23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Certification Analyst – The independent technical liaison for all stakeholders involved in the<br />

C&A process responsible for objectively and independently<br />

evaluating a system as part <strong>of</strong> the risk management process. Based<br />

on the security requirements documented in the security plan,<br />

performs a technical and non-technical review <strong>of</strong> potential<br />

vulnerabilities in the system and determines if the security controls<br />

(management, operational, and technical) are correctly implemented<br />

and effective.<br />

SOURCE: CNSSI-4009<br />

Certification Authority (CA) –<br />

A trusted entity that issues and revokes public key certificates.<br />

SOURCE: FIPS 201<br />

Certification Authority – The entity in a public key infrastructure (PKI) that is responsible for<br />

issuing certificates and exacting compliance to a PKI policy.<br />

SOURCE: SP 800-21; FIPS 186<br />

1. For Certification and Accreditation (C&A) (C&A Assessment):<br />

Official responsible for performing the comprehensive evaluation<br />

<strong>of</strong> the security features <strong>of</strong> an information system and determining<br />

the degree to which it meets its security requirements<br />

2. For Public <strong>Key</strong> Infrastructure (PKI): A trusted third party that<br />

issues digital certificates and verifies the identity <strong>of</strong> the holder <strong>of</strong> the<br />

digital certificate.<br />

SOURCE: CNSSI-4009<br />

Certification Authority Facility – The collection <strong>of</strong> equipment, personnel, procedures and structures<br />

that are used by a Certification Authority to perform certificate<br />

issuance and revocation.<br />

SOURCE: SP 800-32<br />

Certification Authority Workstation<br />

(CAW) –<br />

Commercial <strong>of</strong>f-the-shelf (COTS) workstation with a trusted<br />

operating system and special-purpose application s<strong>of</strong>tware that is<br />

used to issue certificates<br />

SOURCE: CNSSI-4009<br />

Certification Package – Product <strong>of</strong> the certification effort documenting the detailed results <strong>of</strong><br />

the certification activities.<br />

SOURCE: CNSSI-4009<br />

Pg 28

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!