Our client needs certain documents along with the usual development documents like project plan, Test Plans and so on.. Now he has asked me to send the security document also. Can any one help me in this regard
Why not ask the client what they are looking for, just to be sure?
A "security" document, I have found, can mean different things relative to some cultures and how and when they use the term security. I worked with one company in the Commonwealth of Independent States that referred to a "security assurance document" which was more a document regarding confidentiality agreements and the equivalent of non-disclosures.
In general, howver and in my experience, a "security document" usually refers to what your company has in place in terms of security on a given system such that the client feels confident that the system is, in fact, secure and is not susceptible to various types of vulnerabilities. So, in that case, your client might be asking to see what types of security precautions you have taken and how you plan to validate those precautions in terms of determining their effectiveness.