What is the primary purpose of a System Security Plan (SSP) in the NIST Risk Management Framework?
-
A
To provide an overview of the security requirements of an information system and describe the controls in place or planned to meet those requirements
-
B
To document the results of a security assessment and record identified vulnerabilities
-
C
To outline the organization's enterprise-wide information security policy
-
D
To establish the schedule and budget for implementing new security controls