MLchartDataset catalogue

assessment

Term · Cybersecurity · MLC-T-CYB-000228

1. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment provides an environment for decision makers to evaluate and prioritize risks continuously and to recommend strategies to remediate or mitigate those risks.

2. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.

3. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.

4. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

5. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

6. The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.

7. Overall process of risk identification, risk analysis, and risk evaluation.

8. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system.

9. The testing and/or evaluation of the management, operational, and technical security controls in a system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.

10. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

11. See Security Control Assessment.

12. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system.
Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

13. The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and additional safeguards that would mitigate this impact. Part of Risk Management and synonymous with Risk Analysis.

14. Assessment in this context means a formal process of assessing the implementation and reliable use of issuer controls using various methods of assessment (e.g., interviews, document reviews, observations) that support the assertion that an issuer is reliably meeting the requirements of [FIPS 201-2].

15. An evaluation of the amount of entropy provided by a (digitized) noise source and/or the entropy source that employs it.

16. See control assessment or risk assessment.

17. The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.

18. See security control assessment or risk assessment.

19. The testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.

20. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or

21. The vehicle or template or worksheet that is used for each evaluation.

22. Risk management includes threat and vulnerability analyses as well as analyses of adverse effects on individuals arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.

23. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses and analyses of privacy problems arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.

24. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system.

25. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.

26. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. A part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.

27. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.

28. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact. Part of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.

29. The process of identifying risks to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.

30. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.

31. The process of identifying, estimating, and prioritizing risks to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations that result from the operation of a system. A risk assessment is part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls that are planned or in place. It is synonymous with “risk analysis.”

32. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system.

33. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact.
Part of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.

