profile
Term · Cybersecurity · MLC-T-CYB-003308
1. A document that provides an implementation-independent specification of CKMS security requirements for use by a community of interest (e.g., U.S. Government, banking, health, or aerospace).
2. The specifications for Federal CKMSs in SP 800-152, including the requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by Federal organizations and their contractors
3. A profile is a baseline set of minimal cybersecurity requirements for mitigating described threats and vulnerabilities, as well as supporting compliance requirements for a defined scope and type of a particular use case (e.g., industry, information system(s)), using a combination of existing cybersecurity guidance, standards and/or specifications baseline documents or catalogs. A profile organizes selected guidance, standard(s) and/or specification(s) and may narrow, expand and/or otherwise tailor items from the starting material to address the requirements of the profile’s target application.
4. the desired outcome or ‘to be’ state of cybersecurity implementation
5. the ‘as is’ state of system cybersecurity
6. A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories.
7. Profiles define conforming subsets or combinations of base standards used to provide specific functions. Profiles identify the use of particular options available in the base standards, and provide a basis for the development of uniform, internationally recognized, conformance tests.
8. A named tailoring of a benchmark.
9. A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories. [CSF] - Target Profile - the desired outcome or "to be" state of cybersecurity implementaton, - Current profile - the "as is" state of system security.
10. A selection of specific Functions, Categories, and Subcategories from the Core that an organization has prioritized to help it manage privacy risk.
11. A representation of the outcomes that a particular system or organization has selected from the CSF Categories and Subcategories.
| Identifier | MLC-T-CYB-003308 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-152; NIST SP 800-213; NISTIR 8183; NISTIR 8183 from NIST Cybersecurity Framework Version 1.0; NISTIR 8183 Rev. 1 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 1 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 2 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 3 from NIST Cybersecurity Framework Version 1.1; NIST IR 8270; NISTIR 8074 Vol. 2 from ISO/IEC TR 10000-1:1998; NISTIR 7275 Rev. 4; NIST Privacy Framework Version 1.0; NIST IR 8406 [Update 1]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003308",
"term": "profile",
"field": "Cybersecurity",
"definition": "1. A document that provides an implementation-independent specification of CKMS security requirements for use by a community of interest (e.g., U.S. Government, banking, health, or aerospace).\n\n2. The specifications for Federal CKMSs in SP 800-152, including the requirements for their design, implementation, procurement, installation, configuration, management, operation, and use by Federal organizations and their contractors\n\n3. A profile is a baseline set of minimal cybersecurity requirements for mitigating described threats and vulnerabilities, as well as supporting compliance requirements for a defined scope and type of a particular use case (e.g., industry, information system(s)), using a combination of existing cybersecurity guidance, standards and/or specifications baseline documents or catalogs. A profile organizes selected guidance, standard(s) and/or specification(s) and may narrow, expand and/or otherwise tailor items from the starting material to address the requirements of the profile’s target application.\n\n4. the desired outcome or ‘to be’ state of cybersecurity implementation\n\n5. the ‘as is’ state of system cybersecurity\n\n6. A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories.\n\n7. Profiles define conforming subsets or combinations of base standards used to provide specific functions. Profiles identify the use of particular options available in the base standards, and provide a basis for the development of uniform, internationally recognized, conformance tests.\n\n8. A named tailoring of a benchmark.\n\n9. A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories. [CSF] - Target Profile - the desired outcome or \"to be\" state of cybersecurity implementaton, - Current profile - the \"as is\" state of system security.\n\n10. A selection of specific Functions, Categories, and Subcategories from the Core that an organization has prioritized to help it manage privacy risk.\n\n11. A representation of the outcomes that a particular system or organization has selected from the CSF Categories and Subcategories.",
"references": [
"NIST SP 800-152",
"NIST SP 800-213",
"NISTIR 8183",
"NISTIR 8183 from NIST Cybersecurity Framework Version 1.0; NISTIR 8183 Rev. 1 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 1 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 2 from NIST Cybersecurity Framework Version 1.1; NISTIR 8183A Vol. 3 from NIST Cybersecurity Framework Version 1.1; NIST IR 8270",
"NISTIR 8074 Vol. 2 from ISO/IEC TR 10000-1:1998",
"NISTIR 7275 Rev. 4",
"NIST Privacy Framework Version 1.0",
"NIST IR 8406 [Update 1]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/profile/"
}
Record 3,308 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.