System Security and Privacy Plans PL-2
Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PL-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PL-2 (System Security and Privacy Plans) requires a written System Security Plan (SSP) that defines the system's authorization boundary and purpose, the controls chosen and how they are tailored, and who approved it. It is the master document an assessor reads first, and it carries into the Moderate baseline.
What good looks like
- Define the authorization boundary — exactly what is inside the system and what is not.
- Describe the system's purpose, its operating environment, and how it connects to other systems.
- List the selected controls and document any tailoring, each with a plain rationale.
- Have the plan reviewed, dated, and approved by an authorizing official, and keep it current as the system changes.
Framework mapping
- NIST CSF 2.0 — GV.OC-05 — The system's role, dependencies, and boundary are documented and understood
How to move it toward Implemented
- Much of the raw material exists but is not yet a plan: the runbook describes VM 607 (Ubuntu 26.04, DVWA (Damn Vulnerable Web Application) on :8080) and its four-pillar controls, the as-built capture records the live configuration, and the README states the boundary and roles.
- Fold that into a formal SSP that adds what is missing — a stated authorization boundary, the control set with tailoring decisions, the FIPS 199 (Federal Information Processing Standards Publication 199) Moderate categorization, effective dates, and a named approver.
- Cross-reference each implemented control's evidence (auditd, UFW (Uncomplicated Firewall), Fail2Ban, AIDE (Advanced Intrusion Detection Environment), Lynis) from the SSP so the plan and the as-built agree.
- Get the SSP reviewed and signed, then attach it as evidence naming PL-2 to move it from 'Partial' toward 'Completed'.