An abstract model of the necessary and sufficient properties that must be achieved by any mechanism that enforces a constraint.
Sources:
NIST SP 800-160v1r1
from
Engineering a Safer World – Systems Thinking Applied to Safety, ESD-TR-73-51