CGRC System Security Plan (SSP) Development — Questions and Answers
Question 1: What is the primary purpose of a System Security Plan (SSP) in the NIST Risk Management Framework?
- To provide an overview of the security requirements of an information system and describe the controls in place or planned to meet those requirements (Correct answer)
- To document the results of a security assessment and record identified vulnerabilities
- To outline the organization's enterprise-wide information security policy
- To establish the schedule and budget for implementing new security controls
Correct answer: To provide an overview of the security requirements of an information system and describe the controls in place or planned to meet those requirements
The SSP provides an overview of the system's security requirements and describes the security controls that are in place or planned, serving as the master reference document for the system's authorization package. It is distinct from an assessment report, organizational policy, or a project plan.
Question 2: According to NIST guidance, who is primarily responsible for developing and maintaining the System Security Plan?
- The Authorizing Official (AO)
- The Information System Owner (Correct answer)
- The Security Control Assessor (SCA)
- The Chief Information Officer (CIO)
Correct answer: The Information System Owner
The Information System Owner is responsible for developing, maintaining, and ensuring the accuracy of the SSP. The AO reviews and approves it, the SCA uses it during assessment, and the CIO provides oversight — but ownership of the SSP rests with the system owner.
Question 3: Which of the following is NOT typically included as a required component of a System Security Plan?
- System boundary and interconnections
- Security control implementation descriptions
- Detailed source code for security-relevant applications (Correct answer)
- System categorization and impact level
Correct answer: Detailed source code for security-relevant applications
SSPs describe how controls are implemented at a conceptual and procedural level, but do not include actual source code. Required components include the system boundary, control descriptions, categorization, interconnection information, and operational environment details.
Question 4: Under the NIST RMF, at which step is the System Security Plan formally reviewed and approved as part of the authorization package?
- Step 2 – Select
- Step 4 – Assess
- Step 5 – Authorize (Correct answer)
- Step 6 – Monitor
Correct answer: Step 5 – Authorize
The SSP is a core component of the authorization package reviewed by the Authorizing Official during Step 5 (Authorize). It is initiated during Select and updated through Implement and Assess, but formal approval occurs at the Authorize step when the AO makes the risk acceptance decision.
Question 5: A security professional discovers that a third-party software component used by the system has been updated, changing the way authentication is handled. What is the MOST appropriate immediate action regarding the SSP?
- Notify the Authorizing Official and update the SSP to reflect the change before placing the system back into full operation (Correct answer)
- Wait until the next annual review cycle to update the SSP with the authentication change
- Update the Plan of Action and Milestones (POA&M) instead, since the SSP only documents planned controls
- Remove the system from operation until a full reauthorization is completed
Correct answer: Notify the Authorizing Official and update the SSP to reflect the change before placing the system back into full operation
Significant configuration changes that affect security controls require the SSP to be updated promptly and the Authorizing Official notified. Waiting for an annual review or relying solely on a POA&M is insufficient for a change that alters how a security control operates. Full reauthorization may be triggered, but notification and SSP update are the immediate steps.
Question 6: Which NIST Special Publication provides the primary guidance for developing and maintaining a System Security Plan for federal information systems?
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-18 (Correct answer)
- NIST SP 800-60
Correct answer: NIST SP 800-18
NIST SP 800-18, 'Guide for Developing Security Plans for Federal Information Systems,' provides direct guidance on SSP development. SP 800-37 covers the RMF process broadly, SP 800-53 covers the control catalog, and SP 800-60 covers system categorization.
What is the primary purpose of a System Security Plan (SSP) in the NIST Risk Management Framework?