Attachment 6 - NIST SP 800-171 System Security Plan Template.docx
DOCX document 20 KB Posted
- Attached to
- SPE2DX-20-R-0001 SOLICITATION Federal contract opportunity
- Solicitation number
- SPE2DX-20-R-0001_SOLICITATION
About this file
This document contains a system security plan template for meeting NIST SP 800-171 requirements on federal contracts. The template requests information on covered systems, vendors, hardware and software components, users, and a plan for responding to and reporting cyber incidents. An attachment is referenced for the NIST SP 800-171 assessment summary and hardware component list. Additionally, the related federal contract opportunity is for the National Prime Vendor Generation IV solicitation from the Defense Logistics Agency Troop Support Medical seeking unspecified products or services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation SPE2DX20R0001 Final 6.3.2021.pdf | ||
| Attachment 9 - NIST.SP.800-171(r2) Publication.pdf | ||
| Solicitation SPE2DX20R0001 eprocurement.pdf | ||
| Attachment 1 - NPV GEN-IV Day-to-Day.xlsx | XLSX spreadsheet | |
| Attachment 2 - NPV GEN-IV WRM.xlsx | XLSX spreadsheet | |
| Attachment 5 - NPV GEN III FY19 Sales by NDC.xlsx | XLSX spreadsheet | |
| Attachment 7 - NIST SP 800-171 Assessment Summary (final5-13-21).xlsx | XLSX spreadsheet | |
| Attachment 8 - NIST SP 800-171 Assessment Methodology.pdf | ||
| Attachment 3 - NPV GEN-IV Specialty List.xlsx | XLSX spreadsheet | |
| Attachment 4 - NPV GEN-IV Discrepancy Report Template.XLSX | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SYSTEM SECURITY PLAN - company name
DATE: XX/XX/XX
1. INFORMATION TECHNOLOGY INFRASTRUCTURE
1.1. Covered System(s) Name: [Provide a list of covered systems. Spell out acronyms.]
1.2. Vendor System Owner (assignment of security responsibility):
Name:
Title:
Office Address:
Work Phone:
e-Mail Address:
1.3. General Description/Purpose of System(s):
1.4. List all vendor Information Technology systems required to perform the requirements of the contract and their purpose [Provide a short, high-level description of the function/purpose of the system(s). Add rows or tables as needed if there are multiple systems]
1.4.1. Number of end users and privileged users: [In the table below, provide the approximate number of users and administrators of the system. Include all those with privileged access such as system administrators, database administrators, application administrators, etc. Add rows to define different roles as needed.]
Roles of Users and Number of Each Type:
| Number of Users |
| Number of Administrators/ |
Privileged Users
1.5. For each system, include a high-level listing of all hardware and software (system software and application software) components, including make/OEM, model, version, service packs, and person or role responsible for the component. This does not require identifying every workstation or device, but including the types/model each kind of hardware, operating system in use, an type/model of portable components (if applicable), all virtual and physical servers (e.g., file, print, web, database, application), as well as any networked workstations (e.g., Unix, Windows, Mac, Linux), firewalls, routers, switches, copiers, printers, lab equipment, handhelds. [If providing as an attachment, insert the reference or note that the hardware component list is attached. A system topology graphic can be used but would require a narrative consistent with the graphic that clearly lists and describes each system component.]
1.6. Hardware and Software Maintenance and Ownership - Is all hardware and software maintained and owned by the organization? [Yes/No - If no, explain:]
2. NIST REQUIREMENTS
Provide a thorough description of how all 110 NIST SP 800-171 requirements are being met or are planned to be met in the future using the NIST SP 800-171 Assessment Summary spreadsheet.
[Ensure that the Assessment Summary is fully completed and attached along with the System Security Plan.]
3. CYBER INCIDENT RESPONSE AND REPORTING
Provide a plan for responding to Cyber incidents and reporting such incidents.
File details come from the government source that posted it. Updated .