home/dictionary/framework/NIST SP 800-172r3

Dictionary · NIST SP 800-172r3

NIST Special Publication 800 NIST SP 800-172r3 Enhanced Security Requirements for Protecting Controlled Unclassified Information

Sort
Filtercosmetic affordance — live filters Phase 2
120 senses under NIST SP 800-172r3

Nouns

120 senses
Office of Management and Budget
acronym list

OMB: Office of Management and Budget

Information Sharing and Analysis Organizations
acronym list

ISAO: Information Sharing and Analysis Organizations

Return on investment
acronym list

ROI: Return on Investment

National Institute of Standards and Technology
acronym list

NIST: National Institute of Standards and Technology

Security Information and Event Management
acronym list

SIEM: Security Information and Event Management

Information Sharing and Analysis Centers
acronym list

ISAC: Information Sharing and Analysis Centers

Forum of Incident Response and Security Teams
acronym list

FIRST: Forum of Incident Response and Security Teams

National Archives and Records Administration
acronym list

NARA: National Archives and Records Administration

Computer emergency response team
acronym list

CERT: Computer Emergency Response Team

Personal Identification Information
acronym list

PII: Personal Identification Information

Programmable Logic Controller
acronym list

PLC: Programmable Logic Controller

Trusted Platform Module
acronym list

TPM: Trusted Platform Module

Supply Chain Risk Management
acronym list

SCRM: Supply Chain Risk Management

Cybersecurity and Infrastructure Security Agency
acronym list

CISA: Cybersecurity and Infrastructure Security Agency

Address Space Layout Randomization
acronym list

ASLR: Address Space Layout Randomization

Cyber Incident Response Team
acronym list

CIRT: Cyber Incident Response Team

Information Technology Laboratory
acronym list

ITL: Information Technology Laboratory

Freedom of Information Act
acronym list

FOIA: Freedom of Information Act

United States Code
acronym list

USC: United States Code

Defense Industrial Base
acronym list

DIB: Defense Industrial Base

Federal Information Processing Standard
acronym list

FIPS: Federal Information Processing Standards

Trusted Execution Environment
acronym list

TEE: Trusted Execution Environment

Special Publication
acronym list

SP: Special Publication

Committee on National Security Systems
acronym list

CNSS: Committee on National Security Systems

Unified Extensible Firmware Interface
acronym list

UEFI: Unified Extensible Firmware Interface

Federal Information Security Modernization Act
acronym list

FISMA: Federal Information Security Modernization Act

Code of Federal Regulations
acronym list

CFR: Code of Federal Regulations

Government Accountability Office
acronym list

GAO: Government Accountability Office

Basic Input/Output System
acronym list

BIOS: Basic Input/Output System

Executive Order
acronym list

EO: Executive Order

Organization-Defined Parameter
acronym list

ODP: Organization-Defined Parameter

security operations centre
acronym list

SOC: Security Operations Center

CERT Coordination Center
acronym list

CERTCC: CERT Coordination Center

Information Security Oversight Office
acronym list

ISOO: Information Security Oversight Office

High Value Asset
glossary

A designation of federal information or a federal information system when it relates to one or more of the following categories: -Informational Value : The information or information system that processes, stores, or transmits the information is of high value to the Government or its adversaries. -Mission-Essential : The agency that owns the information or information system cannot accomplish its Primary Mission-Essential Functions (PMEF), as approved in accordance with Presidential Policy Directive 40 (PPD-40) National Continuity Policy, within expected timelines without the information or information system. -Federal Civilian Enterprise Essential (FCEE) : The information or information system serves a critical function in maintaining the security and resilience of the federal civilian enterprise. [10]

Operational Technology
glossary

The hardware, software, and firmware components of a system used to detect or cause changes in physical processes through the direct control and monitoring of physical devices.

Tactics, Techniques, and Procedures
glossary

The behavior of an actor. A tactic is the highest-level description of the behavior; techniques provide a more detailed description of the behavior in the context of a tactic; and procedures provide a lower-level, highly detailed description of the behavior in the context of a technique. [14]

nonfederal system
glossary

A system that does not meet the criteria for a federal system.

tainting
glossary

The process of embedding covert capabilities in information, systems, or system components to allow organizations to be alerted to the exfiltration of information.

