23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Unauthorized Access – A person gains logical or physical access without permission to a<br />

network, system, application, data, or other IT resource.<br />

SOURCE: SP 800-61<br />

Unauthorized Access – Occurs when a user, legitimate or unauthorized, accesses a resource<br />

that the user is not permitted to use.<br />

SOURCE: FIPS 191<br />

Any access that violates the stated security policy.<br />

SOURCE: CNSSI-4009<br />

Unauthorized Disclosure – An event involving the exposure <strong>of</strong> information to entities not<br />

authorized access to the information.<br />

SOURCE: SP 800-57; CNSSI-4009<br />

Unsigned data – Data included in an authentication token, in addition to a digital<br />

signature.<br />

SOURCE: FIPS 196<br />

Unclassified – <strong>Information</strong> that has not been determined pursuant to E.O. 12958, as<br />

amended, or any predecessor order, to require protection against<br />

unauthorized disclosure and that is not designated as classified.<br />

SOURCE: CNSSI-4009<br />

Untrusted Process – Process that has not been evaluated or examined for correctness and<br />

adherence to the security policy. It may include incorrect or<br />

malicious code that attempts to circumvent the security mechanisms.<br />

SOURCE: CNSSI-4009<br />

Update (a Certificate) – The act or process by which data items bound in an existing public<br />

key certificate, especially authorizations granted to the subject, are<br />

changed by issuing a new certificate.<br />

SOURCE: SP 800-32; CNSSI-4009<br />

Update (key) – Automatic or manual cryptographic process that irreversibly modifies<br />

the state <strong>of</strong> a COMSEC key.<br />

SOURCE: CNSSI-4009<br />

US-CERT – A partnership between the Department <strong>of</strong> Homeland <strong>Security</strong> and the<br />

public and private sectors, established to protect the nation's Internet<br />

infrastructure. US-CERT coordinates defense against and responses<br />

to cyber attacks across the nation.<br />

SOURCE: CNSSI-4009<br />

Pg 202

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!