23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Policy Management Authority –<br />

(PMA)<br />

Body established to oversee the creation and update <strong>of</strong> Certificate<br />

Policies, review Certification Practice Statements, review the results<br />

<strong>of</strong> CA audits for policy compliance, evaluate non-domain policies for<br />

acceptance within the domain, and generally oversee and manage the<br />

PKI certificate policies. For the FBCA, the PMA is the Federal PKI<br />

Policy Authority.<br />

SOURCE: SP 800-32<br />

Policy Mapping – Recognizing that, when a CA in one domain certifies a CA in another<br />

domain, a particular certificate policy in the second domain may be<br />

considered by the authority <strong>of</strong> the first domain to be equivalent (but<br />

not necessarily identical in all respects) to a particular certificate<br />

policy in the first domain.<br />

SOURCE: SP 800-15<br />

Port – A physical entry or exit point <strong>of</strong> a cryptographic module that<br />

provides access to the module for physical signals, represented by<br />

logical information flows (physically separated ports do not share the<br />

same physical pin or wire).<br />

SOURCE: FIPS 140-2<br />

Port Scanning – Using a program to remotely determine which ports on a system are<br />

open (e.g., whether systems allow connections through those ports).<br />

SOURCE: SP 800-61; CNSSI-4009<br />

Portal – A high-level remote access architecture that is based on a server that<br />

<strong>of</strong>fers teleworkers access to one or more applications through a single<br />

centralized interface.<br />

SOURCE: SP 800-46<br />

Portable Electronic Device (PED) – Any nonstationary electronic apparatus with singular or multiple<br />

capabilities <strong>of</strong> recording, storing, and/or transmitting data, voice,<br />

video, or photo images. This includes but is not limited to laptops,<br />

personal digital assistants, pocket personal computers, palmtops,<br />

MP3 players, cellular telephones, thumb drives, video cameras, and<br />

pagers.<br />

SOURCE: CNSSI-4009<br />

Positive Control Material – Generic term referring to a sealed authenticator system, permissive<br />

action link, coded switch system, positive enable system, or nuclear<br />

command and control documents, material, or devices.<br />

SOURCE: CNSSI-4009<br />

Pg 140

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!