Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls. Contains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M). Note: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan. Source: NIST SP 800-37 Rev 1
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
Documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system or a designated set of common controls. Contains: (i) the security plan; (ii) the security assessment report (SAR); and (iii) the plan of action and milestones (POA&M). Note: Many departments and agencies may choose to include the risk assessment report (RAR) as part of the security authorization package. Also, many organizations use system security plan in place of the security plan. Source: NIST SP 800-37 Rev 1
Cite this term
Election Security Glossary. (2026). Security Authorization Package. In Election Security Glossary. Retrieved August 21, 2026, from https://electionsecurityglossary.com/glossary/security-authorization-package
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.