23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Common Carrier – In a telecommunications context, a telecommunications company that<br />

holds itself out to the public for hire to provide communications<br />

transmission services. Note: In the United States, such companies<br />

are usually subject to regulation by federal and state regulatory<br />

commissions.<br />

SOURCE: SP 800-53<br />

Common Control – A security control that is inherited by one or more organizational<br />

information systems. See <strong>Security</strong> Control Inheritance.<br />

SOURCE: SP 800-53; SP 800-53A; SP 800-37; CNSSI-4009<br />

Common Control Provider – An organizational <strong>of</strong>ficial responsible for the development,<br />

implementation, assessment, and monitoring <strong>of</strong> common controls<br />

(i.e., security controls inherited by information systems).<br />

SOURCE: SP 800-37; SP 800-53A<br />

Common Criteria – Governing document that provides a comprehensive, rigorous<br />

method for specifying security function and assurance requirements<br />

for products and systems.<br />

SOURCE: CNSSI-4009<br />

Common Fill Device – One <strong>of</strong> a family <strong>of</strong> devices developed to read-in, transfer, or store<br />

key.<br />

SOURCE: CNSSI-4009<br />

Common Vulnerabilities and<br />

Exposures (CVE) –<br />

A dictionary <strong>of</strong> common names for publicly known information<br />

system vulnerabilities.<br />

SOURCE: SP 800-51; CNSSI-4009<br />

Communications Cover – Concealing or altering <strong>of</strong> characteristic communications patterns to<br />

hide information that could be <strong>of</strong> value to an adversary.<br />

SOURCE: CNSSI-4009<br />

Communications Deception – Deliberate transmission, retransmission, or alteration <strong>of</strong><br />

communications to mislead an adversary's interpretation <strong>of</strong> the<br />

communications.<br />

SOURCE: CNSSI-4009<br />

Communications Pr<strong>of</strong>ile – Analytic model <strong>of</strong> communications associated with an organization<br />

or activity. The model is prepared from a systematic examination <strong>of</strong><br />

communications content and patterns, the functions they reflect, and<br />

the communications security measures applied.<br />

SOURCE: CNSSI-4009<br />

Pg 37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!