Cybersecurity terminology · MLC-0102
Cybersecurity terms: A (366)
- A1. The associated data string.
- a | xa divides x.
- [a, b]1. The set of integers x, such that a ≤ x ≤ b.
- a mod bThe modulo operation of integers a and b. “a mod b” returns the remainder after dividing a by b.
- {a1, ...ai}The internal state of the DRBG at a point in time. The types and number of the ai values depends on the...
- AAAn entity, recognized by the Federal PKI Policy Authority or comparable Agency body as having the authority...
- AADThe input data to the authenticated encryption function that is authenticated but not encrypted.
- AAL1. A list of applications and application components (libraries, configuration files, etc.) that are...
- AARA document containing findings and recommendations from an exercise or a test.
- ABAC1. An access control approach in which access is mediated based on attributes associated with subjects...
- Abbreviated Dialing Numbersphone book entries kept on the SIM.
- absolute errorThe absolute difference between the noisy and unaltered versions of a query’s output.
- abstractionView of an object that focuses on the information relevant to a particular purpose and ignores the remainder...
- AC1. The process of granting or denying specific requests to 1) obtain and use information and related...
- Acceptable RiskLevel of residual risk to the organization’s operations, assets, or individuals that falls within the defined...
- acceptable use agreementSee user agreement.
- access agreementSee user agreement.
- access and amendmentA privacy principle (FIPP) that refers to an organization's requirements to provide individuals with...
- access authorityAn entity responsible for monitoring and granting access privileges for other authorized entities.
- Access Complexity1. reflects the complexity of the attack required to exploit the software feature misuse vulnerability.
- access control1. The process of granting or denying specific requests to 1) obtain and use information and related...
- access control list1. A mechanism that implements access control for a system resource by enumerating the system entities that...
- Access Control MatrixA table in which each row represents a subject, each column represents an object, and each entry is the set...
- access control mechanism1. Security safeguards (i.e., hardware and software features, physical controls, operating procedures...
- Access Control ModelFormal presentations of the security policies enforced by AC systems, and are useful for proving theoretical...
- Access Control Policy1. Policies that describe who is allowed to access the data and/or which parts of the data.
- Access control systemA set of procedures and/or processes, normally automated, which allows access to a controlled area or to...
- access cross domain solutionA type of transfer cross domain solution (CDS) that provides access to a computing platform, application, or...
- access levelA category within a given security classification limiting entry or system connectivity to only authorized...
- access list1. A list of users, programs, and/or processes and the specifications of access categories to which each is...
- Access ManagementAccess Management is the set of practices that enables only those permitted the ability to perform an action...
- Access Point (AP)A device that logically connects wireless client devices operating in infrastructure to one another and...
- access profileAssociation of a user with a list of protected objects the user may access.
- Access Strum, see AS
- access type1. The nature of an access right to a particular device, program, or file (e.g., read, write, execute...
- Access Vector1. reflects the access required to exploit the vulnerability.
- AccountAn entity in a blockchain that is identified with an address and can send transactions to the blockchain.
- account linkingThe association of multiple federated identifiers with a single RP subscriber account or the management of...
- account recoveryThe ability to regain ownership of a subscriber account and its associated information and privileges.
- account resolutionThe association of an RP subscriber account with information that is already held by the RP prior to the...
- accountability1. Property that ensures that the actions of an entity may be traced uniquely to the entity.
- accounting legend codeA numeric code used to indicate the minimum accounting controls required for items of accountable COMSEC...
- accounting numberA number assigned to an individual item of COMSEC material at its point of origin to facilitate its handling...
- accreditation1. Formal declaration by a designated accrediting authority (DAA) or principal accrediting authority (PAA)...
- accuracy1. Closeness of computations or estimates to the exact or true values that the statistics were intended to...
- accuracy (absolute)1. The degree of conformity of a measured or calculated value to the true value, typically based on a global...
- accuracy (relative)The degree of agreement between measured or calculated values among the devices and applications dependent on...
- ACD, see active cyber defense
- ACL1. A mechanism that implements access control for a system resource by enumerating the system entities that...
- ACMImplementations of formal AC policy such as AC model. Access control mechanisms can be designed to adhere to...
- ACMEA protocol defined in IETF RFC 8555 that provides for the automated enrollment of certificates.
- ACP1. High-level requirements that specify how access is managed and who may access information under what...
