Dictionary · NIST SP 800-172r3
NIST Special Publication 800 NIST SP 800-172r3 Enhanced Security Requirements for Protecting Controlled Unclassified Information
Nouns
120 senses- Office of Management and Budget
- acronym list
OMB: Office of Management and Budget
- Information Sharing and Analysis Organizations
- acronym list
ISAO: Information Sharing and Analysis Organizations
- Return on investment
- acronym list
ROI: Return on Investment
- National Institute of Standards and Technology
- acronym list
NIST: National Institute of Standards and Technology
- Security Information and Event Management
- acronym list
SIEM: Security Information and Event Management
- Information Sharing and Analysis Centers
- acronym list
ISAC: Information Sharing and Analysis Centers
- Forum of Incident Response and Security Teams
- acronym list
FIRST: Forum of Incident Response and Security Teams
- National Archives and Records Administration
- acronym list
NARA: National Archives and Records Administration
- Computer emergency response team
- acronym list
CERT: Computer Emergency Response Team
- Personal Identification Information
- acronym list
PII: Personal Identification Information
- Programmable Logic Controller
- acronym list
PLC: Programmable Logic Controller
- Trusted Platform Module
- acronym list
TPM: Trusted Platform Module
- Supply Chain Risk Management
- acronym list
SCRM: Supply Chain Risk Management
- Cybersecurity and Infrastructure Security Agency
- acronym list
CISA: Cybersecurity and Infrastructure Security Agency
- Address Space Layout Randomization
- acronym list
ASLR: Address Space Layout Randomization
- Cyber Incident Response Team
- acronym list
CIRT: Cyber Incident Response Team
- Information Technology Laboratory
- acronym list
ITL: Information Technology Laboratory
- Freedom of Information Act
- acronym list
FOIA: Freedom of Information Act
- United States Code
- acronym list
USC: United States Code
- Defense Industrial Base
- acronym list
DIB: Defense Industrial Base
- Federal Information Processing Standard
- acronym list
FIPS: Federal Information Processing Standards
- Trusted Execution Environment
- acronym list
TEE: Trusted Execution Environment
- Special Publication
- acronym list
SP: Special Publication
- Committee on National Security Systems
- acronym list
CNSS: Committee on National Security Systems
- Unified Extensible Firmware Interface
- acronym list
UEFI: Unified Extensible Firmware Interface
- Federal Information Security Modernization Act
- acronym list
FISMA: Federal Information Security Modernization Act
- Code of Federal Regulations
- acronym list
CFR: Code of Federal Regulations
- Government Accountability Office
- acronym list
GAO: Government Accountability Office
- Basic Input/Output System
- acronym list
BIOS: Basic Input/Output System
- Executive Order
- acronym list
EO: Executive Order
- Organization-Defined Parameter
- acronym list
ODP: Organization-Defined Parameter
- security operations centre
- acronym list
SOC: Security Operations Center
- CERT Coordination Center
- acronym list
CERTCC: CERT Coordination Center
- Information Security Oversight Office
- acronym list
ISOO: Information Security Oversight Office
- High Value Asset
- glossary
A designation of federal information or a federal information system when it relates to one or more of the following categories: -Informational Value : The information or information system that processes, stores, or transmits the information is of high value to the Government or its adversaries. -Mission-Essential : The agency that owns the information or information system cannot accomplish its Primary Mission-Essential Functions (PMEF), as approved in accordance with Presidential Policy Directive 40 (PPD-40) National Continuity Policy, within expected timelines without the information or information system. -Federal Civilian Enterprise Essential (FCEE) : The information or information system serves a critical function in maintaining the security and resilience of the federal civilian enterprise. [10]
- Operational Technology
- glossary
The hardware, software, and firmware components of a system used to detect or cause changes in physical processes through the direct control and monitoring of physical devices.
- Tactics, Techniques, and Procedures
- glossary
The behavior of an actor. A tactic is the highest-level description of the behavior; techniques provide a more detailed description of the behavior in the context of a tactic; and procedures provide a lower-level, highly detailed description of the behavior in the context of a technique. [14]
- nonfederal system
- glossary
A system that does not meet the criteria for a federal system.
- tainting
- glossary
The process of embedding covert capabilities in information, systems, or system components to allow organizations to be alerted to the exfiltration of information.
