HomeGlossarySecurity & Access

Security & Access

Plain-language definitions of every Security & Access term that shows up in government contracting work.


Security & AccessCCA

Clinger-Cohen Act (CCA)

The Clinger-Cohen Act of 1996 established the Chief Information Officer role in federal agencies and created the framework for IT investment management and oversight in the federal government.

Read definition
Security & AccessCAC

Common Access Card (CAC)

The CAC is the DoD's standard smart card issued to military personnel and contractors, providing physical access to installations and logical access to DoD computer networks.

Read definition
Security & AccessCOMSEC

Communications Security (COMSEC)

COMSEC encompasses the measures taken to deny unauthorized access to telecommunications and to ensure the authenticity of communications in national security contexts.

Read definition
Security & AccessCND

Computer Network Defense (CND)

CND encompasses the actions taken to protect, monitor, analyze, detect, and respond to unauthorized activity within DoD and government information systems and networks.

Read definition
Security & AccessFASA

Federal Acquisition Streamlining Act (FASA)

FASA is the 1994 federal law that simplified government procurement by raising simplified acquisition thresholds, promoting commercial item purchasing, and reducing paperwork burdens on contractors.

Read definition
Security & AccessFOUO

For Official Use Only (FOUO)

FOUO is a legacy handling caveat for sensitive but unclassified government information, now superseded by the Controlled Unclassified Information (CUI) framework.

Read definition
Security & AccessHSAR

Homeland Security Acquisition Regulation (HSAR)

The HSAR is the Department of Homeland Security's FAR supplement that establishes DHS-specific acquisition policies, clauses, and requirements for contractors working with DHS.

Read definition
Security & AccessICAM

Identity, Credential, and Access Management (ICAM)

ICAM is the federal framework for managing digital identities, credentials, and access controls to ensure the right individuals access the right resources at the right time.

Read definition
Security & AccessINFOSEC

Information Security (INFOSEC)

INFOSEC refers to the policies, procedures, and technical controls used to protect government information and information systems from unauthorized access, use, disclosure, disruption, or destruction.

Read definition
Security & AccessOPSEC

Operations Security (OPSEC)

OPSEC is a systematic process that identifies and protects sensitive unclassified information and indicators that adversaries could exploit to harm national security or mission effectiveness.

Read definition
Security & AccessPKI

Public Key Infrastructure (PKI)

PKI is the system of cryptographic certificates, certificate authorities, and policies that federal agencies use to authenticate users, sign documents, and encrypt communications.

Read definition
Security & AccessSSP

System Security Plan (SSP)

A System Security Plan is a formal document that describes the security controls implemented in a federal information system and how they satisfy NIST requirements for authorization.

Read definition
Security & AccessUSML

United States Munitions List (USML)

The USML is the State Department's list of defense articles and services subject to International Traffic in Arms Regulations (ITAR) export licensing requirements.

Read definition

Put Security & Access to work

See how Bidovate turns these government contracting terms into pipeline. Explore the platform or book a 15-minute demo.