Sample documents

What the paperwork looks like

Everything on this page was made for a made-up shop. It is not a client, and nothing here comes from a client.

System Security Plan

Inside the System Security Plan

Two requirements from a sample System Security Plan, marked up to show what each part does.

System Security Plan · Excerpt

Example Machine Co. · Sample

The requirement

Copied word for word from NIST SP 800-171 Revision 2.

3.1 Access control

3.1.1

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Source: NIST SP 800-171 Rev. 2, page 10 Implemented

How your shop does it

In plain words, about your shop. Not copied from a template.

Who does it

The right-hand column: you, your people, or your IT provider. We write it down; we don’t do the IT.

How Example Machine Co. meets it

What happensWho
Everyone who uses the file server, the two CAM PCs or the quality-room PC signs in with their own account. No shared sign-ins.IT provider
Each new account is approved in writing.Owner
Accounts are created, and removed the day someone leaves.IT provider
The list of who can use which computer is kept and checked against the staff list every quarter.Office manager
Backup software runs under its own account.IT provider
Only computers on the shop’s approved list can join the shop network. Visitors use a separate guest Wi-Fi.IT provider

Where the proof is

Each line points to an item in the binder: E-1 is tab E, item 1. When someone asks, you know where to look.

Proof in the binder

  • E-1 Access policy
  • F-1 Access list, with the quarterly checks
  • F-2 Account requests signed by the owner
  • F-3 Approved device list from the IT provider

Every requirement

Gets the same four parts: the rule, how your shop does it, who does it, and where the proof is.

3.8 Media protection

3.8.7

Control the use of removable media on system components.

Source: NIST SP 800-171 Rev. 2, page 30 Implemented

How Example Machine Co. meets it

Programs reach most machines over the shop network from the CAM PCs. Two older machines only take programs by USB.

What happensWho
No personal USB drives on any shop computer or machine.Owner
USB drives are blocked on every office and CAM PC, except the shop’s own two drives on one CAM PC.IT provider
The shop’s two drives are labelled with the shop’s name and a number.Lead programmer
The drives are kept in a locked drawer and signed in and out on a log.Lead programmer

Proof in the binder

  • E-2 Removable media policy
  • F-4 USB settings report from the IT provider
  • F-5 Sign-out log for the two drives

Sample. Made-up shop, not a client.

Requirement text: NIST SP 800-171 Revision 2

The binder

Where it sits in the binder

The full write-up comes as a printed binder, one tab for each part. The proof references above point into tabs E and F.

Drawing of the sample binder taken apart: the cover, and six tabbed sections, A to F, lifted off the rings. The top section shows a small scope map. EXAMPLE MACHINE CO. SAMPLE BINDER Sample. Made-up shop, not a client. SCOPE MAP · SAMPLE A B C D E F SAMPLE BINDER · EXAMPLE MACHINE CO. DRAWN BY NEXXUS ADVISORY
Sample. Made-up shop, not a client.
What’s behind each tab
TabSectionIn this sample
AScope mapNot in this sample
BSystem Security PlanTwo requirements, shown above
CScore worksheetNot in this sample
DPlan of actionNot in this sample
EPoliciesNot in this sample
FEvidenceNot in this sample

The score worksheet and plan of action aren’t shown. They carry a score, and we don’t publish scores, even made-up ones.

Contact

Talk to us

Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.

We don’t record calls.

Please don’t send drawings, contracts, or controlled information by email or through this site.