- Damage-Limiting Operations
- glossary
Procedural and operational measures that use system capabilities to maximize the ability of an organization to detect successful system compromises by an adversary and to limit the effects of such compromises (both detected and undetected).
- Advanced persistent threat
- glossary
An adversary or collection of adversaries collaborating, opportunistically overlapping, or inadvertently converging that uses multiple attack vectors to achieve their objectives, including cyber, physical, and deception. Such adversaries use tactics, techniques, and procedures that display sophisticated levels of expertise and significant resources to achieve their objectives. These objectives typically include establishing and extending footholds within the IT infrastructure of the targeted organizations for purposes of exfiltrating information; undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period, adapts to defenders' efforts to resist it, and is determined to maintain the level of interaction needed to execute its objectives.
- Controlled Unclassified Information
- glossary
Information that a law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. [1]
- Penetration-Resistant Architecture
- glossary
An architecture that uses technology and procedures to limit the opportunities for an adversary to compromise an organizational system and achieve a persistent presence in the system.
- information technology
- glossary
Any services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use. [18]
- Cyber Resiliency
- glossary
The ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources. [13]
- Internet of Things
- glossary
The network of devices that contain the hardware, software, firmware, and actuators which allow the devices to connect, interact, and freely exchange data and information.
- dual authorization
- glossary
A system of storage and handling that is designed to prohibit individual access to certain resources by requiring the presence and actions of at least two authorized persons, each capable of detecting incorrect or unauthorized security procedures with respect to the task being performed. [16, adapted]
- remote access
- glossary
Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet).
- CUI Executive Agent
- glossary
The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO). [5]
- risk
- glossary
A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of (i) the adverse impact or magnitude of harm that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence. [18]
- External Network
- glossary
A network not controlled by the organization.
- moving target defense
- glossary
The concept of controlling change across multiple system dimensions in order to increase uncertainty and apparent complexity for attackers, reduce their window of opportunity, and increase the costs of their probing and attack efforts.
- Information System
- glossary
A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. [24]
- Security
- glossary
A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization's risk management approach.
- nonfederal organization
- glossary
An entity that owns, operates, or maintains a nonfederal system.
- Information Flow Control
- glossary
Procedure to ensure that information transfers within a system are not made in violation of the security policy.
- Authentication
- glossary
Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system. [7, adapted]
- critical program (or technology)
- glossary
A program which significantly increases capability, mission effectiveness, or extends the expected effective life of an essential system/capability. [1]
- threat information
- glossary
Any information related to a threat that might help an organization protect itself against the threat or detect the activities of an actor. Major types of threat information include indicators, TTPs, security alerts, threat intelligence reports, and tool configurations. [14]
- enhanced security requirements
- glossary
Security requirements that can be implemented in addition to the requirements in NIST Special Publication 800171. The additional security requirements provide the foundation for a defense-in-depth protection strategy that includes three mutually supportive and reinforcing components: (1) penetration-resistant architecture, (2) damage-limiting operations, and (3) cyber resiliency.
- Information Resources
- glossary
Information and related resources, such as personnel, equipment, funds, and information technology. [24]
- Integrity
- glossary
Guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity. [20]
- Federal Information System
- glossary
An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. [23]
- network
- glossary
A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices.
- Organization
- glossary
An entity of any size, complexity, or positioning within an organizational structure. [7, adapted]
- Noun #3775
- glossary
The recordings (automated and manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results), which serve as a basis for verifying that the organization and system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain the complete set of information on particular items).
- insider threat
- glossary
The threat that an insider will use their authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities.
- Information Security
- glossary
The protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. [20]
- CUI categories
- glossary
Those types of information for which laws, regulations, or government-wide policies require or permit agencies to exercise safeguarding or dissemination controls and which the CUI Executive Agent has approved and listed in the CUI Registry. [5]
- Boundary
- glossary
Physical or logical perimeter of a system.
- hardware
- glossary
The material physical components of a system. See software and firmware .
- malicious code
- glossary
Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
- assessment
- glossary
See security control assessment .
- System Security Plan
- glossary
A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.
- attack surface
- glossary
The set of points on the boundary of a system, a system element, or an environment where an attacker can try to enter, cause an effect on, or extract data from that system, system element, or environment. [19]
- system
- glossary
See information system .
- on behalf of (an agency)
- glossary
A situation that occurs when (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting federal information; and (ii) those activities are not incidental to providing a service or product to the Government. [5]
- risk assessment
- glossary
The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system. [21]
- Threat intelligence
- glossary
Threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes. [14]
- configuration settings
- glossary
The set of parameters that can be changed in hardware, software, or firmware that affect the security posture or functionality of the system.