Damage-Limiting Operations
glossary

Procedural and operational measures that use system capabilities to maximize the ability of an organization to detect successful system compromises by an adversary and to limit the effects of such compromises (both detected and undetected).

Advanced persistent threat
glossary

An adversary or collection of adversaries collaborating, opportunistically overlapping, or inadvertently converging that uses multiple attack vectors to achieve their objectives, including cyber, physical, and deception. Such adversaries use tactics, techniques, and procedures that display sophisticated levels of expertise and significant resources to achieve their objectives. These objectives typically include establishing and extending footholds within the IT infrastructure of the targeted organizations for purposes of exfiltrating information; undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period, adapts to defenders' efforts to resist it, and is determined to maintain the level of interaction needed to execute its objectives.

Controlled Unclassified Information
glossary

Information that a law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. [1]

Penetration-Resistant Architecture
glossary

An architecture that uses technology and procedures to limit the opportunities for an adversary to compromise an organizational system and achieve a persistent presence in the system.

information technology
glossary

Any services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use. [18]

Cyber Resiliency
glossary

The ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources. [13]

Internet of Things
glossary

The network of devices that contain the hardware, software, firmware, and actuators which allow the devices to connect, interact, and freely exchange data and information.

dual authorization
glossary

A system of storage and handling that is designed to prohibit individual access to certain resources by requiring the presence and actions of at least two authorized persons, each capable of detecting incorrect or unauthorized security procedures with respect to the task being performed. [16, adapted]

remote access
glossary

Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet).

CUI Executive Agent
glossary

The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO). [5]

risk
glossary

A measure of the extent to which an entity is threatened by a potential circumstance or event and typically is a function of (i) the adverse impact or magnitude of harm that would arise if the circumstance or event occurs and (ii) the likelihood of occurrence. [18]

External Network
glossary

A network not controlled by the organization.

moving target defense
glossary

The concept of controlling change across multiple system dimensions in order to increase uncertainty and apparent complexity for attackers, reduce their window of opportunity, and increase the costs of their probing and attack efforts.

Information System
glossary

A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. [24]

Security
glossary

A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization's risk management approach.

nonfederal organization
glossary

An entity that owns, operates, or maintains a nonfederal system.

Information Flow Control
glossary

Procedure to ensure that information transfers within a system are not made in violation of the security policy.

Authentication
glossary

Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system. [7, adapted]

critical program (or technology)
glossary

A program which significantly increases capability, mission effectiveness, or extends the expected effective life of an essential system/capability. [1]

threat information
glossary

Any information related to a threat that might help an organization protect itself against the threat or detect the activities of an actor. Major types of threat information include indicators, TTPs, security alerts, threat intelligence reports, and tool configurations. [14]

enhanced security requirements
glossary

Security requirements that can be implemented in addition to the requirements in NIST Special Publication 800171. The additional security requirements provide the foundation for a defense-in-depth protection strategy that includes three mutually supportive and reinforcing components: (1) penetration-resistant architecture, (2) damage-limiting operations, and (3) cyber resiliency.

Information Resources
glossary

Information and related resources, such as personnel, equipment, funds, and information technology. [24]

Integrity
glossary

Guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity. [20]

Federal Information System
glossary

An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. [23]

network
glossary

A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices.

Organization
glossary

An entity of any size, complexity, or positioning within an organizational structure. [7, adapted]

Noun #3775
glossary

The recordings (automated and manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results), which serve as a basis for verifying that the organization and system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain the complete set of information on particular items).

insider threat
glossary

The threat that an insider will use their authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities.

Information Security
glossary

The protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. [20]

CUI categories
glossary

Those types of information for which laws, regulations, or government-wide policies require or permit agencies to exercise safeguarding or dissemination controls and which the CUI Executive Agent has approved and listed in the CUI Registry. [5]

Boundary
glossary

Physical or logical perimeter of a system.

hardware
glossary

The material physical components of a system. See software and firmware .

malicious code
glossary

Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.

assessment
glossary

See security control assessment .

System Security Plan
glossary

A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.

attack surface
glossary

The set of points on the boundary of a system, a system element, or an environment where an attacker can try to enter, cause an effect on, or extract data from that system, system element, or environment. [19]

system
glossary

See information system .

on behalf of (an agency)
glossary

A situation that occurs when (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting federal information; and (ii) those activities are not incidental to providing a service or product to the Government. [5]

risk assessment
glossary

The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system. [21]

Threat intelligence
glossary

Threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes. [14]

configuration settings
glossary

The set of parameters that can be changed in hardware, software, or firmware that affect the security posture or functionality of the system.

