A combination of mutually-reinforcing security controls (i.e., safeguards and countermeasures) implemented by technical means (i.e., functionality in hardware, software, and firmware), physical means (i.e., physical devices and protective measures), and procedural means (i.e., procedures performed by individuals).
Source(s):
NIST SP 800-53 Rev. 4
NIST SP 800-53A Rev. 4
See Capability, Security.
Source(s):
NISTIR 8011 Vol. 1
A set of mutually reinforcing security controls implemented by technical, physical, and procedural means. Such controls are typically selected to achieve a common information security-related purpose.
Source(s):
NISTIR 8011 Vol. 1
under Capability, Security