23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Capture – The method <strong>of</strong> taking a biometric sample from an end user.<br />

Source: FIPS 201<br />

Cardholder – An individual possessing an issued Personal Identity Verification<br />

(PIV) card.<br />

Source: FIPS 201<br />

Cascading – Downward flow <strong>of</strong> information through a range <strong>of</strong> security levels<br />

greater than the accreditation range <strong>of</strong> a system, network, or<br />

component.<br />

SOURCE: CNSSI-4009<br />

Category – Restrictive label applied to classified or unclassified information to<br />

limit access.<br />

SOURCE: CNSSI-4009<br />

CBC/MAC – See Cipher Block Chaining-Message Authentication Code.<br />

CCM – See Counter with Cipher-Block Chaining-Message Authentication<br />

Code.<br />

Central Office <strong>of</strong> Record (COR) – Office <strong>of</strong> a federal department or agency that keeps records <strong>of</strong><br />

accountable COMSEC material held by elements subject to its<br />

oversight<br />

SOURCE: CNSSI-4009<br />

Central Services Node (CSN) – The <strong>Key</strong> Management Infrastructure core node that provides central<br />

security management and data management services.<br />

SOURCE: CNSSI-4009<br />

Certificate – A digital representation <strong>of</strong> information which at least<br />

1) identifies the certification authority issuing it,<br />

2) names or identifies its subscriber,<br />

3) contains the subscriber's public key,<br />

4) identifies its operational period, and<br />

5) is digitally signed by the certification authority issuing it.<br />

SOURCE: SP 800-32<br />

Certificate – A set <strong>of</strong> data that uniquely identifies an entity, contains the entity’s<br />

public key and possibly other information, and is digitally signed by<br />

a trusted party, thereby binding the public key to the entity.<br />

Additional information in the certificate could specify how the key is<br />

used and its cryptoperiod.<br />

SOURCE: SP 800-21<br />

Pg 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!