Skip to main content

PL-2 System Security Plan

Description

The university (Chief Information Security Officer) develops and implements a security plan that provides an overview of the security requirements and a description of the security controls in place or planned for meeting those requirements.

Applicability

  • This Control is intended to apply to the university as a whole with the Department of Information Resources’ “Agency Security Plan” being the “plan” indicated in this Control. (The template for this Plan is provided by the Texas Department of Information Resources (DIR) in SPECTRIM). The university’s Chief Information Security Officer has the primary responsibility for the implementation of this Control.
  • However, all units in the university should make and execute security plans for the information resources they manage. These “plans” should be based on the results of risk assessments (e.g., risk management decisions and risk mitigation plans such as those provided in SPECTRIM).

Implementation

  • 1The Chief Information Security Officer shall develop a security plan for information systems that:

    • 1.1is consistent with the university’s enterprise architecture;

    • 1.2explicitly defines the authorization boundary for the system;

    • 1.3describes the operational context of the information system in terms of missions and business processes;

    • 1.4provides the security categorization of the information system including supporting rationale (see Control RA-2, Security Categorization);

    • 1.5describes the operational environment for the information systems and relationships with or connections to other university information systems;

    • 1.6provides an overview of the security requirements for the systems;

    • 1.7identifies any relevant overlays, if applicable;

      tip

      Overlay/Tailoring description: The university may initiate a tailoring process to modify and align security controls more closely with the specific conditions within the university. This tailoring can include a variety of enhanced guidance (or overlays) for security controls that are specific to the university.

    • 1.8describes the security controls in place or planned for meeting requirements, including rationale for the tailoring and supplementation decisions; and

    • 1.9is reviewed and approved by the appropriate personnel prior to plan implementation.

  • 2The Chief Information Security Officer shall:

    • 2.1distribute copies of the security plan and communicate changes to the plan as appropriate to authorized individuals;
    • 2.2review the security plan for the information systems biennially and submit report to DIR;
    • 2.3update the plan to address changes to the information system, environment of operation, or issues identified during plan implementation or security control assessments; and
    • 2.4protect the security plan from unauthorized disclosure and modification.