Object, Assessment
Term · Cybersecurity · MLC-T-CYB-002900
1. The item (i.e., specifications, mechanisms, activities, individuals) upon which an assessment method is applied during an assessment.
2. The item (specifications, mechanisms, activities, individuals) upon which an assessment method is applied during an assessment.
3. Passive system-related entity, including bits, bytes, words, fields, devices, files, records, programs, tables, processes, programs, segments, directories, processors, and domains that contain or receive information. Access to an object (by a subject) implies access to the information it contains. Note: Sometimes referred to as "resource."
4. the set of passive entities within the system, protected from unauthorized use.
5. A passive entity that contains or receives information.
6. See Object, Assessment.
7. Assessment objects identify the specific items being assessed, and as such, can have one or more security defects. Assessment objects include specifications, mechanisms, activities, and individuals which in turn may include, but are not limited to, devices, software products, software executables, credentials, accounts, account-privileges, things to which privileges are granted (including data and physical facilities), etc. See SP 800-53A.
| Identifier | MLC-T-CYB-002900 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | Object |
| Synonyms | Assessment Object |
| References | NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-137 from NISTIR 7298; NIST SP 800-53 Rev. 4 [Superseded]; NISTIR 6192; NISTIR 7316; NISTIR 8011 Vol. 1; NISTIR 8011 Vol. 1; NISTIR 8011 Vol. 1; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-002900",
"term": "Object, Assessment",
"field": "Cybersecurity",
"definition": "1. The item (i.e., specifications, mechanisms, activities, individuals) upon which an assessment method is applied during an assessment.\n\n2. The item (specifications, mechanisms, activities, individuals) upon which an assessment method is applied during an assessment.\n\n3. Passive system-related entity, including bits, bytes, words, fields, devices, files, records, programs, tables, processes, programs, segments, directories, processors, and domains that contain or receive information. Access to an object (by a subject) implies access to the information it contains. Note: Sometimes referred to as \"resource.\"\n\n4. the set of passive entities within the system, protected from unauthorized use.\n\n5. A passive entity that contains or receives information.\n\n6. See Object, Assessment.\n\n7. Assessment objects identify the specific items being assessed, and as such, can have one or more security defects. Assessment objects include specifications, mechanisms, activities, and individuals which in turn may include, but are not limited to, devices, software products, software executables, credentials, accounts, account-privileges, things to which privileges are granted (including data and physical facilities), etc. See SP 800-53A.",
"abbreviation": "Object",
"synonyms": [
"Assessment Object"
],
"references": [
"NIST SP 800-53A Rev. 4 [Superseded]",
"NIST SP 800-137 from NISTIR 7298",
"NIST SP 800-53 Rev. 4 [Superseded]",
"NISTIR 6192",
"NISTIR 7316",
"NISTIR 8011 Vol. 1; NISTIR 8011 Vol. 1",
"NISTIR 8011 Vol. 1",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/object-assessment/"
}
Record 2,884 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.