Chapter 1
How Do I Describe My System Boundary in the SSP?
Your assessor asks what is in scope, and your diagram does not answer. SSP is short for System Security Plan, the document that describes how your system protects CUI. CUI is Controlled Unclassified Information: government data that is sensitive but not classified. NIST requirement 3.12.4 says to develop, document, and periodically update plans that describe your system boundaries. (NIST source) Its assessment guide checks that the boundary is described and documented in the plan. (assessment guide) NIST SP 800-18 Revision 2 shows what a good boundary description contains. (boundary guide)
Step 1: Name the system and its job.
Write one paragraph: what the system is and what business job it does. Include where it lives: your office, a cloud region, or both.
Step 2: List every component inside the boundary.
List the hardware, software, and firmware that make up the system. Give each item a unique ID, an owner, and a location. Tag the ones that store, process, or transmit CUI.
Step 3: Draw the network and the CUI data flows.
Draw a diagram showing every component and how they connect. Mark the physical and logical separations, like firewalls between office and server networks. Draw a second diagram tracing CUI: where it is created, where it is stored, and where it leaves.
Step 4: Document external connections and inherited controls.
List every connection to the outside: internet providers, cloud services, vendor remote access. For each cloud service, write down which security jobs the provider does and which you do. Name any third-party services and APIs your system depends on.
Step 5: Say what is out of scope, and why.
Name systems you excluded and give the reason for each. An assessor will ask why, so write the answer down now.
Step 6: Set a review date.
Requirement 3.12.4 also says to define how often you update the plan, then actually update it.
What will the assessor check?
The assessment guide lists exact checks for this requirement: - The SSP exists and names the system. - The boundary is described and documented in the SSP. - The environment of operation is described. - Requirements marked not applicable are listed with the decision. - Connections to other systems are documented. - A review frequency is defined, and the plan was updated on that schedule.
Common boundary mistakes
- The diagram and the component list disagree.
- A laptop or phone that touches CUI is missing from the list.
- A SaaS app, or Software as a Service app, holding CUI is not shown as an external connection.
- Inherited cloud controls are not written down, so nobody owns them.
- Out-of-scope systems have no written reason.
- The diagrams are a year old and the network changed.
Sources
- NIST SP 800-171 Revision 2 (PDF): requirement 3.12.4
- NIST SP 800-171A (CSRC): assessment objectives for 3.12.4
- NIST SP 800-18 Revision 2 (PDF): Authorization Boundary Description section
- NIST SP 800-18 Revision 2 publication page (CSRC)
Next step
PolicyCortex reads your live Azure configuration and maps what it finds into evidence for NIST 800-171. A current inventory makes your boundary diagram easy to defend. See what it can collect for you