assurance
Term · Cybersecurity · MLC-T-CYB-000257
1. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved.
2. Grounds for justified confidence that a claim has been or will be achieved.
3. Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy.
4. The grounds for confidence that the set of intended security controls in an information system are effective in their application.
5. Grounds for confidence that the set of intended security controls in an information system are effective in their application.
6. Grounds for confidence that the other four security goals (integrity, availability, confidentiality, and accountability) have been adequately met by a specific implementation. “Adequately met” includes (1) functionality that performs correctly, (2) sufficient protection against unintentional errors (by users or software), and (3) sufficient resistance to intentional penetration or by-pass.
7. Grounds for confidence that the other four security objectives (integrity, availability, confidentiality, and accountability) have been adequately met by a specific implementation. “Adequately met” includes (1) functionality that performs correctly, (2) sufficient protection against unintentional errors (by users or software), and (3) sufficient resistance to intentional penetration or by-pass.
8. See Assurance.
9. The grounds for confidence that the set of intended security controls or privacy controls in an information system or organization are effective in their application.
10. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved. Note 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims) and the claims themselves may be interrelated. Note 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.
11. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved. Note 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims), and the claims themselves may be interrelated. Note 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.
12. The grounds for confidence that an entity meets its security objectives.
13. In the context of OMB M-04-04 and this document, assurance is defined as 1) the degree of confidence in the vetting process used to establish the identity of an individual to whom the credential was issued, and 2) the degree of confidence that the individual who uses the credential is the individual to whom the credential was issued.
14. Grounds for justified confidence that a claim has been or will be achieved.
Note 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims) and the claims themselves may be interrelated.
Note 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.
| Identifier | MLC-T-CYB-000257 |
|---|---|
| Field | Cybersecurity |
| Synonyms | Security Assurance |
| References | NIST SP 800-53A Rev. 5 from ISO/IEC 15026-1:2019 (Adapted); NIST SP 800-37 Rev. 2 from ISO/IEC 15026-1:2019 (adapted); NIST SP 800-160v1r1 from ISO/IEC 15026-1:2019; NIST SP 800-39 from CNSSI 4009; NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009; CNSSI 4009-2015 from NIST SP 800-27 Rev. A (Adapted); NIST SP 800-137 from NISTIR 7298; NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-39 from NIST SP 800-53; NIST SP 800-12 Rev. 1 from NIST SP 800-27 Rev. A; NIST SP 800-27 Rev. A [Withdrawn]; NIST SP 800-33 [Withdrawn]; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-53 Rev. 5 from ISO/IEC 15026-1:2019 (Adapted); NIST SP 800-53B; NISTIR 7316; NIST SP 800-63-2 [Superseded]; NIST SP 800-160 Vol. 1 from ISO/IEC 15026; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000257",
"term": "assurance",
"field": "Cybersecurity",
"definition": "1. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved.\n\n2. Grounds for justified confidence that a claim has been or will be achieved.\n\n3. Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy.\n\n4. The grounds for confidence that the set of intended security controls in an information system are effective in their application.\n\n5. Grounds for confidence that the set of intended security controls in an information system are effective in their application.\n\n6. Grounds for confidence that the other four security goals (integrity, availability, confidentiality, and accountability) have been adequately met by a specific implementation. “Adequately met” includes (1) functionality that performs correctly, (2) sufficient protection against unintentional errors (by users or software), and (3) sufficient resistance to intentional penetration or by-pass.\n\n7. Grounds for confidence that the other four security objectives (integrity, availability, confidentiality, and accountability) have been adequately met by a specific implementation. “Adequately met” includes (1) functionality that performs correctly, (2) sufficient protection against unintentional errors (by users or software), and (3) sufficient resistance to intentional penetration or by-pass.\n\n8. See Assurance.\n\n9. The grounds for confidence that the set of intended security controls or privacy controls in an information system or organization are effective in their application.\n\n10. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved. Note 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims) and the claims themselves may be interrelated. Note 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.\n\n11. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved. Note 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims), and the claims themselves may be interrelated. Note 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.\n\n12. The grounds for confidence that an entity meets its security objectives.\n\n13. In the context of OMB M-04-04 and this document, assurance is defined as 1) the degree of confidence in the vetting process used to establish the identity of an individual to whom the credential was issued, and 2) the degree of confidence that the individual who uses the credential is the individual to whom the credential was issued.\n\n14. Grounds for justified confidence that a claim has been or will be achieved.\nNote 1: Assurance is typically obtained relative to a set of specific claims. The scope and focus of such claims may vary (e.g., security claims, safety claims) and the claims themselves may be interrelated.\nNote 2: Assurance is obtained through techniques and methods that generate credible evidence to substantiate claims.",
"synonyms": [
"Security Assurance"
],
"references": [
"NIST SP 800-53A Rev. 5 from ISO/IEC 15026-1:2019 (Adapted); NIST SP 800-37 Rev. 2 from ISO/IEC 15026-1:2019 (adapted)",
"NIST SP 800-160v1r1 from ISO/IEC 15026-1:2019",
"NIST SP 800-39 from CNSSI 4009; NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009",
"CNSSI 4009-2015 from NIST SP 800-27 Rev. A (Adapted); NIST SP 800-137 from NISTIR 7298; NIST SP 800-37 Rev. 1 [Superseded]",
"NIST SP 800-39 from NIST SP 800-53",
"NIST SP 800-12 Rev. 1 from NIST SP 800-27 Rev. A; NIST SP 800-27 Rev. A [Withdrawn]",
"NIST SP 800-33 [Withdrawn]",
"NIST SP 800-53 Rev. 4 [Superseded]",
"NIST SP 800-53A Rev. 4 [Superseded]",
"NIST SP 800-53 Rev. 5 from ISO/IEC 15026-1:2019 (Adapted)",
"NIST SP 800-53B",
"NISTIR 7316",
"NIST SP 800-63-2 [Superseded]",
"NIST SP 800-160 Vol. 1 from ISO/IEC 15026",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/assurance/"
}
Record 257 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.