- acquirer1. Organization or entity that acquires or procures a product or service.
- acquisition1. The process associated with obtaining products or services, typically through contracts involving the...
- activationThe process of inputting an activation factor into a multi-factor authenticator to enable its use for...
- activation dataA pass-phrase, personal identification number (PIN), biometric data, or other mechanisms of equivalent...
- activation factorAn additional authentication factor that is used to enable successful authentication with a multi-factor...
- activation secretA password that is used locally as an activation factor for a multi-factor authenticator.
- Activation/IssuanceA process that includes the procurement of FIPS-approved blank PIV Cards or hardware/software tokens (for...
- active attackAn attack on a secure communication protocol where the attacker transmits data to the claimant, Credential...
- active cyber defenseSynchronized, real-time capability to discover, detect, analyze, and mitigate threats and vulnerabilities.
- Active DirectoryA Microsoft directory service for the management of identities in Windows domain networks.
- Active Security TestingSecurity testing that involves direct interaction with a target, such as sending packets to a target.
- Active state1. A lifecycle state for a key in which the key may be used to cryptographically protect information (e.g...
- Active TagA tag that relies on a battery for power.
- Activities1. An assessment object that includes specific protection-related pursuits or actions supporting a system...
- activitySet of cohesive tasks of a process.
- Actor1. The source of risk that can result in harmful impact.
- Actual Residual RiskThe risk remaining after management has taken action to alter its severity.
- Actual StateThe observable state or behavior of an assessment object (device, software, person, credential, account...
- Actuating CapabilityThe ability to change something in the physical world.
- actuatorA device for moving or controlling a mechanism or system. It is operated by a source of energy, typically...
- AD1. Input data to the CCM generation-encryption process that is authenticated but not encrypted.
- Ad Hoc HIEsAn Ad Hoc HIE occurs when two healthcare organizations exchange health information, usually under the...
- Ad Hoc Network1. A wireless network that dynamically connects wireless client devices to each other without the use of an...
- adaptability1. The property of an architecture, design, and implementation that can accommodate changes to the threat...
- Additional Authenticated DataThe input data to the authenticated encryption function that is authenticated but not encrypted.
- Additional input1. Information known by two parties that is cryptographically bound to the secret keying material being...
- Address1. The associated data string.
- Address Resolution Protocol (ARP)1. A protocol used to obtain a node’s physical address. A client station broadcasts an ARP request onto the...
- addressable1. To meet the addressable implementation specifications, a covered entity or business associate must (i)...
- adequate security1. Meets minimum tolerable levels of security as determined by analysis, experience, or a combination of both...
- adj-RIB-InRoutes learned from inbound update messages from BGP peers.
- adj-RIB-OutRoutes that the BGP router will advertise, based on its local policy, to its peers.
- Adjudicative EntityAn agency authorized by law, Executive Order, designation by the Security Executive Agent, or delegation by...
- Administrative domainA logical collection of hosts and network resources (e.g., department, building, company, organization)...
- administrative incident (COMSEC)A violation of procedures or practices dangerous to security that is not serious enough to jeopardize the...
- ADRS1. Address
- ADRS^CCompressed Address
- advanced cyber threatSee advanced persistent threat.
- Advanced Encryption Standard1. A U.S. Government-approved cryptographic algorithm that can be used to protect electronic data. The AES...
- advanced key processorA cryptographic device that performs all cryptographic functions for a management client node and contains...
- advanced persistent threat1. An adversary that possesses sophisticated levels of expertise and significant resources that allow it to...
- Advanced Persistent ThreatsAn adversary with sophisticated levels of expertise and significant resources, allowing it through the use of...
- Advanced Technology AttachmentMagnetic media interface specification. Also known as “IDE” - IntegratedDrive Electronics.
- adversarial exampleA modified testing sample that induces misclassification or misbehavior of a machine learning model at...
- Adversarial Machine LearningAttacks that exploit the statistical, data-based nature of machine learning systems.
- adversary1. Person, group, organization, or government that conducts or has the intent to conduct detrimental...
- adverse consequenceAn undesirable consequence associated with a loss.
- adverse cybersecurity eventAny event with a potentially negative impact on cybersecurity.
- adversity1. The conditions that can cause a loss of assets (e.g., threats, attacks, vulnerabilities, hazards...
