23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

IT-Related Risk – The net mission/business impact considering<br />

1) the likelihood that a particular threat source will exploit, or<br />

trigger, a particular information system vulnerability, and<br />

2) the resulting impact if this should occur. IT-related risks arise<br />

from legal liability or mission/business loss due to, but not limited<br />

to:<br />

Unauthorized (malicious, non-malicious, or accidental)<br />

disclosure, modification, or destruction <strong>of</strong> information;<br />

Non-malicious errors and omissions;<br />

IT disruptions due to natural or man-made disasters; or<br />

Failure to exercise due care and diligence in the<br />

implementation and operation <strong>of</strong> the IT.<br />

SOURCE: SP 800-27<br />

IT <strong>Security</strong> Architecture – A description <strong>of</strong> security principles and an overall approach for<br />

complying with the principles that drive the system design; i.e.,<br />

guidelines on the placement and implementation <strong>of</strong> specific security<br />

services within various distributed computing environments.<br />

SOURCE: SP 800-27<br />

IT <strong>Security</strong> Awareness – The purpose <strong>of</strong> awareness presentations is simply to focus attention<br />

on security. Awareness presentations are intended to allow<br />

individuals to recognize IT security concerns and respond<br />

accordingly.<br />

SOURCE: SP 800-50<br />

IT <strong>Security</strong> Awareness and Training<br />

Program –<br />

Explains proper rules <strong>of</strong> behavior for the use <strong>of</strong> agency IT systems<br />

and information. The program communicates IT security policies and<br />

procedures that need to be followed.<br />

SOURCE: SP 800-50<br />

Explains proper rules <strong>of</strong> behavior for the use <strong>of</strong> agency information<br />

systems and information. The program communicates IT security<br />

policies and procedures that need to be followed (i.e., NSTISSD 501,<br />

NIST SP 800-50).<br />

SOURCE: CNSSI-4009<br />

IT <strong>Security</strong> Education – IT <strong>Security</strong> Education seeks to integrate all <strong>of</strong> the security skills and<br />

competencies <strong>of</strong> the various functional specialties into a common<br />

body <strong>of</strong> knowledge, adds a multidisciplinary study <strong>of</strong> concepts,<br />

issues, and principles (technological and social), and strives to<br />

produce IT security specialists and pr<strong>of</strong>essionals capable <strong>of</strong> vision<br />

and proactive response.<br />

SOURCE: SP 800-50<br />

Pg 103

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!