23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Rules <strong>of</strong> Engagement (ROE) – Detailed guidelines and constraints regarding the execution <strong>of</strong><br />

information security testing. The ROE is established before the start<br />

<strong>of</strong> a security test, and gives the test team authority to conduct defined<br />

activities without the need for additional permissions.<br />

SOURCE: SP 800-115<br />

Ruleset – A table <strong>of</strong> instructions used by a controlled interface to determine<br />

what data is allowable and how the data is handled between<br />

interconnected systems.<br />

SOURCE: SP 800-115; CNSSI-4009<br />

A set <strong>of</strong> directives that govern the access control functionality <strong>of</strong> a<br />

firewall. The firewall uses these directives to determine how packets<br />

should be routed between its interfaces.<br />

SOURCE: SP 800-41<br />

S-box – Nonlinear substitution table used in several byte substitution<br />

transformations and in the <strong>Key</strong> Expansion routine to perform a onefor-one<br />

substitution <strong>of</strong> a byte value.<br />

SOURCE: FIPS 197<br />

S/MIME – A set <strong>of</strong> specifications for securing electronic mail. Secure/<br />

Multipurpose Internet Mail Extensions (S/MIME) is based upon the<br />

widely used MIME standard and describes a protocol for adding<br />

cryptographic security services through MIME encapsulation <strong>of</strong><br />

digitally signed and encrypted objects. The basic security services<br />

<strong>of</strong>fered by S/MIME are authentication, non-repudiation <strong>of</strong> origin,<br />

message integrity, and message privacy. Optional security services<br />

include signed receipts, security labels, secure mailing lists, and an<br />

extended method <strong>of</strong> identifying the signer’s certificate(s).<br />

SOURCE: SP 800-49<br />

Safeguards –<br />

Protective measures prescribed to meet the security requirements<br />

(i.e., confidentiality, integrity, and availability) specified for an<br />

information system. Safeguards may include security features,<br />

management constraints, personnel security, and security <strong>of</strong> physical<br />

structures, areas, and devices. Synonymous with security controls and<br />

countermeasures.<br />

SOURCE: SP 800-53; SP 800-37; FIPS 200; CNSSI-4009<br />

Safeguarding Statement – Statement affixed to a computer output or printout that states the<br />

highest classification being processed at the time the product was<br />

produced and requires control <strong>of</strong> the product, at that level, until<br />

determination <strong>of</strong> the true classification by an authorized individual.<br />

Synonymous with banner.<br />

SOURCE: CNSSI-4009<br />

Pg 163

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!