control assessment
Term · Cybersecurity · MLC-T-CYB-000927
1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.
2. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
3. See control assessment or risk assessment.
4. The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.
5. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or
6. The vehicle or template or worksheet that is used for each evaluation.
7. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.
| Identifier | MLC-T-CYB-000927 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | assessment |
| References | CNSSI 4009-2022; CNSSI 4009-2022 from OMB Circular A-130 (2016) (under "security control assessment"); NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-53A Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-137A; NIST SP 800-55v1; NIST SP 800-55v2; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000927",
"term": "control assessment",
"field": "Cybersecurity",
"definition": "1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.\n\n2. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.\n\n3. See control assessment or risk assessment.\n\n4. The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.\n\n5. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or\n\n6. The vehicle or template or worksheet that is used for each evaluation.\n\n7. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.",
"abbreviation": "assessment",
"references": [
"CNSSI 4009-2022",
"CNSSI 4009-2022 from OMB Circular A-130 (2016) (under \"security control assessment\")",
"NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
"NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-37 Rev. 2; NIST SP 800-53A Rev. 5 from NIST SP 800-37 Rev. 2",
"NIST SP 800-137A",
"NIST SP 800-55v1; NIST SP 800-55v2",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/control-assessment/"
}
Record 927 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.