System and services acquisition policy
procedures addressing system developer security testing
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system developer security test plans
records of developer security testing results for the system, system component, or system service
vulnerability scanning results
system risk assessment reports
threat and vulnerability analysis reports
system security plan
supply chain risk management plan
other relevant documents or records