Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

authorization package

Abbreviation(s) and Synonym(s): Definition(s):

  The results of assessment and supporting documentation provided to the Designated Authorizing Official to be used in the authorization decision process.
Source(s):
NIST SP 800-79-2 under Authorization Package

  See security authorization package
Source(s):
CNSSI 4009-2015

  Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls. Contains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M). Note: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan.
Source(s):
CNSSI 4009-2015 under security authorization package (NIST SP 800-37 Rev. 1)