PREVIOUS

NEXT

anti-signal spoof

Result of measures used to resist attempts to achieve imitative or manipulative communications deception based on signal parameters.
Source: CNSSI No. 1200

anti-spoof

Countermeasures taken to prevent the unauthorized use of legitimate identification & authentication (I&A) data, however it was obtained, to mimic a subject different from the attacker.

anti-tamper (AT)

Systems engineering activities intended to deter and/or delay exploitation of critical technologies in a U.S. defense system in order to impede countermeasure development, unintended technology transfer, or alteration of a system.
See tampering.
Source: DoDI 5200.39

application

A software program hosted by an information system.
Source: NIST SP 800-37 Rev 1

application-specific integrated circuits (ASICs)

Custom-designed and/or custom-manufactured integrated circuits.
Source: CNSSD No. 505

approval to operate (ATO) (C.F.D.)

The official management decision issued by a designated accrediting authority (DAA) or principal accrediting authority (PAA) to authorize operation of an information system and to explicitly accept the residual risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals. See authorization to operate (ATO).
Rationale: Term has been replaced by the term “authorization to operate (ATO)”.

assembly

An item forming a portion of an equipment, that can be provisioned and replaced as an entity and which normally incorporates replaceable parts and groups of parts.
Source: DoD 4140.1-R; CNSSI No. 4033

assessment

See security control assessment or risk assessment.
Source: NIST SP 800-30 Rev 1

assessment approach

The approach used to assess risk and its contributing risk factors, including quantitatively, qualitatively, or semi-quantitatively.
Source: NIST SP 800-30 Rev 1

assessment findings

Assessment results produced by the application of an assessment procedure to a security control or control enhancement to achieve an assessment objective; the execution of a determination statement within an assessment procedure by an assessor that results in either a satisfied or other than satisfied condition.
Source: NIST SP 800-53A Rev 1