23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Personal Identification Number –<br />

(PIN)<br />

Personal Identification Number –<br />

(PIN)<br />

Personal Identity Verification –<br />

(PIV)<br />

Personal Identity Verification<br />

Accreditation –<br />

Personal Identity Verification<br />

Authorizing Official –<br />

Personal Identity Verification Card –<br />

(PIV Card)<br />

Personal Identity Verification<br />

Issuer –<br />

A secret that a claimant memorizes and uses to authenticate his or her<br />

identity. PINs are generally only decimal digits.<br />

SOURCE: FIPS 201<br />

An alphanumeric code or password used to authenticate an identity.<br />

SOURCE: FIPS 140-2<br />

A short numeric code used to confirm identity.<br />

SOURCE: CNSSI-4009<br />

The process <strong>of</strong> creating and using a governmentwide secure and<br />

reliable form <strong>of</strong> identification for federal employees and contractors,<br />

in support <strong>of</strong> HSPD 12, Policy for a Common Identification Standard<br />

for Federal Employees and Contractors.<br />

SOURCE: CNSSI-4009<br />

The <strong>of</strong>ficial management decision to authorize operation <strong>of</strong> a PIV<br />

Card Issuer after determining that the Issuer’s reliability has<br />

satisfactorily been established through appropriate assessment and<br />

certification processes.<br />

SOURCE: CNSSI-4009<br />

An individual who can act on behalf <strong>of</strong> an agency to authorize the<br />

issuance <strong>of</strong> a credential to an applicant.<br />

SOURCE: CNSSI-4009<br />

Physical artifact (e.g., identity card, “smart” card) issued to an<br />

individual that contains stored identity credentials (e.g., photograph,<br />

cryptographic keys, digitized fingerprint representation, etc.) such<br />

that a claimed identity <strong>of</strong> the cardholder may be verified against the<br />

stored credentials by another person (human-readable and verifiable)<br />

or an automated process (computer-readable and verifiable).<br />

SOURCE: FIPS 201; CNSSI-4009<br />

An authorized identity card creator that procures FIPS-approved<br />

blank identity cards, initializes them with appropriate s<strong>of</strong>tware and<br />

data elements for the requested identity verification and access<br />

control application, personalizes the cards with the identity<br />

credentials <strong>of</strong> the authorized subjects, and delivers the personalized<br />

card to the authorized subjects along with appropriate instructions for<br />

protection and use.<br />

SOURCE: FIPS 201<br />

Pg 137

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!