Category:NIST SP 800-53A Terms
APPENDIX B
GLOSSARY
COMMON TERMS AND DEFINITIONS
This appendix provides definitions for security terminology used within Special Publication 800-53A. The terms in the glossary are consistent with the terms used in the suite of FISMA-related security standards and guidelines developed by NIST. Unless otherwise stated, all terms used in this publication are also consistent with the definitions contained in the CNSS Instruction 4009, National Information Assurance Glossary.
Pages in category "NIST SP 800-53A Terms"
The following 128 pages are in this category, out of 128 total.
T
- Term:Accreditation
- Term:Accreditation Boundary
- Term:Accrediting Authority
- Term:Activities
- Term:Adequate Security
- Term:Agency
- Term:Assessment Findings
- Term:Assessment Method
- Term:Assessment Object
- Term:Assessment Objective
- Term:Assessment Procedure
- Term:Assurance
- Term:Assurance Case
- Term:Authentication
- Term:Authenticity
- Term:Authorize Processing
- Term:Authorizing Official
- Term:Availability
- Term:Black Box Testing
- Term:Boundary Protection
- Term:Boundary Protection Device
- Term:Certification
- Term:Certification Agent
- Term:Chief Information Officer
- Term:Common Security Control
- Term:Compensating Security Controls
- Term:Confidentiality
- Term:Configuration Control
- Term:Controlled Area
- Term:Countermeasures
- Term:Coverage
- Term:Depth
- Term:Detailed Testing
- Term:Examine
- Term:Executive Agency
- Term:Extended Assessment Procedure
- Term:External Information System
- Term:External Information System Service
- Term:External Information System Service Provider
- Term:Federal Enterprise Architecture
- Term:Federal Information System
- Term:Focused Testing
- Term:Generalized Testing
- Term:Gray Box Testing
- Term:High-Impact System
- Term:Hybrid Security Control
- Term:Incident
- Term:Individuals
- Term:Industrial Control System
- Term:Information
- Term:Information Owner
- Term:Information Resources
- Term:Information Security
- Term:Information Security Policy
- Term:Information System
- Term:Information System Owner
- Term:Information System Security Officer
- Term:Information Technology
- Term:Information Type
- Term:Integrity
- Term:Interview
- Term:Label
- Term:Local Access
- Term:Low-Impact System
- Term:Major Information System
- Term:Malicious Code
- Term:Malware
- Term:Management Controls
- Term:Mechanisms
- Term:Media
- Term:Media Access Control Address
- Term:Media Sanitization
- Term:Mobile Code
- Term:Mobile Code Technologies
- Term:Moderate-Impact System
- Term:National Security Emergency Preparedness Telecommunications Services
- Term:National Security Information
- Term:National Security System
- Term:Non-Repudiation
- Term:Operational Controls
- Term:Organization
- Term:Penetration Testing
- Term:Plan of Action and Milestones
- Term:Potential Impact
- Term:Privacy Impact Assessment
- Term:Privileged Function
- Term:Privileged User
- Term:Protective Distribution System
- Term:Records
- Term:Remote Access
- Term:Remote Maintenance
- Term:Risk
- Term:Risk Assessment
- Term:Risk Management
- Term:Safeguards
- Term:Security Category
- Term:Security Control Assessment
- Term:Security Control Baseline
- Term:Security Control Enhancements
- Term:Security Controls
- Term:Security Functions
- Term:Security Impact Analysis
- Term:Security Incident
- Term:Security Label
- Term:Security Objective
- Term:Security Perimeter
- Term:Security Plan
- Term:Security Requirements
- Term:Senior Agency Information Security Officer
- Term:Specification
- Term:Spyware
- Term:Subsystem
- Term:Supplementation
- Term:System
- Term:System Security Plan
- Term:System-specific Security Control
- Term:Tailored Security Control Baseline
- Term:Tailoring
- Term:Technical Controls
- Term:Test
- Term:Threat
- Term:Threat Assessment
- Term:Threat Source
- Term:Trusted Path
- Term:User
- Term:Vulnerability
- Term:Vulnerability Assessment
- Term:White Box Testing