- AEThe function of GCM in which the plaintext is encrypted into the ciphertext, and an authentication tag is...
- AES1. Advanced Encryption Standard (as specified in FIPS 197).
- AES(k, input)A single AES encryption operation as specified in [FIPS 197] with k and input being the AES encryption key...
- Affine TransformationA transformation consisting of multiplication by a matrix followed by the addition of a vector.
- After Action ReportA document containing findings and recommendations from an exercise or a test.
- agency1. Any executive department, military department, government corporation, government controlled corporation...
- Agency Dashboard1. An organizational-level dashboard that: a) collects data from a collection system; and b) shows detailed...
- Agent1. Software programs that can interact with their environment, receive information, and undertake...
- AggregateTo combine several more-specific prefixes into a less-specific prefix.
- Aggregated InformationInformation elements collated on a number of individuals, typically used for the purposes of making...
- Aggregation1. See “Event Aggregation”.
- agility1. The property of a system or an infrastructure that can be reconfigured, in which resources can be...
- agreement1. Mutual acknowledgement of terms and conditions under which a working relationship is conducted, or goods...
- AH, see Authentication Header (AH)
- A(i)1. The output of the i^(th) iteration in the first pipeline of a double pipeline iteration mode.
- AI1. (1) Any artificial system that performs tasks under varying and unpredictable circumstances without...
- AIDA globally unique identifier of a card application as defined in ISO/IEC 7816-4.
- air gapAn interface between two systems at which (a) they are not connected physically and (b) any logical...
- Air Traffic OrganizationAuthorization to Operate; One of three possible decisions concerning an issuer made by a Designated...
- AirdropA distribution of digital tokens to a list of blockchain addresses.
- AKP, see advanced key processor
- alarmA device or function that signals the existence of an abnormal condition by making an audible or visible...
- ALC, see accounting legend code
- AlenThe bit length of the associated data.
- AlgorithmA clearly specified mathematical process for computation; a set of rules that, if followed, will give a...
- algorithm identifierA 1-byte identifier that specifies a cryptographic algorithm and key size. For symmetric cryptographic...
- Algorithm originator-usage period1. The period of time during which a specific cryptographic algorithm may be used by originators to apply...
- Algorithm security lifetime1. The estimated time period during which data protected by a specific cryptographic algorithm remains secure.
- algorithmic optimizationThe application of mathematical formulae to calculate the aggregate cost-benefit to the enterprise, given the...
- Allan deviation[See source document for the complete definition.]
- allied nationA nation allied with the U.S. in a current defense effort and with which the U.S. has certain treaties. For...
- allocation1. The process an organization employs to determine whether security controls are defined as system-specific...
- allowedThe algorithm and key length in a FIPS or SP is safe to use; no security risk is currently known when used in...
- allowlistA documented list of specific elements that are allowed, per policy decision. In federation contexts, this is...
- all-source intelligence1. In intelligence collection, a phrase that indicates that in the satisfaction of intelligence requirements...
- AlphabetA finite set of two or more symbols.
- Alphabet sizeThe number of distinct symbols that the noise source produces.
- alternate COMSEC account managerThe primary alternate COMSEC Account Manager is an individual designated by proper authority to perform the...
- Alternating Current, see AC
- ambiguity ruleIt is assumed that out of publicly available information the contribution of one individual to the cell total...
- American Petroleum Institute, see API
- American Registry for Internet NumbersThe American Registry for Internet Numbers for Canada, the United States of America, and many Caribbean and...
- AMLAttacks that exploit the statistical, data-based nature of machine learning systems.
- Analysis1. The examination of acquired data for its significance and probative value to the case.
- Analysis ApproachThe approach used to define the orientation or starting point of the risk assessment, the level of detail in...
- Analytic SystemsIT systems that process the information outputs produced by middleware. Analytic systems may be comprised of...
- Anomalous Event Response and Recovery Management1. See Capability, Anomalous Event Response and Recovery Management.
- anomalyCondition that deviates from expectations based on requirements specifications, design documents, user...
- anonymity1. Condition in identification whereby an entity can be recognized as distinct, without sufficient identity...
- anonymization1. A process that removes the association between the identifying dataset and the data subject.
- anonymized datadata from which the patient cannot be identified by the recipient of the information
- Anonymized InformationPreviously identifiable information that has been de-identified and for which a code or other association for...
