home/dictionary/Environment of Operation

Environment of Operation

nouncandidate·updated May 12, 2026

The physical, technical, and organizational setting in which an information system operates, including but not limited to: missions/business functions; mission/business processes; threat space; vulnerabilities; enterprise and information security architectures; personnel; facilities; supply chain relationships; information technologies; organizational governance and culture; acquisition and procurement processes; organizational policies and procedures; organizational assumptions, constraints, risk tolerance, and priorities/trade-offs).

Framework senses

NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The physical surroundings in which an information system processes, stores, and transmits information.
§2 · sense_2_pending_review
The physical, technical, and organizational setting in which an information system operates, including but not limited to: missions/business functions; mission/business processes; threat space; vulnerabilities; enterprise and information security architectures; personnel; facilities; supply chain relationships; information technologies; organizational governance and culture; acquisition and procurement processes; organizational policies and procedures; organizational assumptions, constraints, risk tolerance, and priorities/trade-offs).
NIST SP 800-53A1 senseview framework →
§1
The physical surroundings in which an information system processes, stores, and transmits information.
NIST SP 800-371 senseview framework →
§1
The physical surroundings in which an information system processes, stores, and transmits information.
NIST SP 800-301 senseview framework →
§1
The physical, technical, and organizational setting in which an information system operates, including but not limited to: missions/business functions; mission/business processes; threat space; vulnerabilities; enterprise and information security architectures; personnel; facilities; supply chain relationships; information technologies; organizational governance and culture; acquisition and procurement processes; organizational policies and procedures; organizational assumptions, constraints, risk tolerance, and priorities/trade-offs).