Attachment-G10-ACF_System Security Plan_V1.0.docx
DOCX document 111 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
Summary of Attachment G10: ACF System Security Plan V1.0
This document is a System Security Plan (SSP) template for the Administration for Children and Families (ACF) that outlines security requirements and implementation measures for federal information systems. The SSP serves as a foundational security documentation artifact within the Authority to Operate (ATO) package and establishes the security posture for systems processing, storing, or transmitting ACF data. The template requires completion of system identification details, FIPS 199 security categorization assessments (confidentiality, integrity, and availability ratings), system description and operational status, accreditation boundary diagrams, and multifactor authentication implementation details. It mandates documentation of internal and external system interconnections with responsible organizations, types of interconnections, agreement types, and security authorization status for each connection.
The SSP template requires linking to comprehensive NIST SP 800-53 Revision 5 security control implementation spreadsheets tailored to the system's identified categorization level, as well as risk assessment documentation covering management, operational, and technical control-related risks. Organizations must establish continuous monitoring activities and frequencies to maintain systems in accordance with approved baseline configurations. The document designates specific roles and responsibilities including the System Owner, Authorizing Official (Robin Collins, Chief Information Officer, ACF Office of the CIO, robin.collins@acf.hhs.gov, 202-401-6501), and other technical and operational points of contact. The SSP requires digital signatures from both the System Owner and System Security and Privacy Officer for approval and authorization, with a document revision history tracking mechanism. This is a template document designed to be completed for individual ACF systems undergoing security authorization.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
System Security Plan System Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 2 |
| 2. System Identification | 2 |
| 3. System Categorization | 2 |
| 3.1 System Categorization | 2 |
| 3.2 Information Types | 3 |
| 4. System Description | 3 |
| 4.1 System Purpose | 3 |
| 4.2 System Type & Operational Status | 3 |
| 4.4 Accreditation Boundary | 3 |
| 4.5 Operating Environment | 4 |
| 4.6 Multifactor implementation | 4 |
| 5. Interconnections | 4 |
| 5.1 Internal System Connections | 4 |
| 5.2 External System Connections | 5 |
| 6. Security Control Implementation | 5 |
| 7. Risk Summary | 5 |
| 7.1 Management Controls | 5 |
| 7.2 Operational Controls | 5 |
| 7.3 Technical Controls | 6 |
| 8. Continuous Monitoring | 6 |
| 8.1 Monitoring frequency: | 6 |
| 8.2 Monitory Activities | 6 |
| 9. Roles and Responsibilities | 7 |
| 9.1 System Owner | 7 |
| 9.2 Authorizing Official | 7 |
| 9.3 Other Points of Contact | 8 |
| 10. Approval and Authorization | 9 |
| Document Revision History | 10 |
1. Introduction and Purpose The System Security Plan (SSP) outlines a system’s security requirements and the measures being implemented to address them. It specifies all users’ roles and expected actions and aims to ensure effective and cost-efficient protection for the system.
2. System Identification Identify the system using its unique identifiers for definition and reference.
Table 1. System Identification Security Identification
| System Name |
| Enter System Name |
| System Acronym |
| Enter System Acronym |
| Unique Identifier (UUID) |
| Enter UUID |
| Web Address |
| Enter Web Address |
3. System Categorization
3.1 System Categorization
In compliance with Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, the system security categorization assessment was made based on the confidentiality, integrity, and availability requirements of the system’s store, processed, and transmitted data.
Table 2. System Security Categorization
Rating
| Confidentiality Rating |
| Select a category |
| Integrity Rating |
| Select a category |
| Availability Rating |
| Select a category |
| Overall Security Categorization |
| Select a category |
3.2 Information Types
Each information type processed, stored, or transmitted by the system has been identified using NIST SP 800-60 and system documentation. Full details can be found in the Security Categorization document in the ATO package.
Enter link to Security Categorization document
4. System Description
4.1 System Purpose
Include a brief description of the function and purpose of the system.
Enter System Purpose
4.2 System Type & Operational Status
Select a system type.
