Plain-English definitions of the fifty acronyms federal technology runs on — from A&A and ATO to XACTA and Zero Trust, cross-linked to full explainers.
Fifty terms, defined plainly. Bookmark it, send it to the new hire, win the acronym argument. Cross-linked to our full explainers where they exist.
A&A — Assessment and Authorization — the end-to-end process of evaluating a system's security and granting it authority to operate.
ACAS — Assured Compliance Assessment Solution — DoD's Tenable-based vulnerability scanning suite.
AO — Authorizing Official — the executive who formally accepts a system's risk and signs the ATO.
ATO — Authority to Operate — formal approval for an information system to run in production. Full explainer.
ATP — Authorization to Proceed — customer go-ahead that lets contract work (or a hire) begin.
cATO — Continuous ATO — authorization sustained by live monitoring instead of periodic reauthorization. Full explainer.
CAGE Code — Commercial and Government Entity code — a five-character ID assigned to entities doing business with the government.
CDS — Cross-Domain Solution — accredited technology that moves data between networks at different classification levels.
CI Polygraph — Counterintelligence-scope polygraph — required for many TS/SCI programs; narrower than a full-scope poly.
CMMC — Cybersecurity Maturity Model Certification — DoD's supply-chain cybersecurity certification. Full explainer.
CNSSI 1253 — The committee instruction that adapts NIST categorization and controls for national security systems.
ConMon — Continuous Monitoring — ongoing verification that controls remain effective after authorization.
CSDM — Common Service Data Model — ServiceNow's standard for structuring service and CMDB data.
CUI — Controlled Unclassified Information — sensitive but unclassified data requiring safeguarding (the data CMMC protects).
DIB — Defense Industrial Base — the contractors and suppliers behind DoD programs.
DISA — Defense Information Systems Agency — operates DoD networks and publishes STIGs.
DoD 8140/8570 — The directives defining cyber workforce certification requirements (IAT/IAM levels).
eMASS — DoD's system of record for A&A packages. Compared with XACTA here.
FedRAMP — The federal authorization program for cloud services — authorize once, reuse across agencies. Comparison.
FIPS-199 — The standard for categorizing systems by impact level (low/moderate/high) — RMF step one.
FISMA — The federal law requiring agencies to secure information systems — the statutory root of most of this glossary.
FSP — Full Scope Polygraph — combined lifestyle and CI polygraph; the most exclusive clearance tier in the market.
GRC / IRM — Governance, Risk, and Compliance (ServiceNow's module family is Integrated Risk Management). Explainer.
IAT / IAM — Information Assurance Technical/Management certification levels under DoD 8570 (e.g., Security+ = IAT II).
ICD 503 — The Intelligence Community directive governing risk management and accreditation of IC systems.
IL2–IL6 — DoD cloud Impact Levels — from public-releasable (IL2) through classified (IL6).
ISSE — Information Systems Security Engineer — engineers security into systems through design and ATO.
ISSM — Information Systems Security Manager — leads the security program across a portfolio of systems.
ISSO — Information Systems Security Officer — owns day-to-day security posture and documentation for assigned systems.
JSIG — Joint SAP Implementation Guide — RMF guidance for special access programs.
Low-to-High — Developing in unclassified environments and promoting into classified ones. Full explainer.
NIST 800-53 — The master catalog of security and privacy controls underlying RMF, FedRAMP, and ICD 503.
NIST 800-171 — The control set protecting CUI in non-federal systems — the technical heart of CMMC Level 2.
POA&M — Plan of Action and Milestones — the tracked list of findings, fixes, owners, and deadlines in an authorization package.
RMF — Risk Management Framework — NIST's six-step process from categorization to continuous monitoring.
Right-to-Represent — A candidate's written authorization for one firm to submit them to a specific role — the consent document behind ethical recruiting.
SAP — Special Access Program — protections beyond standard classification for the most sensitive efforts.
SBOM — Software Bill of Materials — the ingredient list of components in a piece of software; central to supply-chain security.
SCA — Security Control Assessor — independently tests controls and produces assessment findings.
SCI — Sensitive Compartmented Information — intelligence requiring access approvals beyond Top Secret.
SCIF — Sensitive Compartmented Information Facility — an accredited space where SCI can be handled.
SIEM — Security Information and Event Management — the alerting/analytics platform at the center of a SOC (e.g., Splunk).
SPRS — Supplier Performance Risk System — where DoD contractors report their NIST 800-171 self-assessment scores.
SSP — System Security Plan — the master document describing a system, its boundary, and control implementations.
STIG — Security Technical Implementation Guide — DISA's hardening standards; 'STIG'd' means configured to them.
TS/SCI — Top Secret clearance with SCI eligibility — the entry ticket to most IC technical work. Clearance ladder.
UEI — Unique Entity Identifier — the SAM.gov identity for entities doing business with the government.
XACTA — Telos's A&A platform, common in the IC. Compared with eMASS here.
Zero Trust — Security architecture that verifies every access continuously — never trust, always verify, regardless of network location.
This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.
Talk to AusperThis site uses essential browser storage only. With your OK, we’d also use analytics cookies to understand which content is useful. No choice is required — “Essential only” changes nothing. Cookie policy