- anonymous identifieridentifier of a person which does not allow the unambiguous identification of the natural person
- anticipated re-identification rateWhen an organization contemplates performing re-identification, the re-identification rate that the resulting...
- Anti-ForensicA technique for concealing or destroying data so that others cannot access it.
- anti-jamThe result of measures to resist attempts to interfere with communications reception.
- anti-signal fingerprintResult of measures used to resist attempts to uniquely identify a particular transmitter based on its signal...
- anti-signal spoofResult of measures used to resist attempts to achieve imitative or manipulative communications deception...
- anti-spoofCountermeasures taken to prevent the unauthorized use of legitimate identification & authentication (I&A)...
- anti-tamperSystems engineering activities intended to prevent physical manipulation or delay exploitation of critical...
- Anti-tampering, see AT
- Antivirus Software1. A program specifically designed to detect many forms of malware and prevent them from infecting computers...
- antivirus toolsSoftware products and technology used to detect malicious code, prevent it from infecting a system, and...
- AO1. A senior (federal) official or executive with the authority to formally assume responsibility for...
- AODR1. An organizational official acting on behalf of an authorizing official in carrying out and coordinating...
- APA set of filter processes that are arranged in a linear order using one-way inter-process communications to...
- APDUA part of the application layer in the Open Systems Interconnection Reference model that is used for...
- Aperiodic Templates TestThe purpose of this test is to reject sequences that exhibit too many occurrences of a given non-periodic...
- APIA system access point or library function that has a well-defined syntax and is accessible from application...
- APNICThe Regional Internet Registry for the Asia Pacific region that allocates and registers Internet resources in...
- Applicability StatementA complex logical expression to describe an IT platform, formed out of individual CPE names and references to...
- applicant1. An individual applying for a PIV Card or derived PIV credential. The applicant may be a current or...
- applicant referenceA representative of the applicant who can vouch for the identity of the applicant, specific attributes...
- application1. A hardware/software system implemented to satisfy a particular set of requirements. In this context, an...
- application allowlistingA list of applications and application components (libraries, configuration files, etc.) that are authorized...
- Application FirewallA firewall that uses stateful protocol analysis to analyze network traffic for one or more applications.
- application identifierA globally unique identifier of a card application.
- application interconnectionA logical communications link between two or more applications operated by different organizations or within...
- Application Interface CapabilityThe ability for other computing devices to communicate with an IoT device through an IoT device application.
- Application LayerLayer of the TCP/IP protocol stack that sends and receives data for particular applications such as DNS...
- Application Level Gateway (ALG)Application Level Gateways (ALGs) are application specific translation agents that allow an application (like...
- Application Programming Interface (API)A system access point or library function that has a well-defined syntax and is accessible from application...
- Application Property Template, see APT
- Application Protocol Data UnitA part of the application layer in the Open Systems Interconnection Reference model that is used for...
- Application TranslationA function that converts information from one protocol to another.
- Application virtualization1. A virtual implementation of the application programming interface (API) that a running application expects...
- application-layer onboardingConsists of the steps required to provide an IoT device with the application-layer components (e.g...
- Application-Proxy GatewayA firewall capability that combines lower-layer access control with upper layer-functionality, and includes a...
- application-specific integrated circuits (ASICs)A digital or analog circuit, custom-designed and/or custom-manufactured to perform a specific function. An...
- apply cryptographic protectionDepending on the algorithm, to encrypt or sign data, generate a hash function or Message Authentication Code...
- approachSee cyber resiliency implementation approach.
- approval statusUsed to designate usage by the U.S. Federal Government.
- approval to operate1. The official management decision issued by a designated accrediting authority (DAA) or principal...
- approved1. An algorithm or technique for a specific cryptographic use that is specified in a FIPS or NIST...
- approved cryptography1. An encryption algorithm, hash function, random bit generator, or similar technique that is Federal...
- Approved entropy sourceAn entropy source that has been validated as conforming to [NIST SP 800-90B].
- Approved hash algorithms1. Hash algorithms specified in FIPS 180-4.
- Approved security functionA security function (e.g., cryptographic algorithm, cryptographic key management technique, or authentication...
- Approximate Entropy TestThe purpose of the test is to compare the frequency of overlapping blocks of two consecutive/adjacent lengths...
- APT1. An adversary with sophisticated levels of expertise and significant resources, allowing it through the use...
