23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Control <strong>Information</strong> – <strong>Information</strong> that is entered into a cryptographic module for the<br />

purposes <strong>of</strong> directing the operation <strong>of</strong> the module.<br />

SOURCE: FIPS 140-2<br />

Controlled Access Area – Physical area (e.g., building, room, etc.) to which only authorized<br />

personnel are granted unrestricted access. All other personnel are<br />

either escorted by authorized personnel or are under continuous<br />

surveillance.<br />

SOURCE: CNSSI-4009<br />

Controlled Access Protection – Minimum set <strong>of</strong> security functionality that enforces access control on<br />

individual users and makes them accountable for their actions<br />

through login procedures, auditing <strong>of</strong> security-relevant events, and<br />

resource isolation.<br />

SOURCE: CNSSI-4009<br />

Controlled Area – Any area or space for which the organization has confidence that the<br />

physical and procedural protections provided are sufficient to meet<br />

the requirements established for protecting the information and/or<br />

information system.<br />

SOURCE: SP 800-53<br />

Controlled Cryptographic Item –<br />

(CCI)<br />

Controlled Cryptographic Item<br />

(CCI) Assembly –<br />

Controlled Cryptographic Item<br />

(CCI) Component –<br />

Controlled Cryptographic Item<br />

(CCI) Equipment –<br />

Secure telecommunications or information system, or associated<br />

cryptographic component, that is unclassified and handled through<br />

the COMSEC Material Control System (CMCS), an equivalent<br />

material control system, or a combination <strong>of</strong> the two that provides<br />

accountability and visibility. Such items are marked “Controlled<br />

Cryptographic Item,” or, where space is limited, “CCI”.<br />

SOURCE: CNSSI-4009<br />

Device embodying a cryptographic logic or other COMSEC design<br />

that NSA has approved as a Controlled Cryptographic Item (CCI). It<br />

performs the entire COMSEC function, but depends upon the host<br />

equipment to operate.<br />

SOURCE: CNSSI-4009<br />

Part <strong>of</strong> a Controlled Cryptographic Item (CCI) that does not perform<br />

the entire COMSEC function but depends upon the host equipment,<br />

or assembly, to complete and operate the COMSEC function.<br />

SOURCE: CNSSI-4009<br />

Telecommunications or information handling equipment that<br />

embodies a Controlled Cryptographic Item (CCI) component or CCI<br />

assembly and performs the entire COMSEC function without<br />

dependence on host equipment to operate.<br />

SOURCE: CNSSI-4009<br />

Pg 47

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!