A System Security Plan (SSP) Is the central document that explains how your organization secures sensitive data, including Controlled Unclassified Information (CUI). Rather than being a static policy, an SSP documents the actual security controls protecting your systems and how those controls are operated, monitored, and maintained.
A System Security Plan (SSP) Is the central document that explains how your organization secures sensitive data, including Controlled Unclassified Information (CUI). Rather than being a static policy, an SSP documents the actual security controls protecting your systems and how those controls are operated, monitored, and maintained.
Many contractors hear the term NIST 800-171 gap analysis but are not sure what it actually means in practice. Some assume it leads directly to certification, while others believe it is simply a checklist exercise.