commodity service
Term · Cybersecurity · MLC-T-CYB-000754
1. An information system service (e.g., telecommunications service) provided by a commercial service provider typically to a large and diverse set of consumers. The organization acquiring and/or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not in a position to require that the provider implement specific security controls.
2. A system service provided by a commercial service provider to a large and diverse set of consumers. The organization acquiring or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not able to require that the provider implement specific controls.
3. A system service provided by a commercial service provider to a large and diverse set of consumers. The organization acquiring or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not able to require that the provider implement specific security or privacy controls.
| Identifier | MLC-T-CYB-000754 |
|---|---|
| Field | Cybersecurity |
| References | CNSSI 4009-2015 from NIST SP 800-53 Rev. 4; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000754",
"term": "commodity service",
"field": "Cybersecurity",
"definition": "1. An information system service (e.g., telecommunications service) provided by a commercial service provider typically to a large and diverse set of consumers. The organization acquiring and/or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not in a position to require that the provider implement specific security controls.\n\n2. A system service provided by a commercial service provider to a large and diverse set of consumers. The organization acquiring or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not able to require that the provider implement specific controls.\n\n3. A system service provided by a commercial service provider to a large and diverse set of consumers. The organization acquiring or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not able to require that the provider implement specific security or privacy controls.",
"references": [
"CNSSI 4009-2015 from NIST SP 800-53 Rev. 4; NIST SP 800-53 Rev. 4 [Superseded]",
"NIST SP 800-37 Rev. 2",
"NIST SP 800-53 Rev. 5",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/commodity-service/"
}
Record 754 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.