The essential information that an authorizing official uses to determine whether to authorize the operation of an information system or the provision of a designated set of common controls. At a minimum, the authorization package includes an executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. Formerly known as "accreditation package".
Sources:
CNSSI 4009-2022
from
OMB Circular A-130 (2016)
NIST SP 800-37 Rev. 2
from
OMB Circular A-130 (2016)
The results of assessment and supporting documentation provided to the Designated Authorizing Official to be used in the authorization decision process.
Sources:
NIST SP 800-79-2
under Authorization Package