1. National Institute of Standards and Technology (NIST). (2008). Special Publication 800-115, Technical Guide to Information Security Testing and Assessment.
Section 6.1, "Reporting," states, "The final phase of security testing and assessment is reporting. The report synthesizes all the collected information and analysis results into a single document... The report should contain a description of all the tests performed, the vulnerabilities identified, and the risk ratings associated with the vulnerabilities." This directly aligns with the activities described in the question.
2. OWASP Foundation. (2020). OWASP Web Security Testing Guide (WSTG) v4.2.
Section 18, "Reporting," details the structure and purpose of the final deliverable from a security test. It states, "The final product of a penetration test is the report. It is the tangible deliverable that describes the work that was performed, the findings, and the recommendations for remediation." This confirms that documenting test results creates a security testing report.
3. Viega, J., & McGraw, G. (2001). Building Secure Software: How to Avoid Security Problems the Right Way. Addison-Wesley Professional.
Chapter 11, "Penetration Testing," (p. 268), a foundational text used in university curricula, discusses the output of penetration testing: "The most important part of any penetration test is the final report... The report should be a complete technical write-up of the team's findings." This reinforces that the deliverable being prepared is a formal report of testing activities.