- Media
- glossary
Physical devices or writing surfaces, including but not limited to magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system. [7]
- Executive Agency
- glossary
An executive department specified in 5 U.S.C. Sec. 101; a military department specified in 5 U.S.C. Sec. 102; an independent establishment as defined in 5 U.S.C. Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C. Chapter 91. [18]
- Federal Agency
- glossary
See executive agency .
- Network Access
- glossary
Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet).
- Security Functions
- glossary
The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.
- Configuration management
- glossary
A collection of activities focused on establishing and maintaining the integrity of information technology products and systems through the control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.
- Availability
- glossary
Ensuring timely and reliable access to and use of information. [20]
- Component
- glossary
See system component .
- Misdirection
- glossary
The process of maintaining and employing deception resources or environments and directing adversary activities to those resources or environments.
- external system (or component)
- glossary
A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
- mobile device
- glossary
A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and Ereaders.
- CUI program
- glossary
The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry. [5]
- personnel security
- glossary
The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities requiring trustworthiness. [8]
- Confidentiality
- glossary
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. [20]
- security solution
- glossary
The key design, architectural, and implementation choices made by organizations in satisfying specified security requirements for systems or system components.
- threat
- glossary
Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [21]
- discussion
- glossary
Statements used to provide additional explanatory information for controls, control enhancements, security requirements, or enhanced security requirements.
- cyber-physical system
- glossary
Interacting digital, analog, physical, and human components engineered for function through integrated physics and logic.
- information
- glossary
Any communication or representation of knowledge, such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms. [18]
- security assessment
- glossary
See security control assessment .
- Security Domain
- glossary
A domain that implements a security policy and is administered by a single authority. [16, adapted]
- Firmware
- glossary
Computer programs and data stored in hardware-typically in read-only memory (ROM) or programmable readonly memory (PROM)-such that programs and data cannot be dynamically written or modified during execution of the programs. See hardware and software .
- Agency
- glossary
Any executive agency or department, military department, Federal Government corporation, Federal Governmentcontrolled corporation, or other establishment in the Executive Branch of the Federal Government or any independent regulatory agency. [18]
- security control
- glossary
The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. [18]
- Impact Value
- glossary
The assessed worst-case potential impact that could result from a compromise of the confidentiality, integrity, or availability of information expressed as a value of low, moderate, or high. [6]
- system service
- glossary
A capability provided by a system that facilitates information processing, storage, or transmission.
- Assessor
- glossary
See security control assessor .
- Mutual Authentication
- glossary
The process of both entities involved in a transaction verifying each other. See bidirectional authentication .
- bidirectional authentication
- glossary
Two parties authenticating each other at the same time. Also known as mutual authentication or two-way authentication.
- incident
- glossary
An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. [20]
- system component
- glossary
A discrete, identifiable information technology asset that represents a building block of a system and may include hardware, software, and firmware. [26]
- Sanitization
- glossary
Actions taken to render data written on media unrecoverable by both ordinary and, for some forms of sanitization, extraordinary means. Process to remove information from media such that data recovery is not possible.
- audit record
- glossary
An individual entry in an audit log related to an audited event.
- Security Control Assessment
- glossary
The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization. [18]
- Noun #2269
- glossary
Information security strategy integrating people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.
- potential impact
- glossary
The loss of confidentiality, integrity, or availability could be expected to have (i) a limited adverse effect (FIPS Publication 199 low); (ii) a serious adverse effect (FIPS Publication 199 moderate); or (iii) a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals. [6]
- baseline configuration
- glossary
A documented set of specifications for a system or a configuration item within a system that has been formally reviewed and agreed on at a given point in time and which can be changed only through change control procedures.
- roots of trust
- glossary
Highly reliable hardware, firmware, and software components that perform specific, critical security functions. Because roots of trust are inherently trusted, they must be secure by design. Roots of trust provide a firm foundation from which to build security and trust. [25]
- Impact
- glossary
With respect to security, the effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system. With respect to privacy, the adverse effects that individuals could experience when an information system processes their PII.
- Disinformation
- glossary
The process of providing deliberately deceptive information to adversaries to mislead or confuse them regarding the security posture of the system or organization or the state of cyber preparedness.