- System name, owner, and purpose
- Scope and boundary: what is in, what is out, and why
- Network diagram, matching the running network, dated
- Asset inventory: in-scope systems, security protection assets
- Data flows for Specified Information: arrive, rest, work, leave, echo
- Roles and responsibilities, including MSP and cloud, with the shared responsibility matrix attached
- Control implementation, requirement by requirement from the index: how, where, evidence location
- Open items: reference to the remediation register (plan of action and milestones)
- Change log and review triggers
// CPCSC TEMPLATES · 14 OF 14
System security plan outline
Last verified: 2026-10-05
The document the assessment orbits. Satisfies 03.15.02 when the contents are true. Aim for accurate over long.
Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.