Information security program plan
privacy program plan
procedures addressing management (i.e., documentation, tracking, and reporting) of the authorization process
assessment, authorization, and monitoring policy
assessment, authorization, and monitoring procedures
system authorization documentation
lists or other documentation about authorization process roles and responsibilities
risk assessment results relevant to the authorization process and the organization-wide risk management program
organizational risk management strategy
other relevant documents or records