Policy
Term · Cybersecurity · MLC-T-CYB-003181
1. The set of basic principles and associated guidelines, formulated and enforced by the governing body of an organization, to direct and limit its actions in pursuit of long-term goals.
2. The representation of rules or relationships that makes it possible to determine if a requested access should be allowed, given the values of the attributes of the subject/entity, object/resource, and possibly environment conditions.
3. Statements, rules or assertions that specify the correct or expected behavior of an entity. For example, an authorization policy might specify the correct access control rules for a software component.
4. Statements, rules, or assertions that specify the correct or expected behavior of an entity. For example, an authorization policy might specify the correct access control rules for a software component.
5. A statement of objectives, rules, practices or regulations governing the activities of people within a certain context.
| Identifier | MLC-T-CYB-003181 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-175A; CNSSI 4009-2022 from NIST SP 800-162 (adapted); NIST SP 800-95 from Open Grid Services Architecture Glossary of Terms; NISTIR 7621 Rev. 1 from NIST SP 800-95; NIST SP 1800-15B from NIST SP 800-95, NISTIR 7621 Rev. 1; NIST SP 1800-15C from NIST SP 800-95, NISTIR 7621 Rev. 1; NISTIR 4734; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003181",
"term": "Policy",
"field": "Cybersecurity",
"definition": "1. The set of basic principles and associated guidelines, formulated and enforced by the governing body of an organization, to direct and limit its actions in pursuit of long-term goals.\n\n2. The representation of rules or relationships that makes it possible to determine if a requested access should be allowed, given the values of the attributes of the subject/entity, object/resource, and possibly environment conditions.\n\n3. Statements, rules or assertions that specify the correct or expected behavior of an entity. For example, an authorization policy might specify the correct access control rules for a software component.\n\n4. Statements, rules, or assertions that specify the correct or expected behavior of an entity. For example, an authorization policy might specify the correct access control rules for a software component.\n\n5. A statement of objectives, rules, practices or regulations governing the activities of people within a certain context.",
"references": [
"NIST SP 800-175A",
"CNSSI 4009-2022 from NIST SP 800-162 (adapted)",
"NIST SP 800-95 from Open Grid Services Architecture Glossary of Terms; NISTIR 7621 Rev. 1 from NIST SP 800-95",
"NIST SP 1800-15B from NIST SP 800-95, NISTIR 7621 Rev. 1; NIST SP 1800-15C from NIST SP 800-95, NISTIR 7621 Rev. 1",
"NISTIR 4734",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/policy/"
}
Record 3,181 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.