23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Data Asset – 1. Any entity that is comprised <strong>of</strong> data. For example, a database is<br />

a data asset that is comprised <strong>of</strong> data records. A data asset may be a<br />

system or application output file, database, document, or Web page.<br />

A data asset also includes a service that may be provided to access<br />

data from an application. For example, a service that returns<br />

individual records from a database would be a data asset. Similarly,<br />

a Web site that returns data in response to specific queries (e.g.,<br />

www.weather.com) would be a data asset.<br />

2. An information-based resource.<br />

SOURCE: CNSSI-4009<br />

Data Element – A basic unit <strong>of</strong> information that has a unique meaning and<br />

subcategories (data items) <strong>of</strong> distinct value. Examples <strong>of</strong> data<br />

elements include gender, race, and geographic location.<br />

Data Encryption Algorithm (DEA) –<br />

Data Encryption Standard (DES) –<br />

SOURCE: SP 800-47; CNSSI-4009<br />

The cryptographic engine that is used by the Triple Data Encryption<br />

Algorithm (TDEA).<br />

SOURCE: SP 800-67<br />

Cryptographic algorithm designed for the protection <strong>of</strong> unclassified<br />

data and published by the National Institute <strong>of</strong> Standards and<br />

Technology (NIST) in Federal <strong>Information</strong> Processing Standard<br />

(FIPS) Publication 46. (FIPS 46-3 withdrawn 19 May 2005) See<br />

Triple DES.<br />

SOURCE: CNSSI-4009<br />

Data Flow Control – Synonymous with information flow control.<br />

SOURCE: CNSSI-4009<br />

Data Integrity – The property that data has not been altered in an unauthorized<br />

manner. Data integrity covers data in storage, during processing, and<br />

while in transit.<br />

SOURCE: SP 800-27<br />

The property that data has not been changed, destroyed, or lost in an<br />

unauthorized or accidental manner.<br />

SOURCE: CNSSI-4009<br />

Data Origin Authentication – The process <strong>of</strong> verifying that the source <strong>of</strong> the data is as claimed and<br />

that the data has not been modified.<br />

SOURCE: CNSSI-4009<br />

Pg 58

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!