About SSP Library
A System Security Plan is the document where your security story lives. Assessors read it first. SSP Library builds that document with you, one chapter at a time, aimed at CMMC Level 2.
Read the chapters in order, or jump to the one you are writing this week.
PolicyCortex is a cloud governance and compliance automation platform. It uses 33 collectors that read live Azure configuration. It connects to Microsoft Azure and Amazon Web Services. It reads live settings such as conditional access, diagnostic settings, Defender posture, backup, and firewall configuration. It checks those settings against NIST 800-53 and NIST 800-171 controls. It turns that evidence into SSP, SAR, and POA&M documents. It re-checks controls after you fix them. It is strongest in commercial Azure.
See how PolicyCortex generates SSPs from live evidence
Learn more