Skip to content

System security plan

Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.

  • Project / nonsensitive identifier: [fill in]
  • Prepared by / accountable owner: [fill in]
  • Version / date / next review: [fill in]
  • Classification and agreement references: [fill in]
  • Approved evidence location: [fill in]

Scope and system inventory

  • Purpose, dataset versions, and permitted users: [fill in]
  • Explicit exclusions and prohibited destinations: [fill in]
  • CyVerse zone/collection and operator: [fill in]
  • VM provider, region, instance, host administrators: [fill in]
  • Container image digest, package manifest, update owner: [fill in]
  • Identity services, transfer clients, and key service: [fill in]
  • Plaintext boundaries and dependencies: [fill in]

Control implementation register

Requirement / source Control and layer Owner Supported evidence Configured evidence Verified test/date Approved scope/date Gap / action
Authentication / MFA
Access / administrators
Encryption / keys
Storage / replicas
Compute / patches
Network / egress
Logging / incidents
Retention / outputs
  • Reassessment cadence and triggers: [fill in]
  • Links to data flow, key plan, access register, and incident plan: [fill in]

Review and authorization

  • Unresolved controls / remediation owner / due date: [fill in]
  • Exceptions, approving authority, scope, and expiry: [fill in]
  • Custodian decision / date / evidence reference: [fill in]
  • Institutional decision / date / evidence reference: [fill in]
  • Provider confirmation references: [fill in]
  • Material changes requiring revalidation: [fill in]

For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.