Jul 302012

For some US Government agencies, such as NASA, an Information Technology Security Management Plan (ITSMP) is required within the first 30 days of contract award.  This is different from the System Security Plan (SSP), which is a much more involved and detailed document.  The ITSMP is a high level plan that shows the government how you, as the contactor, expect to secure and manage IT resources.

To download the Word document, go to the below link.  I understand that it is not without some irony that an IT security plan template is formatted as a Word document on a public website, so download at your own risk.  Unfortunately, to be of any use this is the best way to present the information.

ITSMP – sanitized but real

Additional Reading

Official NASA ITSMP Template