The "Responsible Organization" in a System Security Plan (SSP) is the entity that owns and operates the information system and is ultimately accountable for the security of the system and the Controlled Unclassified Information (CUI) it processes, stores, or transmits. This organization is responsible for implementing and maintaining the security controls outlined in the SSP and ensuring compliance with NIST SP 800-171 Rev. 3.

Vetting Policy for Employee Access to Controlled Unclassified Information (CUI)