System security plan¶
Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.
- Project / nonsensitive identifier: [fill in]
- Prepared by / accountable owner: [fill in]
- Version / date / next review: [fill in]
- Classification and agreement references: [fill in]
- Approved evidence location: [fill in]
Scope and system inventory¶
- Purpose, dataset versions, and permitted users: [fill in]
- Explicit exclusions and prohibited destinations: [fill in]
- CyVerse zone/collection and operator: [fill in]
- VM provider, region, instance, host administrators: [fill in]
- Container image digest, package manifest, update owner: [fill in]
- Identity services, transfer clients, and key service: [fill in]
- Plaintext boundaries and dependencies: [fill in]
Control implementation register¶
| Requirement / source | Control and layer | Owner | Supported evidence | Configured evidence | Verified test/date | Approved scope/date | Gap / action |
|---|---|---|---|---|---|---|---|
| Authentication / MFA | |||||||
| Access / administrators | |||||||
| Encryption / keys | |||||||
| Storage / replicas | |||||||
| Compute / patches | |||||||
| Network / egress | |||||||
| Logging / incidents | |||||||
| Retention / outputs |
- Reassessment cadence and triggers: [fill in]
- Links to data flow, key plan, access register, and incident plan: [fill in]
Review and authorization¶
- Unresolved controls / remediation owner / due date: [fill in]
- Exceptions, approving authority, scope, and expiry: [fill in]
- Custodian decision / date / evidence reference: [fill in]
- Institutional decision / date / evidence reference: [fill in]
- Provider confirmation references: [fill in]
- Material changes requiring revalidation: [fill in]
For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.