A passive entity that contains or receives information. Note that access to an object potentially implies access to the information it contains.
Source(s):
NIST SP 800-33
[Withdrawn]
NIST SP 800-27 Rev. A
[Withdrawn]
Passive information system-related entity (e.g., devices, files, records, tables, processes, programs, domains) containing or receiving information. Access to an object (by a subject) implies access to the information it contains. See subject.
Source(s):
CNSSI 4009-2015
NIST SP 800-53 Rev. 4
NIST SP 800-53 Rev. 4
under Object
the set of passive entities within the system, protected from unauthorized use.
Source(s):
NISTIR 6192
under Object
A passive entity that contains or receives information.
Source(s):
NISTIR 7316
under Object
See Object, Assessment.
Source(s):
NISTIR 8011 Vol. 1
under Object
Assessment objects identify the specific items being assessed, and as such, can have one or more security defects. Assessment objects include specifications, mechanisms, activities, and individuals which in turn may include, but are not limited to, devices, software products, software executables, credentials, accounts, account-privileges, things to which privileges are granted (including data and physical facilities), etc. See SP 800-53A.
Source(s):
NISTIR 8011 Vol. 1
under Object, Assessment