23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

A backup facility that has the necessary electrical and physical<br />

components <strong>of</strong> a computer facility, but does not have the computer<br />

equipment in place. The site is ready to receive the necessary<br />

replacement computer equipment in the event that the user has to<br />

move from their main computing location to an alternate site.<br />

SOURCE: SP 800-34<br />

Cold Start – Procedure for initially keying crypto-equipment.<br />

SOURCE: CNSSI-4009<br />

Collision – Two or more distinct inputs produce the same output.<br />

SOURCE: SP 800-57<br />

Command Authority – Individual responsible for the appointment <strong>of</strong> user representatives for<br />

a department, agency, or organization and their key ordering<br />

privileges.<br />

SOURCE: CNSSI-4009<br />

Commercial COMSEC Evaluation<br />

Program (CCEP) –<br />

Relationship between NSA and industry in which NSA provides the<br />

COMSEC expertise (i.e., standards, algorithms, evaluations, and<br />

guidance) and industry provides design, development, and production<br />

capabilities to produce a type 1 or type 2 product. Products<br />

developed under the CCEP may include modules, subsystems,<br />

equipment, systems, and ancillary devices.<br />

SOURCE: CNSSI-4009<br />

Commodity Service – An information system service (e.g., telecommunications service)<br />

provided by a commercial service provider typically to a large and<br />

diverse set <strong>of</strong> consumers. The organization acquiring and/or<br />

receiving the commodity service possesses limited visibility into the<br />

management structure and operations <strong>of</strong> the provider, and while the<br />

organization may be able to negotiate service-level agreements, the<br />

organization is typically not in a position to require that the provider<br />

implement specific security controls.<br />

SOURCE: SP 800-53<br />

Common Access Card (CAC) – Standard identification/smart card issued by the Department <strong>of</strong><br />

Defense that has an embedded integrated chip storing public key<br />

infrastructure (PKI) certificates.<br />

SOURCE: CNSSI-4009<br />

Pg 36

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!