23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Personal Identity Verification<br />

Registrar –<br />

Personal Identity Verification<br />

Sponsor –<br />

Personally Identifiable <strong>Information</strong> –<br />

(PII)<br />

An entity that establishes and vouches for the identity <strong>of</strong> an applicant<br />

to a PIV Issuer. The PIV RA authenticates the applicant’s identity by<br />

checking identity source documents and identity pro<strong>of</strong>ing, and that<br />

ensures a proper background check has been completed, before the<br />

credential is issued.<br />

SOURCE: FIPS 201<br />

An individual who can act on behalf <strong>of</strong> a department or agency to<br />

request a PIV Card for an applicant.<br />

SOURCE: FIPS 201<br />

<strong>Information</strong> which can be used to distinguish or trace an individual's<br />

identity, such as their name, social security number, biometric<br />

records, etc., alone, or when combined with other personal or<br />

identifying information which is linked or linkable to a specific<br />

individual, such as date and place <strong>of</strong> birth, mother’s maiden name,<br />

etc.<br />

SOURCE: CNSSI-4009<br />

Any information about an individual maintained by an agency,<br />

including (1) any information that can be used to distinguish or trace<br />

an individual‘s identity, such as name, social security number, date<br />

and place <strong>of</strong> birth, mother‘s maiden name, or biometric records; and<br />

(2) any other information that is linked or linkable to an individual,<br />

such as medical, educational, financial, and employment information.<br />

SOURCE: SP 800-122<br />

Personnel Registration Manager – The management role that is responsible for registering human users,<br />

i.e., users that are people.<br />

SOURCE: CNSSI-4009<br />

Phishing – Tricking individuals into disclosing sensitive personal information<br />

through deceptive computer-based means.<br />

SOURCE: SP 800-83<br />

Deceiving individuals into disclosing sensitive personal information<br />

through deceptive computer-based means.<br />

SOURCE: CNSSI-4009<br />

A digital form <strong>of</strong> social engineering that uses authentic-looking—but<br />

bogus—emails to request information from users or direct them to a<br />

fake Web site that requests information.<br />

SOURCE: SP 800-115<br />

Pg 138

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!