Defined term

Security Authorization Package

Security Authorization Package: Documents the results of the security control assessment and provides the authorizing official with essential information…

📋 Single Source
Cybersecurity

Definition

Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls. Contains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M). Note: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan.

Sources

1
Committee on National Security Systems Glossary CNSSI 4009-2015
View Source

Continue Research

Browse the full glossary for adjacent terms, or subscribe for updates when definitions and sources are expanded.