// Capability Statement — Download PDF
Insights / Glossary
Glossary

The govcon glossary.

Plain-English definitions of the fifty acronyms federal technology runs on — from A&A and ATO to XACTA and Zero Trust, cross-linked to full explainers.

Fifty terms, defined plainly. Bookmark it, send it to the new hire, win the acronym argument. Cross-linked to our full explainers where they exist.

A

A&A — Assessment and Authorization — the end-to-end process of evaluating a system's security and granting it authority to operate.

ACAS — Assured Compliance Assessment Solution — DoD's Tenable-based vulnerability scanning suite.

AO — Authorizing Official — the executive who formally accepts a system's risk and signs the ATO.

ATO — Authority to Operate — formal approval for an information system to run in production. Full explainer.

ATP — Authorization to Proceed — customer go-ahead that lets contract work (or a hire) begin.

C

cATO — Continuous ATO — authorization sustained by live monitoring instead of periodic reauthorization. Full explainer.

CAGE Code — Commercial and Government Entity code — a five-character ID assigned to entities doing business with the government.

CDS — Cross-Domain Solution — accredited technology that moves data between networks at different classification levels.

CI Polygraph — Counterintelligence-scope polygraph — required for many TS/SCI programs; narrower than a full-scope poly.

CMMC — Cybersecurity Maturity Model Certification — DoD's supply-chain cybersecurity certification. Full explainer.

CNSSI 1253 — The committee instruction that adapts NIST categorization and controls for national security systems.

ConMon — Continuous Monitoring — ongoing verification that controls remain effective after authorization.

CSDM — Common Service Data Model — ServiceNow's standard for structuring service and CMDB data.

CUI — Controlled Unclassified Information — sensitive but unclassified data requiring safeguarding (the data CMMC protects).

D

DIB — Defense Industrial Base — the contractors and suppliers behind DoD programs.

DISA — Defense Information Systems Agency — operates DoD networks and publishes STIGs.

DoD 8140/8570 — The directives defining cyber workforce certification requirements (IAT/IAM levels).

E

eMASS — DoD's system of record for A&A packages. Compared with XACTA here.

F

FedRAMP — The federal authorization program for cloud services — authorize once, reuse across agencies. Comparison.

FIPS-199 — The standard for categorizing systems by impact level (low/moderate/high) — RMF step one.

FISMA — The federal law requiring agencies to secure information systems — the statutory root of most of this glossary.

FSP — Full Scope Polygraph — combined lifestyle and CI polygraph; the most exclusive clearance tier in the market.

G

GRC / IRM — Governance, Risk, and Compliance (ServiceNow's module family is Integrated Risk Management). Explainer.

I

IAT / IAM — Information Assurance Technical/Management certification levels under DoD 8570 (e.g., Security+ = IAT II).

ICD 503 — The Intelligence Community directive governing risk management and accreditation of IC systems.

IL2–IL6 — DoD cloud Impact Levels — from public-releasable (IL2) through classified (IL6).

ISSE — Information Systems Security Engineer — engineers security into systems through design and ATO.

ISSM — Information Systems Security Manager — leads the security program across a portfolio of systems.

ISSO — Information Systems Security Officer — owns day-to-day security posture and documentation for assigned systems.

J

JSIG — Joint SAP Implementation Guide — RMF guidance for special access programs.

L

Low-to-High — Developing in unclassified environments and promoting into classified ones. Full explainer.

N

NIST 800-53 — The master catalog of security and privacy controls underlying RMF, FedRAMP, and ICD 503.

NIST 800-171 — The control set protecting CUI in non-federal systems — the technical heart of CMMC Level 2.

P

POA&M — Plan of Action and Milestones — the tracked list of findings, fixes, owners, and deadlines in an authorization package.

R

RMF — Risk Management Framework — NIST's six-step process from categorization to continuous monitoring.

Right-to-Represent — A candidate's written authorization for one firm to submit them to a specific role — the consent document behind ethical recruiting.

S

SAP — Special Access Program — protections beyond standard classification for the most sensitive efforts.

SBOM — Software Bill of Materials — the ingredient list of components in a piece of software; central to supply-chain security.

SCA — Security Control Assessor — independently tests controls and produces assessment findings.

SCI — Sensitive Compartmented Information — intelligence requiring access approvals beyond Top Secret.

SCIF — Sensitive Compartmented Information Facility — an accredited space where SCI can be handled.

SIEM — Security Information and Event Management — the alerting/analytics platform at the center of a SOC (e.g., Splunk).

SPRS — Supplier Performance Risk System — where DoD contractors report their NIST 800-171 self-assessment scores.

SSP — System Security Plan — the master document describing a system, its boundary, and control implementations.

STIG — Security Technical Implementation Guide — DISA's hardening standards; 'STIG'd' means configured to them.

T

TS/SCI — Top Secret clearance with SCI eligibility — the entry ticket to most IC technical work. Clearance ladder.

U

UEI — Unique Entity Identifier — the SAM.gov identity for entities doing business with the government.

X

XACTA — Telos's A&A platform, common in the IC. Compared with eMASS here.

Z

Zero Trust — Security architecture that verifies every access continuously — never trust, always verify, regardless of network location.

Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper