| |
| | rfc2828.txt |
 | | For the term "security service", for example, the "O" definition deals narrowly with only communication services provided by layers in the OSI model and is inadequate for the full range of ISD usage; the "I" definition can be used in more situations and for more kinds of service. |
 | | (See: authenticate, authentication, validate vs. verify) $ authority (D) "An entity, responsible for the issuance of certificates." [FPDAM] (C) ISDs SHOULD NOT use this term as a synonym for AA, CA, RA, ORA, or similar terms, because it may cause confusion. |
 | | In actual practice, however, entities outside a security perimeter that can receive output from the system but cannot provide input or otherwise directly interact with the system, might be treated as not having "access" and, therefore, be exempt from security policy requirements, such as the need for a security clearance. |
| www.ietf.org /rfc/rfc2828.txt (733 words) |
|