MLchartDataset catalogue

accreditation

Term · Cybersecurity · MLC-T-CYB-000054

1. Formal declaration by a designated accrediting authority (DAA) or principal accrediting authority (PAA) that an information system is approved to operate at an acceptable level of risk, based on the implementation of an approved set of technical, managerial, and procedural safeguards.

2. Formal recognition that a laboratory is competent to carry out specific tests or calibrations or types of tests or calibrations.

3. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.

4. The official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals, based on the implementation of an agreed-upon set of security controls.

5. also known as authorize processing (OMB Circular A-130, Appendix III),and approval to operate. Accreditation (or authorization to process information) is granted by a management official and provides an important quality control. By accrediting a system or application, a manager accepts the associated risk. Accreditation (authorization) must be based on a review of controls. (See Certification.)

6. See Accreditation.

7. Formal declaration by a Designated Approving Authority that an Information System is approved to operate in a particular security mode using a prescribed set of safeguards at an acceptable level of risk.

8. Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Authorization also applies to common controls inherited by agency information systems. Note 1: The system is authorized to operate for a specified period in accordance with terms and conditions established by the authorizing official. Note 2: Formerly known as "approval to operate." Term was replaced in the risk management framework in 2010.

9. See authorization.

Table 1. Record
IdentifierMLC-T-CYB-000054
FieldCybersecurity
Synonymsauthorization to operate; authorize processing
ReferencesCNSSI 4009-2015; CNSSI 4009-2022 from NIST HB 150-2016, NVLAP; CNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 1, NIST SP 800-37 Rev. 1; FIPS 200; NIST SP 800-18 Rev. 1 [Superseded] from NIST SP 800-37; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200, NIST SP 800-37; NIST SP 800-82 Rev. 2 [Superseded] from NIST SP 800-53; NIST SP 800-16; NIST SP 800-18 Rev. 1 [Superseded]; NIST SP 800-32 [Withdrawn]; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; CNSSI 4009-2022 from OMB Circular A-130 (2016); CNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-37 Rev. 1; NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]; NIST CSRC Glossary
See alsocertification
Record as JSON
{
  "id": "MLC-T-CYB-000054",
  "term": "accreditation",
  "field": "Cybersecurity",
  "definition": "1. Formal declaration by a designated accrediting authority (DAA) or principal accrediting authority (PAA) that an information system is approved to operate at an acceptable level of risk, based on the implementation of an approved set of technical, managerial, and procedural safeguards.\n\n2. Formal recognition that a laboratory is competent to carry out specific tests or calibrations or types of tests or calibrations.\n\n3. The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.\n\n4. The official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals, based on the implementation of an agreed-upon set of security controls.\n\n5. also known as authorize processing (OMB Circular A-130, Appendix III),and approval to operate. Accreditation (or authorization to process information) is granted by a management official and provides an important quality control. By accrediting a system or application, a manager accepts the associated risk. Accreditation (authorization) must be based on a review of controls. (See Certification.)\n\n6. See Accreditation.\n\n7. Formal declaration by a Designated Approving Authority that an Information System is approved to operate in a particular security mode using a prescribed set of safeguards at an acceptable level of risk.\n\n8. Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Authorization also applies to common controls inherited by agency information systems. Note 1: The system is authorized to operate for a specified period in accordance with terms and conditions established by the authorizing official. Note 2: Formerly known as \"approval to operate.\" Term was replaced in the risk management framework in 2010.\n\n9. See authorization.",
  "synonyms": [
    "authorization to operate",
    "authorize processing"
  ],
  "see_also": [
    "certification"
  ],
  "references": [
    "CNSSI 4009-2015",
    "CNSSI 4009-2022 from NIST HB 150-2016, NVLAP",
    "CNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 1, NIST SP 800-37 Rev. 1",
    "FIPS 200; NIST SP 800-18 Rev. 1 [Superseded] from NIST SP 800-37; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200, NIST SP 800-37; NIST SP 800-82 Rev. 2 [Superseded] from NIST SP 800-53",
    "NIST SP 800-16",
    "NIST SP 800-18 Rev. 1 [Superseded]",
    "NIST SP 800-32 [Withdrawn]",
    "NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; CNSSI 4009-2022 from OMB Circular A-130 (2016)",
    "CNSSI 4009-2015 from NIST SP 800-53 Rev. 4, NIST SP 800-37 Rev. 1; NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/accreditation/"
}

Record 54 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.