IT Security Plan (ITSP)
The ITSP is the security document approved for a single CIS (Communication and Information System). It records what the system is, what data and functions it holds, how valuable those are to the organisation, what could compromise them, and what will be done about it — in a form your system owner can sign and your auditor can follow.
It is written against ITSRM (the IT Security Risk Management methodology, version 1.2, published by DG DIGIT Unit S1), which is the method EU institutions, bodies and agencies are expected to apply.