Dictionary · NIST SP 800-128
L2 — definitions grouped by regulatory framework.
Nouns
15 senses- Asset Identification
Security Content Automation Protocol (SCAP) constructs to uniquely identify assets (components) based on known identifiers and/or known information about the assets.
- Asset Reporting Format
SCAP data model for expressing the transport format of information about assets (components) and the relationships between assets and reports.
- baseline configuration
A set of specifications for a system, or Configuration Item (CI) within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures. The baseline configuration is used as a basis for future builds, releases, and/or changes.
- Common Configuration Enumeration
A SCAP specification that provides unique, common identifiers for configuration settings found in a wide variety of hardware and software products.
- Common Configuration Scoring System
A SCAP specification for measuring the severity of software security configuration issues.
- Common Platform Enumeration
A SCAP specification that provides a standard naming convention for operating systems, hardware, and applications for the purpose of providing consistent, easily parsed names that can be shared by multiple parties and solutions to refer to the same specific platform type.
- Common Vulnerabilities and Exposures
An SCAP specification that provides unique, common names for publicly known information system vulnerabilities.
- Common Vulnerability Scoring System
An SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity.
- Extensible Configuration Checklist Description Format
SCAP language for specifying checklists and reporting checklist results.
- Open Checklist Interactive Language
SCAP language for expressing security checks that cannot be evaluated without some human interaction or feedback.
- Open Vulnerability and Assessment Language
SCAP language for specifying low-level testing procedures used by checklists.
- Security Information and Event Management
Application that provides the ability to gather security data from information system components and present that data as actionable information via a single interface.
- Security Management Dashboard
A tool that consolidates and communicates information relevant to the organizational security posture in near real-time to security management stakeholders.
- United States Government Configuration Baseline
The United States Government Configuration Baseline (USGCB) provides security configuration baselines for Information Technology products widely deployed across the federal agencies. The USGCB baseline evolved from the federal Desktop Core Configuration mandate. The USGCB is a Federal government-wide initiative that provides guidance to agencies on what should be done to improve and maintain an effective configuration settings focusing primarily on security.
- whitelist
A list of discrete entities, such as hosts or applications that are known to be benign and are approved for use within an organization and/or information system.