Dictionary · NIST SP 800-95
L2 — definitions grouped by regulatory framework.
Nouns
4 senses- Agent
A program acting on behalf of a person or organization.
- Kerberos
A means of verifying the identities of principals on an open network. It accomplishes this without relying on the authentication, trustworthiness, or physical security of hosts while assuming all packets can be read, modified and inserted at will. It uses a trust broker model and symmetric cryptography to provide authentication and authorization of users and systems on the network.
- Security Assertion Markup Language
A framework for exchanging authentication and authorization information. Security typically involves checking the credentials presented by a party for authentication and authorization. SAML standardizes the representation of these credentials in an XML format called “assertions,” enhancing the interoperability between disparate applications.
- Role Based Access Control
A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.