to assist in the process. The ssp toolkit also comes with a poam and waiver document that are required to document corrective action plans and capture deviations from nist sp 800 171 rev.
An ssp is a comprehensive summary of all security practices and policies that will help to keep dod data secure if the contractor is awarded a dod contract. 1 system security requirements and describes controls in place or planned to meet those requirements. Our full set of nist 800 171 templates simplify the entire process saving contractors money and countless man hours. Dod contractors who have an internal it department who has cyber security knowledge can opt to develop an ssp in house.