# System security plan — Security Protection Assets

STARTER TEMPLATE. Replace every bracket. Not a completed plan. Not legal advice. Not an assessment.

32 CFR § 170.19 Table 3 says the organization documents Security Protection Assets in the asset inventory, documents their treatment in the system security plan, and documents them on the network diagram of the assessment scope. The DoD CMMC Scoping Guide — Level 2 says there is no requirement to embed each asset in the plan. Point to the inventory instead of pasting it here.

This section is for assets that provide security functions or capabilities and do not process, store, or transmit CUI. If an asset does handle CUI, do not leave it only in this section. Treat it as a CUI asset, and if an external cloud holds that CUI, follow DFARS 252.204-7012 and Table 4.

## 1. Purpose of this section

This section describes how [organization] treats Security Protection Assets in the Level 2 assessment scope for [system name].

The asset inventory is [file or system of record]. The network diagram is [diagram title and date].

## 2. What counts as an SPA in this system

[Describe the security functions in scope. Examples of functions, not of products: central logging, endpoint detection, vulnerability scanning, identity for in-scope systems, device management, hosted VPN, managed detection.]

An asset is listed as an SPA in the inventory only when it does not process, store, or transmit CUI. The basis for that statement is [how you checked: data types reviewed, vendor answers, configuration that blocks content].

## 3. Security protection data

Security protection data in this system includes [configuration, logs, vulnerability status, credentials that grant access, or other categories you actually have].

The following were checked and are not CUI, or are kept out of these assets: [state the check]. If a log line or a tenant later contains CUI, that asset leaves this section.

Locations, including backups and longer-term log storage: [list, matching the inventory].

## 4. External providers

For each external provider that handles security protection data or operates a security function:

- Provider and service: [name]
- Cloud service provider, or not: [which, and why]
- CUI in the service: [no, with the basis]
- Service description: [document title]
- Customer responsibility matrix: [document title and date]
- Agreement that covers incident notice, data location, and return of data: [document title]

Table 4 of § 170.19 assesses security protection data without CUI as Security Protection Assets. This section does not claim a FedRAMP authorization for that case.

## 5. People

Roles that administer these assets, including provider personnel if they have access: [roles, not personal names unless your plan standard includes them].

Vendor access is [standing, or granted per request]. Customer administrators are [how they are separated, if they are].

## 6. Requirements relevant to the capabilities

SPAs are assessed against Level 2 security requirements relevant to the capabilities provided, not automatically against every Level 2 requirement.

| Capability | Where it is implemented | Who configures it | Who reviews it | Evidence location |
| --- | --- | --- | --- | --- |
| [Example row — logging. Delete or replace.] | [control] | [customer or provider] | [role] | [ticket, export, or procedure] |

## 7. Open items

- [ ] Inventory matches this section
- [ ] Diagram matches the data-flow table
- [ ] Each external provider has a current responsibility matrix
- [ ] CUI check repeated after the last change to log content or retention
