Pattern-Library

System Security Plan (SSP)

OSCAL Model: System Security Plan

The System Security Plan (SSP) model documents the system’s security posture, including the system’s authorization boundary, architecture, data flows, and detailed descriptions of how each control is implemented.

About the Summit System

Summit is a fictitious cloud-based information system operated by Oscalate Systems. It is hosted in AWS and provides a public-facing web application consisting of a static front end with an API backend that serves public customers.

Key characteristics:

View the SSP

View the Summit SSP interactively using the OSCAL Viewer:

View Summit SSP in OSCAL Viewer

System Diagrams

Technical Architecture

Summit Technical Architecture

Authorization Boundary

Summit Authorization Boundary

What Belongs Here

Key Concepts

OSCAL Reference