home/dictionary/framework/NIST SP 800-33

Dictionary · NIST SP 800-33

L2 — definitions grouped by regulatory framework.

Sort
Filtercosmetic affordance — live filters Phase 2
4 senses under NIST SP 800-33

Nouns

4 senses
Identity-Based Security Policy

A security policy based on the identities and/or attributes of the object (system resource) being accessed and of the subject (user, group of users, process, or device) requesting access.

Reference Monitor

The security engineering term for IT functionality that— 1) controls all access, 2) cannot be bypassed, 3) is tamper-resistant, and 4) provides confidence that the other three items are true.

Residual risk

The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.

Rule-Based Security Policy

A security policy based on global rules imposed for all subjects. These rules usually rely on a comparison of the sensitivity of the objects being accessed and the possession of corresponding attributes by the subjects requesting access.