# System Security Plan Working Outline

> Use this as a working outline. Replace every placeholder section with system-specific information and align it to the current contractual / assessment baseline.

## 1. System identification
- System / enclave name:
- Business owner:
- Technical owner:
- Security owner:
- Locations:
- Contract / opportunity references:
- Information types handled (FCI / CUI category):
- Current CMMC / assessment identifiers:

## 2. System purpose
Describe what contract work the environment supports and what users do inside it.

## 3. Authorization boundary
Describe the exact boundary. Reference a versioned network diagram and data-flow diagram.

## 4. Asset inventory
Link to the controlled inventory. Identify CUI assets, security protection assets, specialized assets, and relevant external services.

## 5. Data flow
Document how FCI/CUI enters, moves, is stored, is shared, is backed up, and is destroyed.

## 6. External connections and service providers
For each provider, record service, data handled, administrative access, security responsibilities, incident obligations, and evidence.

## 7. Identity and privileged administration
Describe identity sources, MFA, privileged roles, remote administration, joiner/mover/leaver process, and access reviews.

## 8. Requirement implementation
For each applicable requirement:
- Requirement ID
- Implementation statement
- Responsible owner
- System/component
- Evidence index references
- Review / refresh trigger
- Known limitation or approved POA&M reference if applicable

## 9. Incident response and reporting
Describe detection, internal escalation, government reporting responsibilities where applicable, evidence preservation, and provider coordination.

## 10. Configuration, vulnerability, and patch management
Describe baselines, change control, scanning, remediation, exceptions, and evidence.

## 11. Backup and recovery
Describe protected data copies, providers, encryption, access, restoration paths, and restore testing.

## 12. Physical and media protection
Describe facilities, remote work, printing, removable media, storage, transport, sanitization, and disposal.

## 13. Continuous maintenance
List change events that trigger SSP review. Record the last review date, approver, and next scheduled review.
