home/dictionary/framework/NIST SP 800-128

Dictionary · NIST SP 800-128

L2 — definitions grouped by regulatory framework.

Sort
Filtercosmetic affordance — live filters Phase 2
15 senses under NIST SP 800-128

Nouns

15 senses
Asset Identification

Security Content Automation Protocol (SCAP) constructs to uniquely identify assets (components) based on known identifiers and/or known information about the assets.

Asset Reporting Format

SCAP data model for expressing the transport format of information about assets (components) and the relationships between assets and reports.

baseline configuration

A set of specifications for a system, or Configuration Item (CI) within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures. The baseline configuration is used as a basis for future builds, releases, and/or changes.

Common Configuration Enumeration

A SCAP specification that provides unique, common identifiers for configuration settings found in a wide variety of hardware and software products.

Common Configuration Scoring System

A SCAP specification for measuring the severity of software security configuration issues.

Common Platform Enumeration

A SCAP specification that provides a standard naming convention for operating systems, hardware, and applications for the purpose of providing consistent, easily parsed names that can be shared by multiple parties and solutions to refer to the same specific platform type.

Common Vulnerabilities and Exposures

An SCAP specification that provides unique, common names for publicly known information system vulnerabilities.

Common Vulnerability Scoring System

An SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity.

Extensible Configuration Checklist Description Format

SCAP language for specifying checklists and reporting checklist results.

Open Checklist Interactive Language

SCAP language for expressing security checks that cannot be evaluated without some human interaction or feedback.

Open Vulnerability and Assessment Language

SCAP language for specifying low-level testing procedures used by checklists.

Security Information and Event Management

Application that provides the ability to gather security data from information system components and present that data as actionable information via a single interface.

Security Management Dashboard

A tool that consolidates and communicates information relevant to the organizational security posture in near real-time to security management stakeholders.

United States Government Configuration Baseline

The United States Government Configuration Baseline (USGCB) provides security configuration baselines for Information Technology products widely deployed across the federal agencies. The USGCB baseline evolved from the federal Desktop Core Configuration mandate. The USGCB is a Federal government-wide initiative that provides guidance to agencies on what should be done to improve and maintain an effective configuration settings focusing primarily on security.

whitelist

A list of discrete entities, such as hosts or applications that are known to be benign and are approved for use within an organization and/or information system.