Skip to main content
◢ Course

Writing a System Security Plan

Build the document a federal authorisation actually turns on

Intermediate

Level

12

Modules

31

Lessons

12

Graded quizzes

1

Assignments

30 hours

Estimated time

What you will be able to do

  • Explain what an SSP is for, and why it is a decision document rather than a form
  • Categorise a system from its information types and apply the high water mark
  • Draw and defend an authorisation boundary, including the awkward third-party cases
  • Write control implementation statements an assessor can actually test
  • Produce the operational plans behind the controls, and know what their tests must show
  • Assemble the full appendix set and say honestly what is present, partial or missing
  • Keep a plan alive through change, using impact analysis and continuous monitoring
  • Read somebody else's SSP the way an assessor reads it

What is inside

12 modules, 31 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    What an SSP is, and the decision it supports

    The System Security Plan as a decision document rather than a form. Who reads it and what each reader needs from it, and the five ways plans fail before anyone assesses them.

    3 lessons · 6 quiz questions

  2. 02

    Before you write: categorisation, boundary and privacy

    The three decisions that have to be right before a word of the plan is written. Information types and the high water mark, where the authorisation boundary sits and why, and the privacy chain that can stop an authorisation outright.

    3 lessons · 6 quiz questions

  3. 03

    System information, roles, and who signs

    The front matter that looks administrative and is not. Getting the system type right because inheritance depends on it, writing a description a stranger can use, and the five roles with the separation that makes assurance possible.

    2 lessons · 5 quiz questions

  4. 04

    Describing the system: architecture, ports, cryptography and duties

    The body sections that describe how the system actually works. Writing a narrative that makes a diagram testable, justifying every open port, treating data at rest and in transit as separate problems, and stating separation of duties honestly when the team is small.

    4 lessons · 5 quiz questions

  5. 05

    What you inherit, and what you depend on

    The two sections that decide how much work you actually have. Inheriting controls from an authorised platform without creating false assurance, splitting hybrid controls precisely, and disclosing the dependencies that hold no authorisation at all.

    2 lessons · 4 quiz questions

  6. 06

    Appendix A: writing control implementation statements

    The largest part of the plan and the part that gets tested. Reading a control as a list of clauses, writing statements with a verifiable artefact, matching evidence to the assessment method, and why honest partials buy credibility everywhere else.

    4 lessons · 6 quiz questions

  7. 07

    The operational plans: contingency, incident response, configuration

    The three plans that live behind the controls and get tested rather than read. Activation criteria and the analysis that makes recovery targets defensible, the reporting clock that starts before you know anything, and the impact analysis that must come before the change.

    3 lessons · 5 quiz questions

  8. 08

    The inventory and the shared responsibility matrix

    The two workbooks that look like housekeeping and are not. Why a missing inventory entry becomes an invisible gap in scanning, patching and recovery, and why 'shared' without a precise split is the same as unassigned.

    2 lessons · 4 quiz questions

  9. 09

    The governance appendices

    The appendices that carry authority rather than technical detail. Why one line in the list is really twenty documents, the difference between a policy and a procedure and why each is weak alone, and the acknowledgement record that is the actual control.

    2 lessons · 4 quiz questions

  10. 10

    Keeping the plan alive

    What happens after the signature. Monitoring that runs on triggers as well as a calendar, a POA&M read for its dates rather than its findings, and the three mechanisms that keep a plan describing the system that actually exists.

    3 lessons · 5 quiz questions

  11. 11

    Reading someone else's SSP

    The reviewer's view. How an assessor forms a judgement by sampling rather than reading, what one visible inaccuracy costs across the whole document, and ten questions that find the gaps, including on your own work.

    2 lessons · 4 quiz questions

  12. 12

    Capstone: a complete plan

    Finish the document. The body in full, an honest inventory of all seventeen appendices, three appendices developed properly, and a closing page naming the weakest part of your own work.

    1 lessons · 3 quiz questions · assignment