- architecture1. A highly structured specification of an acceptable approach within a framework for solving a specific...
- Architecture ConstructsDesign structures that can serve as the basic building blocks for a Notional Architecture.
- architecture descriptionA work product used to express an architecture.
- Architecture Design PrinciplesBest practices derived from large-scale information-sharing implementations that serve as the overall...
- architecture frameworkConventions, principles, and practices for the description of architectures established within a specific...
- architecture viewA work product expressing the architecture of a system from the perspective of specific system concerns.
- architecture viewpointA work product establishing the conventions for the construction, interpretation, and use of architecture...
- Archive1. Noun: See Archive facility.
- Archive facility1. Noun: See Archive facility.
- area under the curveA measure of the ability of a classifier to distinguish between classes in machine learning. A higher AUC...
- ARF, see asset reporting format
- ARINThe American Registry for Internet Numbers for Canada, the United States of America, and many Caribbean and...
- ARP, see Address Resolution Protocol (ARP)
- Array1. A fixed-size data structure that stores a collection of elements, where each element is identified by its...
- artifact1. A piece of evidence
- artificial intelligence1. (1) Any artificial system that performs tasks under varying and unpredictable circumstances without...
- artificial intelligence modelA component of an information system that implements AI technology and uses computational, statistical, or...
- artificial intelligence red-teamingA structured testing effort to find flaws and vulnerabilities in an AI system, often in a controlled...
- artificial intelligence systemAny data system, software, hardware, application, tool, or utility that operates in whole or in part using AI.
- ASAn Autonomous System specifies a network, mostly an organization that can own or announce network addresses...
- Asia-Pacific Network Information CentreThe Regional Internet Registry for the Asia Pacific region that allocates and registers Internet resources in...
- ASN, see Autonomous System Number (ASN)
- aspect1. The parts, features, and characteristics used to describe, consider, interpret, or assess something.
- assemblyAn item forming a portion of an equipment, that can be provisioned and replaced as an entity and which...
- assertion1. A verifiable statement from an IdP to an RP that contains information about an end user. Assertions may...
- assertion injection attackIn the context of a federated protocol, consists of an attacker attempting to force an RP to accept or...
- assertion presentationThe method by which an assertion is transmitted to the RP.
- assessment1. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment...
- assessment activitiesAn assessment object that includes specific protection related pursuits or actions supporting an information...
- Assessment BoundaryThe scope of (assessment objects included in) an organization’s ISCM implementation to which assessment of...
- Assessment CompletenessThe degree to which the continuous monitoring-generated, security-related information is collected on all...
- Assessment Criterion/CriteriaA rule (or rules) of logic to allow the automated or manual detection of defects. Typically, the assessment...
- assessment elementA specific ISCM concept to be evaluated in the context of a specific ISCM Process Step.
- assessment element attributeAn item of information that is specifically applicable to an assessment element, such as the source for the...
- assessment element textA statement that should be true for a well-implemented ISCM program. This statement is the evaluation...
- assessment method1. One of three types of actions (i.e., examine, interview, test) taken by assessors in obtaining evidence...
- assessment object1. The item (i.e., specifications, mechanisms, activities, individuals) upon which an assessment method is...
- assessment objective1. A set of determination statements that expresses the desired outcome for the assessment of a security...
- assessment plan1. The objectives for the control assessments and a detailed roadmap of how to conduct such assessments.
- assessment procedure1. A set of assessment objectives and an associated set of assessment methods and assessment objects.
- assessment resultsThe output or outcome of an assessment.
- Assessment TimelinessThe degree to which the continuous monitoring-generated, security-related information is collected within the...
- assessor1. The individual, group, or organization responsible for conducting a security or privacy control assessment.
- asset1. A distinguishable entity that provides a service or capability. Assets are people, physical entities, or...
- asset identification1. SCAP constructs to uniquely identify assets (components) based on known identifiers and/or known...
- Asset Identification ElementA complete, bound expression of an asset identification using the constructs defined in this specification.
- Asset ReportA collection of content (or link to content) about an asset.
- Asset Report RequestA collection of structured information used as input to generate an asset report. An asset report request may...
- asset reporting format1. SCAP data model for expressing the transport format of information about assets (components) and the...
- Asset Reporting Format ReportThe collection of all assets, report requests, reports, and relationships for a given instance of ARF.
