SSP Generation
Complinist generates professional System Security Plans (SSPs) compliant with NIST SP 800-53 Revision 5. This guide explains how to create your SSP.
Overview
The SSP Generator creates PDF documents that include:
- System information and description
- Authorization boundary diagram
- Security control implementations
- Hardware and software inventory
- Network topology diagrams
- Control narratives for all applicable controls
Prerequisites
Before generating an SSP, ensure you have:
- A project with topology - Your network diagram should be complete
- Baseline selected - LOW, MODERATE, or HIGH
- Control narratives - At least key controls should have implementations
- Device inventory - Devices should have relevant properties filled in
Step 1: Access the SSP Wizard
- Open your project
- Click SSP in the top navigation bar
- The SSP wizard will open
Step 2: System Information
Fill in the required system information:
Basic Information
| Field | Description | Example |
|---|---|---|
| System Name | Official name of your system | "Enterprise Resource Management System" |
| System Acronym | Short identifier | "ERMS" |
| System Version | Current version | "2.1.0" |
System Description
Provide a comprehensive description including:
- System purpose and mission
- Key functionality
- User base
- Data types processed
System Categorization
| Field | Description |
|---|---|
| Impact Level | LOW, MODERATE, or HIGH |
| Confidentiality | Impact level for confidentiality |
| Integrity | Impact level for integrity |
| Availability | Impact level for availability |
Step 3: Organizational Information
System Owner
Enter the system owner's name, title, organization, email, and phone.
Authorizing Official
Enter the AO's name, title, and organization.
Information System Security Officer (ISSO)
Enter the ISSO's name, title, and email.
Step 4: Authorization Boundary
Define what's included in your authorization:
Boundary Description
Describe the authorization boundary including:
- What systems/components are included
- What is explicitly excluded
- External connections and interfaces
Boundary Diagram
Your topology diagram will be included automatically. Ensure:
- All components within the boundary are shown
- External interfaces are clearly marked
- Security zones are defined with boundaries
Step 5: Review Control Narratives
The wizard shows all controls applicable to your baseline:
Control Families
- AC - Access Control
- AU - Audit and Accountability
- AT - Awareness and Training
- CM - Configuration Management
- CP - Contingency Planning
- IA - Identification and Authentication
- IR - Incident Response
- MA - Maintenance
- MP - Media Protection
- PE - Physical and Environmental Protection
- PL - Planning
- PS - Personnel Security
- RA - Risk Assessment
- CA - Security Assessment and Authorization
- SC - System and Communications Protection
- SI - System and Information Integrity
- SA - System and Services Acquisition
- SR - Supply Chain Risk Management
For each control, you can view the requirement, review your implementation narrative, edit narratives, and link controls to specific devices.
See Control Narratives for detailed guidance.
Step 6: Hardware/Software Inventory
Review the automatically generated inventory from your topology devices. See Device Inventory for managing inventory.
Step 7: Generate PDF
- Review all sections in the wizard
- Click Generate PDF
- Choose save location
- Wait for generation
PDF Contents
The generated SSP includes:
- Cover page
- Table of contents
- Executive summary
- System identification
- System description
- Authorization boundary (with diagram)
- System architecture
- Hardware inventory
- Software inventory
- Network diagram
- Security controls (all applicable controls with narratives)
- Appendices
Security Baselines
LOW Baseline (~50 controls)
For systems where loss would have limited adverse effect: minor financial loss, minor mission impact, no harm to individuals.
MODERATE Baseline (~140 controls)
For systems where loss would have serious adverse effect: significant financial loss, significant mission impact, significant harm to individuals.
HIGH Baseline (~200+ controls)
For systems where loss would have severe or catastrophic effect: major financial loss, major mission impact, loss of life or serious injury.
Best Practices
Before Generating
- Complete your topology - Include all system components
- Write control narratives - At least for key controls
- Fill device properties - IP addresses, hostnames, etc.
- Define boundaries - Show security zones clearly
Control Narratives
- Be specific - Reference your actual systems and processes
- Include device names - "Firewall FW-01 enforces..."
- Describe implementation - How you meet the control, not just that you do
- Note inherited controls - If controls are provided by a cloud provider
Compliance Mapping
| Framework | Support |
|---|---|
| NIST SP 800-53 Rev 5 | Full support (all 20 families) |
| FedRAMP | Export-ready format |
| RMF/ATO | PDF export for RMF authorization packages |
| StateRAMP | Compatible format |
Troubleshooting
PDF Generation Fails
- Check that all required fields are filled
- Ensure topology has at least one device
- Try with a smaller project to identify issues
Missing Controls
- Verify your baseline selection
- Some controls may not apply to your system
- Check if controls are marked as "Not Applicable"
Diagram Not Appearing
- Ensure topology has devices
- Check that devices are within view bounds
- Try regenerating after saving project
Next Steps
After generating your SSP:
- Review the PDF - Check for accuracy and completeness
- Get stakeholder review - Have ISSO and AO review
- Update as needed - Revise narratives based on feedback
- Regenerate - Create new PDF with updates
- Submit for authorization - Include in your ATO package