Security Control Assessment
Security Control Assessment: The testing and/or evaluation of the management, operational, and technical security controls in an information system to…
Definition
The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
Alternative Definitions
- Definition 2
The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. (SP 800-37; SP 800-53; SP 800-53A) (NISTIR)