Body of Evidence & Artifacts
What each phase produces, who owns the work, and how the records stay current.
Find the source documents in Compliance.
NIST preparation · added in SP 800-37 Rev. 2
Prepare
Get the mission, boundaries, and responsibilities straight before deciding what protection the system needs.
Produce or update
- Mission and stakeholder records; assigned responsibilities.
- Information and asset inventories; an initial authorization boundary.
- Risk priorities, requirements, and potential common control providers.
Who’s responsible?
The system owner works with information owners, security staff, and control providers. Organization-level preparation sets the risk strategy and responsibilities they work within.
Keep it current
Revisit these records when the mission, information, people, or dependencies change. Carry them into the system description and categorization analysis.
At Secure By Design For Secure By Design, capture the fully air-gapped boundary and the people who approve, perform, and review manual media transfers.
2016 JSIG · Step 1
Categorize
Describe the system and make the impact of losing confidentiality, integrity, or availability explainable.
Produce or update
- Draft System Security Plan (SSP), including the system description and boundary.
- System registration with the appropriate SAP authority.
- Categorization analysis and applicable overlay considerations; an early Risk Assessment Report (RAR) is recommended.
Who’s responsible?
The information system owner (ISO) and information owner propose the impact levels. The security control assessor (SCA) reviews the rationale; the authorizing official (AO) approves the categorization.
Keep it current
Reconcile the SSP, inventories, information types, and boundary whenever the scope or mission impact changes. Keep the rationale and approval with the category.
At Secure By Design Secure By Design starts at Moderate confidentiality, Low integrity, and Low availability (MLL). Document why each level fits; the three letters alone do not explain the decision.
2016 JSIG · Step 2
Select
Agree on the controls, who provides them, and how their effectiveness will be monitored.
Produce or update
- Updated and approved draft SSP with its Security Controls Traceability Matrix (SCTM).
- Draft RAR.
- Documented Continuous Monitoring (ConMon) Plan or Strategy.
Who’s responsible?
The ISO coordinates with security managers or officers (ISSM/ISSO), security engineers (ISSE), and common control providers. The AO, SCA, or AO designee reviews the plan; baseline exceptions require AO approval.
Keep it current
Keep control allocation, inheritance, parameters, tailoring rationale, and approvals together. Update them when a requirement, provider, or assigned responsibility changes.
At Secure By Design Keep Secure By Design’s Revision 5 selection separate from the 2016 JSIG baseline. For a SAP system, establish the applicable CNSSI 1253 selection, overlays, and AO direction; an SP 800-53B Moderate baseline alone is not a JSIG baseline.
2016 JSIG · Step 3
Implement
Put the controls into operation, then describe what was actually built and how it works.
Produce or update
- Updated SSP/SCTM with functional implementation descriptions.
- Supporting implementation evidence, such as approved procedures, configuration records, and scoped exports.
Who’s responsible?
The ISO is accountable, with the ISSE and the people implementing each control. Common control providers supply the information needed to describe inherited protection.
Keep it current
Update the implementation description after changes. Keep the approved configuration, observed settings, responsible person, and collection context aligned so an assessor can evaluate the same system the plan describes.
At Secure By Design For a manual transfer process, retain the approved procedure, media inventory, transfer records, and content-check results. These support assessment; they do not establish effectiveness by themselves.
2016 JSIG · Step 4
Assess
Use agreed procedures to determine whether the controls work, and record what the evidence actually supports.
Produce or update
- Security Assessment Plan, reviewed and approved by the SCA.
- Security Assessment Report (SAR) with findings and recommendations.
- Updated RAR and SSP; assessment and reassessment evidence.
Who’s responsible?
The ISO and security staff develop the assessment plan. The SCA approves it; assessors perform the work and document results. Control owners address weaknesses, with reassessment as appropriate.
Keep it current
Tie findings to the assessment objective, evidence, scope, and result. Add retest results after remediation, preserve the original assessment results, and correct the SSP to match the implementation.
At Secure By Design A transfer log can show that a transfer was recorded. A scoped assessment must also check the approvals, handling steps, and required checks behind that entry.
2016 JSIG · Step 5
Authorize
Give the decision-maker a complete account of the system, its weaknesses, and the risk that remains.
Produce or update
- Plan of Action and Milestones (POA&M).
- Security authorization package: SSP, including SCTM, ConMon Plan/Strategy, and RAR; SAR; and POA&M.
- Authorization decision document, issued after review, with its outcome, conditions, and duration.
Who’s responsible?
The ISO verifies and submits the package and maintains the POA&M. The AO determines whether the risk is acceptable and issues the decision.
Keep it current
Track the exact package version reviewed, unresolved findings, corrective actions, resources, and milestones. Retain the decision and its conditions. New evidence or changed risk can require another decision.
At Secure By Design An assessment report is not permission to operate. Outcomes include Authorization to Operate (ATO), Interim Authorization to Test (IATT), or Denial of Authorization to Operate (DATO).
2016 JSIG · Step 6
Monitor
Keep the risk picture current as the system, its controls, and its operating environment change.
Produce or update
- Periodic ConMon deliverables and security status reports.
- Updated SSP/SCTM, SAR, POA&M, RAR, and monitoring information as the work changes.
- Updated authorization when appropriate; decommissioning and record-retention documentation when the system leaves service.
Who’s responsible?
The ISO keeps records and status reporting current. Control owners and providers supply results; assessors evaluate affected controls; the AO or designee reviews whether the risk remains acceptable.
Keep it current
Follow the approved monitoring strategy and event triggers. Document change impacts, reassess where needed, track corrective actions, and preserve earlier information needed for oversight and audit. Record destruction follows an AO-approved retention plan.
At Secure By Design Air-gapped does not mean unchanging. A manually imported software update can change the configuration baseline, assessment evidence, and risk analysis. Record the transfer and follow the change process.
Keep the BOE useful after the decision.
A collection of files only helps if it still describes the system. JSIG’s Monitor step calls for updated records, ongoing status reporting, and preservation of information needed for oversight. See JSIG §2.3.6, Tasks 6-4–6-7.
- Make the record traceable. For Secure By Design, identify the requirement, source system, scope, collector, collection date, version, and assessment result. This is a practical filing approach, not a JSIG-mandated filename format.
- Update related records together. A change may affect the SSP, SCTM, RAR, assessment results, monitoring plan, and POA&M. Follow the approved monitoring strategy and change process rather than inventing one review interval for every document.
- Preserve the history. Keep the package that supported the decision and distinguish it from later revisions. Protect the records, retain original assessment information, and follow the approved retention and decommissioning arrangements.