sha3:0e4262ee7f5180e6e7a852a86bf3484e0c764ed12e301d1b4842ff1317ba2232Intact71d69f454167d8fd04a8d4a5ba80c11a4e1dd4ddf57a3f59e8e461187fe35639prev:d8ccc3b5206fRegisterGlossary
What is SSP?
An SSP is the document describing how an organization implements each required security control across its in-scope environment.
def573b10d342cc4f1a20a856cb25887c84cd62899d60bb1617c1372a20cf977prev:71d69f454167SSP stands for System Security Plan.
The System Security Plan (SSP) documents your system boundary, the CUI data flows within it, and how each of the 110 NIST 800-171 controls is implemented. It is the central artifact a C3PAO reviews.
Assessors consistently report that documentation gaps — an SSP that does not match the live environment — drive more failed assessments than missing technical controls. SSPs commonly run to hundreds of pages.
Keeping the SSP true to a continuously changing cloud environment is the core challenge; automated evidence generation exists to close the gap between what the SSP claims and what the environment actually does.
0e4262ee7f5180e6e7a852a86bf3484e0c764ed12e301d1b4842ff1317ba2232prev:def573b10d34Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended
- Unchanged since sealing