Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

control assessment

Abbreviations / Acronyms / Synonyms:

assessment

Definitions:

  An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent, impact, or capabilities of an item, organization, group, policy, activity, or person. Note: Assessments are generally informational in nature and used to support decision making and to inform formal inspections or audits. Assessments may consider information garnered from past audits, inspections, risk analyses, incident reports, intelligence collection, and other related activities, but are considered separate from these activities.
Sources:
CNSSI 4009-2022 under assessment

  The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
Sources:
CNSSI 4009-2022 from OMB Circular A-130 (2016) - under "security control assessment"

  See control assessment or risk assessment.
Sources:
NIST SP 800-37 Rev. 2 under assessment
NIST SP 800-53 Rev. 5 under assessment
NIST SP 800-53A Rev. 5 under assessment

  The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.
Sources:
NIST SP 800-37 Rev. 2
NIST SP 800-53 Rev. 5 from NIST SP 800-37 Rev. 2
NIST SP 800-53A Rev. 5 from NIST SP 800-37 Rev. 2

  A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or
Sources:
NIST SP 800-137A under assessment

  The vehicle or template or worksheet that is used for each evaluation.
Sources:
NIST SP 800-137A under assessment

  The action of evaluating, estimating, or judging against defined criteria. Different types of assessment (i.e., qualitative, quantitative, and semi-quantitative) are used to assess risk. Some types of assessment yield results.
Sources:
NIST SP 800-55v1 under assessment
NIST SP 800-55v2 under assessment