23.03.2013 Views

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

NISTIR 7298 Revision 1, Glossary of Key Information Security Terms

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NIST IR <strong>7298</strong> <strong>Revision</strong> 1, <strong>Glossary</strong> <strong>of</strong> <strong>Key</strong> <strong>Information</strong> <strong>Security</strong> <strong>Terms</strong><br />

Incomplete Parameter Checking – System flaw that exists when the operating system does not check all<br />

parameters fully for accuracy and consistency, thus making the<br />

system vulnerable to penetration.<br />

SOURCE: CNSSI-4009<br />

Inculpatory Evidence – Evidence that tends to increase the likelihood <strong>of</strong> fault or guilt.<br />

SOURCE: SP 800-72<br />

Independent Validation Authority –<br />

(IVA)<br />

Independent Verification &<br />

Validation (IV&V) –<br />

Entity that reviews the soundness <strong>of</strong> independent tests and system<br />

compliance with all stated security controls and risk mitigation<br />

actions. IVAs will be designated by the Authorizing Official as<br />

needed.<br />

SOURCE: CNSSI-4009<br />

A comprehensive review, analysis, and testing (s<strong>of</strong>tware and/or<br />

hardware) performed by an objective third party to confirm (i.e.,<br />

verify) that the requirements are correctly defined, and to confirm<br />

(i.e., validate) that the system correctly implements the required<br />

functionality and security requirements.<br />

SOURCE: CNSSI-4009<br />

Indication – A sign that an incident may have occurred or may be currently<br />

occurring.<br />

SOURCE: SP 800-61<br />

Indicator – Recognized action, specific, generalized, or theoretical, that an<br />

adversary might be expected to take in preparation for an attack.<br />

SOURCE: CNSSI-4009<br />

Individual – A citizen <strong>of</strong> the United States or an alien lawfully admitted for<br />

permanent residence. Agencies may, consistent with individual<br />

practice, choose to extend the protections <strong>of</strong> the Privacy Act and E-<br />

Government Act to businesses, sole proprietors, aliens, etc.<br />

SOURCE: SP 800-60<br />

Individual Accountability – Ability to associate positively the identity <strong>of</strong> a user with the time,<br />

method, and degree <strong>of</strong> access to an information system.<br />

SOURCE: CNSSI-4009<br />

Individuals – An assessment object that includes people applying specifications,<br />

mechanisms, or activities.<br />

SOURCE: SP 800-53A<br />

Pg 90

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!