PlumbTrackLive demoGRC Risk System

← internal audit

Audit — PL-2 — System Security and Privacy Plans

Framework: NIST SP 800-53 Rev.5 PL-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Confirm a current, approved System Security and Privacy Plan (SSP) exists for the system and that it explicitly defines the authorization boundary and enumerates all constituent components (hardware, software, network segments, external interfaces, and data flows), consistent with the authoritative asset inventory (CIS Controls v8 Controls 1 and 2).
Examine Verify the SSP identifies the information types processed, stored, and transmitted and documents the security categorization (FIPS 199 confidentiality/integrity/availability impact levels) together with the supporting rationale and any privacy impact determination.
Examine Verify the SSP describes the operational/mission context and provides an overview of the security and privacy requirements, mapping each to the controls that are in place or planned, including tailoring decisions and controls inherited as common/shared controls.
Interview Interview the system owner and Information System Security Officer (ISSO)/privacy officer to confirm the individuals named for the security and privacy roles in the plan are actually assigned, current, and understand the responsibilities the plan attributes to them.
Examine Verify the SSP was reviewed and formally approved by the authorizing official (or designated approving authority) prior to system operation, evidenced by a dated approval/signature, and that approved copies were distributed to the personnel and roles identified in the plan.
Test Confirm the plan is reviewed at the organization-defined frequency and updated to reflect changes to the system, its environment of operation, or problems identified during assessments/incidents, by comparing the version history/change log against the defined review cadence and recent significant changes.
Test Observe that the SSP repository enforces least-privilege access so the plan is protected from unauthorized disclosure and modification, confirming only authorized personnel can view or edit it and that access is logged (CIS Controls v8 Controls 3 and 6).