trustworthiness
Term · Cybersecurity · MLC-T-CYB-004445
1. The interdependent combination of attributes of a person, system, or enterprise that provides confidence to others of the qualifications, capabilities, and reliability of that entity to perform specific tasks and fulfill assigned responsibilities. The degree to which a system (including the technology components that are used to build the system) can be expected to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by the system across the full range of threats.
2. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.
3. The degree to which the behavior of a component is demonstrably compliant with its stated requirements.
4. The attribute of a person or enterprise that provides confidence to others of the qualifications, capabilities, and reliability of that entity to perform specific tasks and fulfill assigned responsibilities.
5. Computer hardware, software and procedures that - 1) are reasonably secure from intrusion and misuse;
2) provide a reasonable level of availability, reliability, and correct operation;
3) are reasonably suited to performing their intended functions; and
4) adhere to generally accepted security procedures.
6. The degree to which an information system (including the information technology components that are used to build the system) can be expected to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by the system across the full range of threats. A trustworthy information system is a system that is believed to be capable of operating within defined levels of risk despite the environmental disruptions, human errors, structural failures, and purposeful attacks that are expected to occur in its environment of operation.
7. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, business function, enterprise, or other entity.
8. Computer hardware, software and procedures that: (1) are reasonably secure from intrusion and misuse; (2) provide a reasonable level of availability, reliability, and correct operation; (3) are reasonably suited to performing their intended functions; and (4) adhere to generally accepted security procedures.
9. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity. Note: From a privacy perspective, a trustworthy system is a system that meets specific privacy requirements in addition to meeting other critical requirements.
10. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.
Note From a privacy perspective, a trustworthy system is a system that meets specific privacy requirements in addition to meeting other critical requirements.
11. Worthy of being trusted to fulfill whatever critical requirements may be needed.
12. Security decision with respect to extended investigations to determine and confirm qualifications, and suitability to perform specific tasks and responsibilities.
13. The degree to which the security behavior of a component is demonstrably compliant with its stated functionality.
14. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.
Note: From a security perspective, a trustworthy system is a system that meets specific security requirements in addition to meeting other critical requirements.
| Identifier | MLC-T-CYB-004445 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5 (adapted); NIST SP 800-160v1r1 from Neumann04; NIST SP 800-160v1r1; CNSSI 4009-2015; NIST SP 800-37 Rev. 2 from CNSSI 4009-2015; NIST SP 800-53 Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-39 from CNSSI 4009; NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009; NIST SP 800-53A Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-12 Rev. 1 from NIST SP 800-32; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-160 Vol. 1; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-160 Vol. 1; NIST SP 800-32 [Withdrawn]; NISTIR 8062 from Neumann04 (adapted), NIST SP 800-160 Vol. 1; NISTIR 8062 from Neumann04 (Derived), NIST SP 800-160 Vol. 1; NISTIR 8320A from NIST SP 800-160 Vol. 2 (Adapted from "trustworthiness"); NISTIR 8320B from NIST SP 800-160 Vol. 2 Rev. 1 (adapted); FIPS 201 [version unknown]; NIST SP 800-160 Vol. 1; NIST SP 800-160 Vol. 1 from Neumann04; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-004445",
"term": "trustworthiness",
"field": "Cybersecurity",
"definition": "1. The interdependent combination of attributes of a person, system, or enterprise that provides confidence to others of the qualifications, capabilities, and reliability of that entity to perform specific tasks and fulfill assigned responsibilities. The degree to which a system (including the technology components that are used to build the system) can be expected to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by the system across the full range of threats.\n\n2. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.\n\n3. The degree to which the behavior of a component is demonstrably compliant with its stated requirements.\n\n4. The attribute of a person or enterprise that provides confidence to others of the qualifications, capabilities, and reliability of that entity to perform specific tasks and fulfill assigned responsibilities.\n\n5. Computer hardware, software and procedures that - 1) are reasonably secure from intrusion and misuse;\n2) provide a reasonable level of availability, reliability, and correct operation;\n3) are reasonably suited to performing their intended functions; and\n4) adhere to generally accepted security procedures.\n\n6. The degree to which an information system (including the information technology components that are used to build the system) can be expected to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by the system across the full range of threats. A trustworthy information system is a system that is believed to be capable of operating within defined levels of risk despite the environmental disruptions, human errors, structural failures, and purposeful attacks that are expected to occur in its environment of operation.\n\n7. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, business function, enterprise, or other entity.\n\n8. Computer hardware, software and procedures that: (1) are reasonably secure from intrusion and misuse; (2) provide a reasonable level of availability, reliability, and correct operation; (3) are reasonably suited to performing their intended functions; and (4) adhere to generally accepted security procedures.\n\n9. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity. Note: From a privacy perspective, a trustworthy system is a system that meets specific privacy requirements in addition to meeting other critical requirements.\n\n10. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.\nNote From a privacy perspective, a trustworthy system is a system that meets specific privacy requirements in addition to meeting other critical requirements.\n\n11. Worthy of being trusted to fulfill whatever critical requirements may be needed.\n\n12. Security decision with respect to extended investigations to determine and confirm qualifications, and suitability to perform specific tasks and responsibilities.\n\n13. The degree to which the security behavior of a component is demonstrably compliant with its stated functionality.\n\n14. Worthy of being trusted to fulfill whatever critical requirements may be needed for a particular component, subsystem, system, network, application, mission, enterprise, or other entity.\nNote: From a security perspective, a trustworthy system is a system that meets specific security requirements in addition to meeting other critical requirements.",
"references": [
"NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5 (adapted)",
"NIST SP 800-160v1r1 from Neumann04",
"NIST SP 800-160v1r1",
"CNSSI 4009-2015; NIST SP 800-37 Rev. 2 from CNSSI 4009-2015; NIST SP 800-53 Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-39 from CNSSI 4009; NIST SP 800-53 Rev. 4 [Superseded] from CNSSI 4009; NIST SP 800-53A Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022",
"NIST SP 800-12 Rev. 1 from NIST SP 800-32",
"NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-53 Rev. 4 [Superseded]",
"NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-160 Vol. 1; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-160 Vol. 1",
"NIST SP 800-32 [Withdrawn]",
"NISTIR 8062 from Neumann04 (adapted), NIST SP 800-160 Vol. 1",
"NISTIR 8062 from Neumann04 (Derived), NIST SP 800-160 Vol. 1",
"NISTIR 8320A from NIST SP 800-160 Vol. 2 (Adapted from \"trustworthiness\"); NISTIR 8320B from NIST SP 800-160 Vol. 2 Rev. 1 (adapted)",
"FIPS 201 [version unknown]",
"NIST SP 800-160 Vol. 1",
"NIST SP 800-160 Vol. 1 from Neumann04",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/trustworthiness/"
}
Record 4,445 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.