23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Steganography – The art and science <strong>of</strong> communicating in a way that hides the<br />

existence <strong>of</strong> the communication. For example, a child pornography<br />

image can be hidden inside another graphic image file, audio file, or<br />

other file format.<br />

SOURCE: SP 800-72; SP 800-101<br />

The art, science, and practice <strong>of</strong> communicating in a way that hides<br />

the existence <strong>of</strong> the communication.<br />

SOURCE: CNSSI-4009<br />

Storage Object – Object supporting both read and write accesses to an information<br />

system.<br />

SOURCE: CNSSI-4009<br />

Strength <strong>of</strong> Mechanism (SoM) – A scale for measuring the relative strength <strong>of</strong> a security mechanism.<br />

SOURCE: CNSSI-4009<br />

Striped Core – A network architecture in which user data traversing a core IP<br />

network is decrypted, filtered and re-encrypted one or more times.<br />

Note: The decryption, filtering, and re-encryption are performed<br />

within a “Red gateway”; consequently, the core is “striped” because<br />

the data path is alternately Black, Red, and Black.<br />

SOURCE: CNSSI-4009<br />

Strong Authentication – The requirement to use multiple factors for authentication and<br />

advanced technology, such as dynamic passwords or digital<br />

certificates, to verify an entity’s identity.<br />

SOURCE: CNSSI-4009<br />

Subassembly – Major subdivision <strong>of</strong> an assembly consisting <strong>of</strong> a package <strong>of</strong> parts,<br />

elements, and circuits that perform a specific function.<br />

SOURCE: CNSSI-4009<br />

Subject – The person whose identity is bound to a particular credential.<br />

SOURCE: SP 800-63<br />

Generally an individual, process, or device causing information to<br />

flow among objects or changes to the system state.<br />

See Object.<br />

SOURCE: SP 800-53<br />

An active entity (generally an individual, process, or device) that<br />

causes information to flow among objects or changes the system<br />

state. See also object.<br />

SOURCE: CNSSI-4009<br />

Pg 183

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!