← Cybersecurity Alphabet Soup

SSP

System Security Plan

governancemedium

An SSP is the authoritative document describing a system's boundary, its operating environment, and how each required security control is implemented. It is a core RMF and FedRAMP artifact, is what an assessor reads before testing anything, and is paired with a POA&M listing the controls that are not yet fully met. Under DFARS and NIST SP 800-171, a current SSP is itself a contractual requirement.

Sources

More in governance