System Security Plan
Read-only view of the SSP boundary scoping and authored sections.
Authorization Boundary Statement
The NEIS authorization boundary comprises NWD-FS01, NWD-ERP01, eleven engineering workstations, the Entra ID tenant and the perimeter gateway. CUI is stored only on the engineering share and transmitted only through the gateway. The shop-floor kiosk and the corporate finance systems are outside the boundary and do not process CUI.
System Identification
- Organization
- Northwind Defense Components, LLC
- System Name
- Northwind Engineering Information System (NEIS)
- System Description
- Engineering file share, ERP and eleven CAD workstations processing CUI drawings for machined aerospace components under DFARS 252.204-7012 flow-downs.
System Personnel
- System Owner
- Dana Whitfield, Director of Engineering (fictional)
- dana.whitfield@northwind-defense.example
- ISSO
- Marcus Oyelaran, IT Lead (fictional)
- marcus.oyelaran@northwind-defense.example
CUI Categories In Scope
External Service Providers (2)
1 inherited control
CUI types: CUI (encrypted)
0 inherited controls
CUI types: Work orders
Network & Boundary Narrative
Scoped 2026-03 with the boundary diagram NWD-BD-2026-03 rev C.
Authored SSP Sections
5/5 completed[SSP] System Identification
The Northwind Engineering Information System (NEIS) processes CUI drawings and specifications received under DFARS 252.204-7012 flow-downs for machined aerospace components. System owner: the Director of Engineering. ISSO: the IT Lead, with a second designate in training.
[SSP] System Boundary and Scope
The boundary comprises one file server (NWD-FS01), the ERP application server, eleven engineering workstations, the Entra ID tenant and the perimeter gateway. The shop-floor kiosk is out of scope by policy: no CUI is opened on it, and the policy is enforced by share permissions. The conference-room camera is a specialized asset.
[SSP] Operating Environment
On-premises Windows Server 2025 and Windows 11 with Entra ID for identity. Backups go to an off-site encrypted target (see POA&M for 3.13.11). Remote access is via the gateway with MFA; vendor maintenance access is being moved behind the bastion (POA&M for 3.1.12 and 3.13.1).
[SSP] Boundary Diagram
Diagram NWD-BD-2026-03 (rev C) is attached to the assessment package. It shows the CUI share, the workstations, the identity plane and the two egress paths.
[SSP] Monitoring Architecture
Weekly hardening validation of every in-boundary host with results written to a signed chain; firewall and identity logs forwarded to the workspace; correlation rules for break-glass sign-in, log clearing and new services. Endpoint telemetry forwarding is a POA&M item (3.14.6).