3.1.2Security Plan (SP).The SP shall use the approved DAA, NAO, AO, or ISSM format. The SP shall contain at a minimum, System Information, Mission Description, Concept of Operations (CONOPS), Environment, Operating and Computing Environment, Physical Security Measures, Facilities Descriptions, Threat Analysis, System Architecture Description, Components, Configurations, Accreditation Boundaries, Connection Process Guide (CPG) Compliant Network Diagrams, External Interfaces and Data Flow, Internal Data Flow, Contingency Plan, Incident Response Plan, User Descriptions and Clearances, Security Roles, Hardware Lists, Software Lists, Ports, Protocols, and Services (PPS), Configuration Management Plan, Information Assurance Vulnerability Management (IAVM) Plan, and A&A Tasks and Milestones. The SP shall be approved and signed by the ISSM, User Rep, Program Manager (PM), and DAA, NAO, or AO.