Terms starting with “S”
610 election security terms starting with S, with direct links to full definitions and source-backed context.
Security Plan
VerifiedFormal document that provides an overview of the security requirements for an information system or an information security program and describes the security controls in place or...
Security Policy
VerifiedA rule or set of rules that govern the acceptable use of an organization's information and services to a level of acceptable risk and the means for protecting the organization's in...
Security Policy Security Posture
VerifiedA set of criteria for the provision of security services. Source: NIST SP 800-53 Rev 4 The security status of an enterprise's networks, information, and systems based on informatio...
Security Posture
VerifiedThe security status of an enterprise's networks, information, and systems based on IA resources (e.g., people, hardware, software, policies) and capabilities in place to manage the...
Security Program Management
VerifiedIn the NICE Framework, cybersecurity work where a person: Manages information security (e.g., information security) implications within the organization, specific program, or other...
Security Program Plan
VerifiedFormal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management security controls...
Security Protocol
VerifiedAn abstract or concrete protocol that performs security-related functions. Source: CNSSP No. 15
Security Punch
VerifiedA "punch placed on a ballot card to identify to the computer program the offices and propositions for which votes may be cast and to indicate the manner in which votes cast should...
Security Range
VerifiedHighest and lowest security levels that are permitted in or on an information system, system component, subsystem, or network. See system high and system low.
Security Requirements
VerifiedRequirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, or procedures, or...
Security Requirements Baseline
VerifiedDescription of the minimum requirements necessary for an information system to maintain an acceptable level of risk.
Security Requirements Guide (srg) Security Requirements Traceability Matrix (srtm)
VerifiedCompilation of control correlation identifiers (CCIs) grouped in more applicable, specific technology areas at various levels of technology and product specificity. Contains all re...
Security Requirements Traceability Matrix (srtm)
VerifiedMatrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system's secu...
Security Safeguards
VerifiedProtective measures and controls prescribed to meet the security requirements specified for an information system. Safeguards may include security features, management constraints,...
Security Service
VerifiedA capability that supports one, or many, of the security goals. Examples of security services are key management, access control, and authentication. Source: NIST SP 800-27 Rev A
Security Specification
VerifiedDetailed description of the safeguards required to protect an information system. (CNSSI-4009) (NISTIR)
Security Strength
A number associated with the amount of work (that is, the number of operations) that is required to break a cryptographic algorithm or system. In this policy, security strength is...
Security Tag – I
Verifiednformation unit containing a representation of certain securityrelated information (e.g., a restrictive attribute bit map). (FIPS 188) (NISTIR)
Security Target
An implementation-dependent statement of security needs for a specific identified target of evaluation (TOE). Source: ISO/IEC 15408-1
Security Technical Implementation Guide (stig)
VerifiedBased on Department of Defense (DoD) policy and security controls. Implementation guide geared to a specific product and version. Contains all requirements that have been flagged a...
Security Test & Evaluation
Verified(ST&E) Examination and analysis of the safeguards required to protect an information system, as they have been applied in an operational environment, to determine the security post...
Security Test And Evaluation
VerifiedAbbreviated ST&E.
Security Test And Evaluation (st&e)
VerifiedExamination and analysis of the safeguards required to protect an information system, as they have been applied in an operational environment, to determine the security posture of...
Security Testing
VerifiedProcess to determine that an information system protects data and maintains functionality as intended. (CNSSI-4009) (NISTIR)