Security control assessment
Term · Cybersecurity · MLC-T-CYB-003795
1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.
2. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.
3. The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
4. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
5. The testing and/or evaluation of the management, operational, and technical security controls in a system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
6. See Security Control Assessment.
7. See Security Control Assessment or Privacy Control Assessment.
8. See control assessment or risk assessment.
9. See security control assessment or risk assessment.
10. The testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
11. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or
12. The vehicle or template or worksheet that is used for each evaluation.
13. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for a system or organization.
| Identifier | MLC-T-CYB-003795 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | assessment |
| Synonyms | security assessment |
| References | CNSSI 4009-2022; NIST SP 800-55v1; NIST SP 800-55v2; CNSSI 4009-2015 from NIST SP 800-37 Rev. 1; NIST SP 800-137 from CNSSI 4009 (Adapted); NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-172 [Superseded] from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009 (Adapted); NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-172A [Superseded] from OMB Circular A-130 (2016); NIST SP 800-171 Rev. 2 [Superseded] from OMB Circular A-130 (2016); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-172r3 from NIST SP 800-39; NIST SP 800-172Ar3 from OMB Circular A-130 (2016); NIST SP 800-12 Rev. 1 from NIST SP 800-37; NIST SP 800-137; NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-39; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-171 Rev. 2 [Superseded]; NIST SP 800-172 [Superseded]; NIST SP 800-171 Rev. 2 [Superseded]; NIST SP 800-172 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-171 Rev. 1 [Superseded]; NIST SP 800-171 Rev. 1 [Superseded]; NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; CNSSI 4009-2015 from NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1 from NIST SP 800-39, CNSSI 4009 (Adapted); NIST SP 800-39 from CNSSI 4009 (Adapted); NIST SP 800-137A; NIST SP 800-171 Rev. 1 [Superseded] from CNSSI 4009 (Adapted); NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003795",
"term": "Security control assessment",
"field": "Cybersecurity",
"definition": "1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.\n\n2. The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.\n\n3. The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.\n\n4. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.\n\n5. The testing and/or evaluation of the management, operational, and technical security controls in a system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.\n\n6. See Security Control Assessment.\n\n7. See Security Control Assessment or Privacy Control Assessment.\n\n8. See control assessment or risk assessment.\n\n9. See security control assessment or risk assessment.\n\n10. The testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.\n\n11. A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or\n\n12. The vehicle or template or worksheet that is used for each evaluation.\n\n13. The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for a system or organization.",
"abbreviation": "assessment",
"synonyms": [
"security assessment"
],
"references": [
"CNSSI 4009-2022",
"NIST SP 800-55v1; NIST SP 800-55v2",
"CNSSI 4009-2015 from NIST SP 800-37 Rev. 1; NIST SP 800-137 from CNSSI 4009 (Adapted); NIST SP 800-37 Rev. 1 [Superseded]",
"NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-172 [Superseded] from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009 (Adapted); NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-172A [Superseded] from OMB Circular A-130 (2016); NIST SP 800-171 Rev. 2 [Superseded] from OMB Circular A-130 (2016); NIST SP 800-171Ar3 from OMB Circular A-130 (2016); NIST SP 800-171r3 from OMB Circular A-130 (2016); NIST SP 800-172r3 from NIST SP 800-39; NIST SP 800-172Ar3 from OMB Circular A-130 (2016)",
"NIST SP 800-12 Rev. 1 from NIST SP 800-37",
"NIST SP 800-137; NIST SP 800-37 Rev. 1 [Superseded]; NIST SP 800-39; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-171 Rev. 2 [Superseded]; NIST SP 800-172 [Superseded]; NIST SP 800-171 Rev. 2 [Superseded]; NIST SP 800-172 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-171 Rev. 1 [Superseded]; NIST SP 800-171 Rev. 1 [Superseded]",
"NIST SP 800-53A Rev. 4 [Superseded]",
"NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
"CNSSI 4009-2015 from NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1",
"NIST SP 800-30 Rev. 1 from NIST SP 800-39, CNSSI 4009 (Adapted); NIST SP 800-39 from CNSSI 4009 (Adapted)",
"NIST SP 800-137A",
"NIST SP 800-171 Rev. 1 [Superseded] from CNSSI 4009 (Adapted)",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/security-control-assessment/"
}
Record 3,776 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.