Documents how the system protects information at rest and in transit, partitions trust, defends boundaries, manages cryptographic key material, secures DNS / certificate / session integrity, and provides architectural protections (process isolation, DoS resilience, mobile-code containment). Covers the controls of the SC family in NIST SP 800-53 r5 and aligns with NIST SP 800-52 r2 (TLS), NIST SP 800-57 (Key Management), NIST SP 800-77 r1 (IPsec VPNs), NIST SP 800-95 (Web Services Security), FIPS 140-3 (Cryptographic Module Validation), and FIPS 199 / FIPS 200.
Public site — unclassified data only.
Do not enter classified, CUI, or other sensitive non-public information into this plan. Use placeholders for sensitive content and complete those fields on an authorized system within the appropriate enclave.