23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Ephemeral <strong>Key</strong> – A cryptographic key that is generated for each execution <strong>of</strong> a key<br />

establishment process and that meets other requirements <strong>of</strong> the key<br />

type (e.g., unique to each message or session).<br />

SOURCE: SP 800-57<br />

Erasure – Process intended to render magnetically stored information<br />

irretrievable by normal means.<br />

SOURCE: CNSSI-4009<br />

Error Detection Code – A code computed from data and comprised <strong>of</strong> redundant bits <strong>of</strong><br />

information designed to detect, but not correct, unintentional changes<br />

in the data.<br />

SOURCE: FIPS 140-2; CNSSI-4009<br />

Escrow – Something (e.g., a document, an encryption key) that is "delivered to<br />

a third person to be given to the grantee only upon the fulfillment <strong>of</strong> a<br />

condition."<br />

SOURCE: FIPS 185<br />

Evaluation Products List (EPL) – List <strong>of</strong> validated products that have been successfully evaluated<br />

under the National <strong>Information</strong> Assurance Partnership (NIAP)<br />

Common Criteria Evaluation and Validation Scheme (CCEVS).<br />

SOURCE: CNSSI-4009<br />

Evaluation Assurance Level (EAL) – Set <strong>of</strong> assurance requirements that represent a point on the Common<br />

Criteria predefined assurance scale.<br />

SOURCE: CNSSI-4009<br />

Event – Any observable occurrence in a network or system.<br />

SOURCE: SP 800-61<br />

Any observable occurrence in a system and/or network. Events<br />

sometimes provide indication that an incident is occurring.<br />

SOURCE: CNSSI-4009<br />

Examination – A technical review that makes the evidence visible and suitable for<br />

analysis; tests performed on the evidence to determine the presence<br />

or absence <strong>of</strong> specific data.<br />

SOURCE: SP 800-72<br />

Pg 71

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!