Table 1. Record
IdentifierMLC-T-CYB-000228
FieldCybersecurity
Synonymscontrol assessment; Privacy Control Assessment; risk assessment; security control assessment
ReferencesCNSSI 4009-2022 from DoDD 3020.40; NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8441 from NIST SP 800-30 Rev. 1; CNSSI 4009-2022; CNSSI 4009-2022 from OMB Circular A-130 (2016) (under "security control assessment"); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-172Ar3 from OMB Circular A-130 (2016); NIST SP 800-172r3 from NIST SP 800-39; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 1800-21B; NIST SP 800-137; NIST SP 800-137; NIST SP 800-160 Vol. 2 Rev. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-171r3 from NIST SP 800-30 Rev. 1; NIST SP 800-37 Rev. 2 from NIST SP 800-30 Rev. 1; NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-53A Rev. 5 from NIST SP 800-39; NIST SP 800-12 Rev. 1; NIST SP 800-12 Rev. 1 from NIST SP 800-39; NIST SP 800-137; NIST SP 800-39; NIST SP 800-39; NIST SP 1800-10B; NIST SP 1800-25B; NIST SP 1800-26B; NIST SP 800-79-2; NIST SP 800-90B; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-53A Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST SP 800-39; NIST SP 800-137A; NIST SP 800-53 Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53A Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53B from NIST SP 800-39; NIST IR 8401 from NIST SP 800-30 Rev. 1; NIST SP 1800-21C; NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-39 (adapted); NIST SP 800-188 from NIST SP 800-39; NIST SP 800-82r3 from NIST SP 800-39 (adapted); NISTIR 8183; NISTIR 8183 Rev. 1 from NIST SP 800-82r3; NISTIR 8183A Vol. 1; NISTIR 8183A Vol. 2; NISTIR 8183A Vol. 3; NIST SP 800-175A; NIST SP 800-55v1; NIST SP 800-55v2; NIST SP 800-63-4; NIST SP 800-63A-4; NIST SP 800-172r3 from 44 U.S.C., Sec. 3552; NISTIR 8183 from NIST SP 800-82r3; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-000228",
  "term": "assessment",
  "field": "Cybersecurity",
  "definition": "1. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment provides an environment for decision makers to evaluate and prioritize risks continuously and to recommend strategies to remediate or mitigate those risks.\n\n2. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.\n\n3. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.\n\n4. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n5. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n6. The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.\n\n7. Overall process of risk identification, risk analysis, and risk evaluation.\n\n8. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system.\n\n9. The testing and/or evaluation of the management, operational, and technical security controls in a system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.\n\n10. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n11. See Security Control Assessment.\n\n12. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system.\nPart of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n13. The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and additional safeguards that would mitigate this impact. Part of Risk Management and synonymous with Risk Analysis.\n\n14. Assessment in this context means a formal process of assessing the implementation and reliable use of issuer controls using various methods of assessment (e.g., interviews, document reviews, observations) that support the assertion that an issuer is reliably meeting the requirements of [FIPS 201-2].\n\n15. An evaluation of the amount of entropy provided by a (digitized) noise source and/or the entropy source that employs it.\n\n16. See control assessment or risk assessment.\n\n17. The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.\n\n18. See security control assessment or risk assessment.\n\n19. The testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.\n\n20. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or\n\n21. The vehicle or template or worksheet that is used for each evaluation.\n\n22. Risk management includes threat and vulnerability analyses as well as analyses of adverse effects on individuals arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.\n\n23. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses and analyses of privacy problems arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.\n\n24. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system.\n\n25. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n26. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. A part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n27. The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.\n\n28. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact. Part of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.\n\n29. The process of identifying risks to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place.\n\n30. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.\n\n31. The process of identifying, estimating, and prioritizing risks to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations that result from the operation of a system. A risk assessment is part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls that are planned or in place. It is synonymous with “risk analysis.”\n\n32. The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation of a system.\n\n33. The process of identifying risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate this impact.\nPart of risk management, synonymous with risk analysis. Incorporates threat and vulnerability analyses.",
  "synonyms": [
    "control assessment",
    "Privacy Control Assessment",
    "risk assessment",
    "security control assessment"
  ],
  "references": [
    "CNSSI 4009-2022 from DoDD 3020.40; NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8441 from NIST SP 800-30 Rev. 1",
    "CNSSI 4009-2022",
    "CNSSI 4009-2022 from OMB Circular A-130 (2016) (under \"security control assessment\"); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-172Ar3 from OMB Circular A-130 (2016); NIST SP 800-172r3 from NIST SP 800-39; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016)",
    "NIST SP 1800-21B; NIST SP 800-137",
    "NIST SP 800-137",
    "NIST SP 800-160 Vol. 2 Rev. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73",
    "NIST SP 800-171r3 from NIST SP 800-30 Rev. 1; NIST SP 800-37 Rev. 2 from NIST SP 800-30 Rev. 1; NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-53A Rev. 5 from NIST SP 800-39",
    "NIST SP 800-12 Rev. 1",
    "NIST SP 800-12 Rev. 1 from NIST SP 800-39",
    "NIST SP 800-137; NIST SP 800-39",
    "NIST SP 800-39",
    "NIST SP 1800-10B; NIST SP 1800-25B; NIST SP 1800-26B",
    "NIST SP 800-79-2",
    "NIST SP 800-90B",
    "NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
    "NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-53A Rev. 5 from NIST SP 800-37 Rev. 2",
    "NIST SP 800-30 Rev. 1",
    "NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST SP 800-39",
    "NIST SP 800-137A",
    "NIST SP 800-53 Rev. 5 from NISTIR 8062 (Adapted); NIST SP 800-53A Rev. 5 from NISTIR 8062 (Adapted)",
    "NIST SP 800-53B from NIST SP 800-39; NIST IR 8401 from NIST SP 800-30 Rev. 1",
    "NIST SP 1800-21C",
    "NIST SP 1800-11B from NIST SP 800-30 Rev. 1; NIST SP 1800-30B from NIST SP 800-30 Rev. 1; NIST SP 1800-34B from NIST SP 800-30 Rev. 1",
    "NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-39 (adapted)",
    "NIST SP 800-188 from NIST SP 800-39",
    "NIST SP 800-82r3 from NIST SP 800-39 (adapted); NISTIR 8183; NISTIR 8183 Rev. 1 from NIST SP 800-82r3; NISTIR 8183A Vol. 1; NISTIR 8183A Vol. 2; NISTIR 8183A Vol. 3",
    "NIST SP 800-175A",
    "NIST SP 800-55v1; NIST SP 800-55v2",
    "NIST SP 800-63-4; NIST SP 800-63A-4",
    "NIST SP 800-172r3 from 44 U.S.C., Sec. 3552",
    "NISTIR 8183 from NIST SP 800-82r3",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/assessment/"
}

Record 228 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.