Which document serves as the primary artifact in the NIST RMF that describes the security controls implemented in an information system?
-
A
Plan of Action and Milestones (POA&M)
-
B
System Security Plan (SSP)
-
C
Security Assessment Report (SAR)
-
D
Authorization to Operate (ATO)