SSP Generation

Complinist generates professional System Security Plans (SSPs) compliant with NIST SP 800-53 Revision 5. This guide explains how to create your SSP.

Overview

The SSP Generator creates PDF documents that include:

  • System information and description
  • Authorization boundary diagram
  • Security control implementations
  • Hardware and software inventory
  • Network topology diagrams
  • Control narratives for all applicable controls

Prerequisites

Before generating an SSP, ensure you have:

  1. A project with topology - Your network diagram should be complete
  2. Baseline selected - LOW, MODERATE, or HIGH
  3. Control narratives - At least key controls should have implementations
  4. Device inventory - Devices should have relevant properties filled in

Step 1: Access the SSP Wizard

  1. Open your project
  2. Click SSP in the top navigation bar
  3. The SSP wizard will open

Step 2: System Information

Fill in the required system information:

Basic Information

FieldDescriptionExample
System NameOfficial name of your system"Enterprise Resource Management System"
System AcronymShort identifier"ERMS"
System VersionCurrent version"2.1.0"

System Description

Provide a comprehensive description including:

  • System purpose and mission
  • Key functionality
  • User base
  • Data types processed

System Categorization

FieldDescription
Impact LevelLOW, MODERATE, or HIGH
ConfidentialityImpact level for confidentiality
IntegrityImpact level for integrity
AvailabilityImpact level for availability

Step 3: Organizational Information

System Owner

Enter the system owner's name, title, organization, email, and phone.

Authorizing Official

Enter the AO's name, title, and organization.

Information System Security Officer (ISSO)

Enter the ISSO's name, title, and email.

Step 4: Authorization Boundary

Define what's included in your authorization:

Boundary Description

Describe the authorization boundary including:

  • What systems/components are included
  • What is explicitly excluded
  • External connections and interfaces

Boundary Diagram

Your topology diagram will be included automatically. Ensure:

  • All components within the boundary are shown
  • External interfaces are clearly marked
  • Security zones are defined with boundaries

Step 5: Review Control Narratives

The wizard shows all controls applicable to your baseline:

Control Families

  • AC - Access Control
  • AU - Audit and Accountability
  • AT - Awareness and Training
  • CM - Configuration Management
  • CP - Contingency Planning
  • IA - Identification and Authentication
  • IR - Incident Response
  • MA - Maintenance
  • MP - Media Protection
  • PE - Physical and Environmental Protection
  • PL - Planning
  • PS - Personnel Security
  • RA - Risk Assessment
  • CA - Security Assessment and Authorization
  • SC - System and Communications Protection
  • SI - System and Information Integrity
  • SA - System and Services Acquisition
  • SR - Supply Chain Risk Management

For each control, you can view the requirement, review your implementation narrative, edit narratives, and link controls to specific devices.

See Control Narratives for detailed guidance.

Step 6: Hardware/Software Inventory

Review the automatically generated inventory from your topology devices. See Device Inventory for managing inventory.

Step 7: Generate PDF

  1. Review all sections in the wizard
  2. Click Generate PDF
  3. Choose save location
  4. Wait for generation

PDF Contents

The generated SSP includes:

  1. Cover page
  2. Table of contents
  3. Executive summary
  4. System identification
  5. System description
  6. Authorization boundary (with diagram)
  7. System architecture
  8. Hardware inventory
  9. Software inventory
  10. Network diagram
  11. Security controls (all applicable controls with narratives)
  12. Appendices

Security Baselines

LOW Baseline (~50 controls)

For systems where loss would have limited adverse effect: minor financial loss, minor mission impact, no harm to individuals.

MODERATE Baseline (~140 controls)

For systems where loss would have serious adverse effect: significant financial loss, significant mission impact, significant harm to individuals.

HIGH Baseline (~200+ controls)

For systems where loss would have severe or catastrophic effect: major financial loss, major mission impact, loss of life or serious injury.

Best Practices

Before Generating

  1. Complete your topology - Include all system components
  2. Write control narratives - At least for key controls
  3. Fill device properties - IP addresses, hostnames, etc.
  4. Define boundaries - Show security zones clearly

Control Narratives

  1. Be specific - Reference your actual systems and processes
  2. Include device names - "Firewall FW-01 enforces..."
  3. Describe implementation - How you meet the control, not just that you do
  4. Note inherited controls - If controls are provided by a cloud provider

Compliance Mapping

FrameworkSupport
NIST SP 800-53 Rev 5Full support (all 20 families)
FedRAMPExport-ready format
RMF/ATOPDF export for RMF authorization packages
StateRAMPCompatible format

Troubleshooting

PDF Generation Fails

  • Check that all required fields are filled
  • Ensure topology has at least one device
  • Try with a smaller project to identify issues

Missing Controls

  • Verify your baseline selection
  • Some controls may not apply to your system
  • Check if controls are marked as "Not Applicable"

Diagram Not Appearing

  • Ensure topology has devices
  • Check that devices are within view bounds
  • Try regenerating after saving project

Next Steps

After generating your SSP:

  1. Review the PDF - Check for accuracy and completeness
  2. Get stakeholder review - Have ISSO and AO review
  3. Update as needed - Revise narratives based on feedback
  4. Regenerate - Create new PDF with updates
  5. Submit for authorization - Include in your ATO package