> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/security-vetting-and-technical-assurance-playbook/glossary.md).

# Glossary

### ABAC

Attribute-Based Access Control. Access decisions based on attributes such as role, clearance, project, classification, device, location or risk context.

### BPSS

Baseline Personnel Security Standard. A baseline screening process, not a national security clearance.

### CAF

Cyber Assessment Framework. NCSC framework for assessing cyber resilience for organisations responsible for essential functions.

### CSM

Cyber Security Model. MOD model for assessing supplier cyber risk and control requirements.

### DEFCON 658

MOD defence condition used to contractually apply cyber security requirements.

### DPIA

Data Protection Impact Assessment.

### Def Stan 05-138

Defence standard specifying cyber controls for defence suppliers at each cyber risk profile level.

### IAM

Identity and Access Management.

### JML

Joiners, Movers and Leavers access lifecycle process.

### JSP 453

MOD Digital Policies and Standards for Defence. Treat as customer or sponsor-controlled where applicable.

### Least privilege

Granting only the access required to perform an approved function.

### Need-to-know

Access only where the individual has a legitimate business or operational need.

### OFFICIAL-SENSITIVE

A handling caveat used where OFFICIAL information needs additional handling protection.

### PAM

Privileged Access Management.

### RBAC

Role-Based Access Control.

### RPO

Recovery Point Objective.

### RTO

Recovery Time Objective.

### SBOM

Software Bill of Materials.

### Secure by Design

Approach that embeds security throughout planning, design, delivery and operation.

### Zero trust

Architecture approach that removes inherent trust from networks and verifies access requests against policy.