Media
glossary

Physical devices or writing surfaces, including but not limited to magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system. [7]

Executive Agency
glossary

An executive department specified in 5 U.S.C. Sec. 101; a military department specified in 5 U.S.C. Sec. 102; an independent establishment as defined in 5 U.S.C. Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C. Chapter 91. [18]

Federal Agency
glossary

See executive agency .

Network Access
glossary

Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet).

Security Functions
glossary

The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.

Configuration management
glossary

A collection of activities focused on establishing and maintaining the integrity of information technology products and systems through the control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.

Availability
glossary

Ensuring timely and reliable access to and use of information. [20]

Component
glossary

See system component .

Misdirection
glossary

The process of maintaining and employing deception resources or environments and directing adversary activities to those resources or environments.

external system (or component)
glossary

A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

mobile device
glossary

A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and Ereaders.

CUI program
glossary

The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry. [5]

personnel security
glossary

The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities requiring trustworthiness. [8]

Confidentiality
glossary

Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. [20]

security solution
glossary

The key design, architectural, and implementation choices made by organizations in satisfying specified security requirements for systems or system components.

threat
glossary

Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [21]

discussion
glossary

Statements used to provide additional explanatory information for controls, control enhancements, security requirements, or enhanced security requirements.

cyber-physical system
glossary

Interacting digital, analog, physical, and human components engineered for function through integrated physics and logic.

information
glossary

Any communication or representation of knowledge, such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms. [18]

security assessment
glossary

See security control assessment .

Security Domain
glossary

A domain that implements a security policy and is administered by a single authority. [16, adapted]

Firmware
glossary

Computer programs and data stored in hardware-typically in read-only memory (ROM) or programmable readonly memory (PROM)-such that programs and data cannot be dynamically written or modified during execution of the programs. See hardware and software .

Agency
glossary

Any executive agency or department, military department, Federal Government corporation, Federal Governmentcontrolled corporation, or other establishment in the Executive Branch of the Federal Government or any independent regulatory agency. [18]

security control
glossary

The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. [18]

Impact Value
glossary

The assessed worst-case potential impact that could result from a compromise of the confidentiality, integrity, or availability of information expressed as a value of low, moderate, or high. [6]

system service
glossary

A capability provided by a system that facilitates information processing, storage, or transmission.

Assessor
glossary

See security control assessor .

Mutual Authentication
glossary

The process of both entities involved in a transaction verifying each other. See bidirectional authentication .

bidirectional authentication
glossary

Two parties authenticating each other at the same time. Also known as mutual authentication or two-way authentication.

incident
glossary

An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. [20]

system component
glossary

A discrete, identifiable information technology asset that represents a building block of a system and may include hardware, software, and firmware. [26]

Sanitization
glossary

Actions taken to render data written on media unrecoverable by both ordinary and, for some forms of sanitization, extraordinary means. Process to remove information from media such that data recovery is not possible.

audit record
glossary

An individual entry in an audit log related to an audited event.

Security Control Assessment
glossary

The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization. [18]

Noun #2269
glossary

Information security strategy integrating people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.

potential impact
glossary

The loss of confidentiality, integrity, or availability could be expected to have (i) a limited adverse effect (FIPS Publication 199 low); (ii) a serious adverse effect (FIPS Publication 199 moderate); or (iii) a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals. [6]

baseline configuration
glossary

A documented set of specifications for a system or a configuration item within a system that has been formally reviewed and agreed on at a given point in time and which can be changed only through change control procedures.

roots of trust
glossary

Highly reliable hardware, firmware, and software components that perform specific, critical security functions. Because roots of trust are inherently trusted, they must be secure by design. Roots of trust provide a firm foundation from which to build security and trust. [25]

Impact
glossary

With respect to security, the effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system. With respect to privacy, the adverse effects that individuals could experience when an information system processes their PII.

Disinformation
glossary

The process of providing deliberately deceptive information to adversaries to mislead or confuse them regarding the security posture of the system or organization or the state of cyber preparedness.