Table 4. System Type & Operational Status System Type & Operational Status
| System Type |
| Select a system type |
| System Operational Status |
| Select operational status |
4.4 Accreditation Boundary
Include an accreditation boundary diagram. Only hardware, software, subsystems, and components relevant to the system’s operation are included within the accreditation boundary. For clarity, the diagram may display other systems or parts the system is connected to but doesn’t control. These include client computers, shared tech resources, support systems, and services provided by the hosting environment.
4.5 Operating Environment
Identify the system’s operating environment.
Table 5. Operating Environment Operating Environment
| System Inventory |
| Enter link |
| System Environment |
| Select an environment |
| Are the system and its components IPv6 enabled? |
| Select an answer |
4.6 Multifactor implementation
Provide details about the multifactor authentication solution(s) in place for each user group.
Enter details
5. Interconnections This section describes the ports, protocols, and services in use within the accreditation boundary and the data or services outside the accreditation boundary.
5.1 Internal System Connections
List connections to other systems or data within ACF. Include systems that are within ACF’s inventory but not included in the accreditation boundary in the SSP.
Table 6. Internal System Connections
| System Name |
| Responsible Organization |
| Type of Interconnection |
| Type of Agreement |
| FIPS-199 Rating |
| Security Authorization |
5.2 External System Connections
List all external interfaces with data paths crossing the accreditation boundary:
Table 7. Internal System Connections
| System Name |
| Responsible Organization |
| Type of Interconnection |
| Type of Agreement |
| FIPS-199 Rating |
| Security Authorization |
6. Security Control Implementation Provide the link to the location of the spreadsheet with the complete set of NIST SP 800-53 Rev. 5 control implementations for this system’s level (established in Section 3 above). The spreadsheet should be maintained alongside the SSP as part of the system’s ATO package.
Insert link to spreadsheet
7. Risk Summary The results of the system Risk Assessment, dated Enter date, indicated that the risks to the system resources in the areas of Management, Operational, and Technical controls are as follows:
7.1 Management Controls
List the most significant management control related risks.
Enter management control related risks
7.2 Operational Controls
List the most significant operational controls related risks.
Enter operational control related risks
7.3 Technical Controls
List the most significant technical control related risks.
Enter technical control risks
Risks in areas such as natural, environmental, human intentional, and human unintentional threats were also assessed. The assessment found that identified risks could be fully mitigated through the implementation of relevant security controls. For more information, view the Security Risk Assessment.
Enter link to Security Risk Assessment
8. Continuous Monitoring The System’s security state is monitored to ensure that the information system is being maintained in accordance with policy and the approved baseline configurations.
8.1 Monitoring frequency:
Provide the frequency at which the system is monitored.
Enter monitoring frequency
8.2 Monitory Activities
Describe the specific activities used to monitor the system.
Enter monitoring activities
9. Roles and Responsibilities
9.1 System Owner
Table 4. System Owner Information
| Name |
| Enter name |
| Title |
| Enter title |
| Organization |
| Administration for Children and Families, |
Enter Program Office
| Address |
| Administration for Children and Families |
U.S. Department of Health and Human Services 330 C. Street, SW Washington, DC 20201
| Enter email |
| Phone |
| Enter phone |
9.2 Authorizing Official
Table 5. Authorizing Official Information
| Name |
| Robin Collins |
| Title |
| Chief Information Officer |
| Organization |
| ACF Office of the CIO |
| Address |
| 330 C St SW, Washington, DC 20201 |
| robin.collins@acf.hhs.gov |
| Phone |
| 202-401-6501 |
9.3 Other Points of Contact
List all individuals who technically and operationally manage and support the system. Add additional rows as needed.
Table 8. Other Points of Contact
| Name |
| Organization |
| Title |
| Address |
| Phone |
10. Approval and Authorization We, the undersigned, approve the content of this System Security Plan for the Administration for Children and Families Enter type of system located at Enter location, including the system boundary, the FIPS 199 Impact Level of Select a level, and the NIST SP 800-53 Rev. 5 security controls as tailored specifically for this system.
Digital Signature – System Owner
Digital Signature – System Security and Privacy Officer
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 System Security Plan 1 image1.png image2.png image3.png
File details come from the government source that posted it. Updated .