U.S. flag   An official website of the United States government
A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

security control assessment

Abbreviation(s) and Synonym(s):

Definition(s):

  The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
Source(s):
CNSSI 4009-2015 NIST SP 800-37 Rev. 1
NIST SP 800-137 under Security Control Assessment CNSSI 4009 - Adapted
NIST SP 800-37 Rev. 1 under Security Control Assessment

  The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
Source(s):
NIST SP 800-171 Rev. 2 OMB Circular A-130
NIST SP 800-37 Rev. 2
NIST SP 800-53 Rev. 4 under Security Control Assessment CNSSI 4009 - Adapted
NIST SP 800-53A Rev. 4 under Security Control Assessment

  The testing and/or evaluation of the management, operational, and technical security controls in a system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
Source(s):
NIST SP 800-12 Rev. 1 under Security Control Assessment NIST SP 800-37

  See Security Control Assessment.
Source(s):
NIST SP 800-137 under Assessment
NIST SP 800-37 Rev. 1 under Assessment
NIST SP 800-39 under Assessment
NIST SP 800-53 Rev. 4 under Assessment
NIST SP 800-171 Rev. 2 under assessment
NIST SP 800-171 Rev. 2 under security assessment
NIST SP 800-53 Rev. 4 under Security Assessment
NIST SP 800-171 Rev. 1 under assessment [Superseded]
NIST SP 800-171 Rev. 1 under security assessment [Superseded]

  See Security Control Assessment or Privacy Control Assessment.
Source(s):
NIST SP 800-53A Rev. 4 under Assessment

  See control assessment or risk assessment.
Source(s):
NIST SP 800-37 Rev. 2 under assessment

  See security control assessment or risk assessment.
Source(s):
CNSSI 4009-2015 under assessment NIST SP 800-30 Rev. 1
NIST SP 800-30 Rev. 1 under Assessment

  The testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
Source(s):
NIST SP 800-30 Rev. 1 under Security Control Assessment NIST SP 800-39, CNSSI 4009 - Adapted
NIST SP 800-39 under Security Control Assessment CNSSI 4009 - Adapted

  A completed or planned action of evaluation of an organization, a mission or business process, or one or more systems and their environments; or
Source(s):
NIST SP 800-137A under assessment

  The vehicle or template or worksheet that is used for each evaluation.
Source(s):
NIST SP 800-137A under assessment

  The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for a system or organization.
Source(s):
NIST SP 800-171 Rev. 1 [Superseded] CNSSI 4009 - Adapted