System Security Plan Template Australia
The ssp toolkit also comes with a poam and waiver document that are required to document corrective.
System security plan template australia. Resources and training for professionals looking to strengthen the cyber security of industrial control systems ics. The system security plan ssp is the main document of a security package in which a csp describes all the security controls in use on the information system and their implementation. It outlines the steps you and your staff need to follow. 1 system security requirements and describes controls in place or planned to meet those requirements.
The security plan allows entities to review the degree of security risk that exists in different areas of operations and take action to mitigate identified risks. The seller will work with a representative sme to develop this template. Once completed a ssp provides a detailed narrative of a csp s security control implementation a detailed system description including components and services inventory and detailed depictions of the system s data flows and authorization boundary. An incident response plan helps you prepare for and respond to a cyber incident.
Security plan template for major applications and general support systems table of contents executive summary a. Consider the following stages when preparing a plan. Prepare a cyber security incident response plan. Template information security policy this template details the mandatory clauses which must be included in an agency s information security policy as per the requirements of the wog information security policy manual.
Application system identification a 1 application system category indicate whether the application system is a major application or a general support system. A security plan see security plan specifies the approach responsibilities and resources applied to managing protective security risks. Security plan template ms word excel use this security plan template to describe the system s security requirements controls and roles responsibilities of authorized individuals. The cdic is seeking to engage a seller to develop a template for a system security plan compliant with nist sp800 171 based on industry best practice and suited for implementation by an sme.
This 25 page word template and 7 excel templates including a threats matrix risk assessment controls identification and authentication controls controls status access control lists contingency planning controls and an application inventory form.