MLchartDataset catalogue

security authorization package

Term · Cybersecurity · MLC-T-CYB-003782

1. Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls.
Contains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M).
Note: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan.

2. See security authorization package

3. The essential information that an authorizing official uses to determine whether to authorize the operation of an information system or the provision of a designated set of common controls. At a minimum, the authorization package includes an executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. Formerly known as "accreditation package".

Table 1. Record
IdentifierMLC-T-CYB-003782
FieldCybersecurity
Synonymsauthorization package
ReferencesCNSSI 4009-2015 from NIST SP 800-37 Rev. 1; CNSSI 4009-2015; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-003782",
  "term": "security authorization package",
  "field": "Cybersecurity",
  "definition": "1. Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls.\nContains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M).\nNote: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan.\n\n2. See security authorization package\n\n3. The essential information that an authorizing official uses to determine whether to authorize the operation of an information system or the provision of a designated set of common controls. At a minimum, the authorization package includes an executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. Formerly known as \"accreditation package\".",
  "synonyms": [
    "authorization package"
  ],
  "references": [
    "CNSSI 4009-2015 from NIST SP 800-37 Rev. 1",
    "CNSSI 4009-2015",
    "NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); CNSSI 4009-2022 from OMB Circular A-130 (2016)",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/security-authorization-package/"
}

Record 3,782 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.