- Asset TagSimple key value attributes that are associated with a platform (e.g., location, company name, division, or...
- assignment operation1. See organization-defined parameters and selection operation.
- assignment statementA control parameter that allows an organization to assign a specific, organization-defined value to the...
- Associated Data1. Data that is authenticated but not encrypted.
- Association1. A relationship for a particular purpose. For example, a key is associated with the application or process...
- Assumption1. This term is used to indicate the conditions that are required to be true when an approved...
- assurance1. Grounds for justified confidence that a [security or privacy] claim has been or will be achieved.
- assurance case1. A structured set of arguments and a body of evidence showing that a system satisfies specific claims with...
- assurance evidence1. The information upon which decisions regarding assurance, trustworthiness, and risk of the solution are...
- Assurance messageSee private-key-possession assurance message.
- Assurance of domain parameter validity1. Confidence that the domain parameters are arithmetically correct.
- assurance of integrity1. Quality of being complete and unaltered.
- Assurance of possession1. Confidence that an entity possesses a private key and any associated keying material.
- Assurance of public key validity1. Confidence that the public key is arithmetically correct.
- Assurance of validity1. Confidence that either a key or a set of domain parameters is arithmetically correct.
- Assurance- signatureA digital signature on a private-key-possession assurance message.
- assurance_levelThe level of assurance (e.g., HIGH, MEDIUM, or LOW) that a claimed signatory possesses the private signature...
- assurance_timeThe time at which assurance of possession is obtained.
- assured information sharingThe ability to confidently share information with those who need it, when and where they need it, as...
- assured pipelineA set of filter processes that are arranged in a linear order using one-way inter-process communications to...
- AS&W, see attack sensing and warning
- asymmetric cryptography1. Cryptography that uses two separate keys to exchange data - one to encrypt or digitally sign the data and...
- Asymmetric-key cryptography1. A cryptographic system where users have a private key that is kept secret and used to generate a public...
- Asymptotic AnalysisA statistical technique that derives limiting approximations for functions of interest.
- Asymptotic DistributionThe limiting distribution of a test statistic arising when n approaches infinity.
- Asynchronous Connection-Less, see ACL
- ATSystems engineering activities intended to prevent physical manipulation or delay exploitation of critical...
- ATAMagnetic media interface specification. Also known as “IDE” - IntegratedDrive Electronics.
- ATO1. The official management decision issued by a designated accrediting authority (DAA) or principal...
- atomic clockA clock referenced to an atomic oscillator. Only clocks with an internal atomic oscillator qualify as atomic...
- atomic operationAn atomic operation is effectively executed as a single step, no other process can read or modify the...
- atomic oscillatorAn oscillator that uses the quantized energy levels in atoms or molecules as the source of its resonance. The...
- Atomic SwapAn exchange of tokens that does not involve the intervention of any trusted intermediary and automatically...
- attack1. Any kind of malicious activity that attempts to collect, disrupt, deny, degrade, or destroy information...
- attack sensing and warningDetection, correlation, identification, and characterization of intentional unauthorized activity with...
- attack signatureA specific sequence of events indicative of an unauthorized access attempt.
- attack surface1. The set of points on the boundary of a system, a system element, or an environment where an attacker can...
- attack treeA branching, hierarchical data structure that represents a set of potential approaches to achieving an event...
- attacker1. A person who seeks to exploit potential vulnerabilities of a system.
- attendedUnder continuous positive control of personnel authorized for access or use.
- attestation1. The issue of a statement, based on a decision, that fulfillment of specified requirements has been...
- Attestation Service, see AS
- attribute1. Characteristic or property of an entity that can be used to describe its state, appearance, or other...
- Attribute AuthorityAn entity, recognized by the Federal PKI Policy Authority or comparable Agency body as having the authority...
- attribute disclosureRe-identification event in which an entity learns confidential information about a data principal, without...
- attribute inference attacksAn attack against machine learning models that infers sensitive attributes of a training data record, given...
- attribute providerThe provider of an identity API that provides access to a subscriber’s attributes without necessarily...
- Attribute Reference1. A statement asserting a property of an entity without necessarily containing identity information...
- attribute serviceA service that provides a common access point to accurate and current attributes obtained from one or more...
- attribute validation1. Confirmation (through the provision of strong, sound, and objective evidence and demonstration) that...
- Attribute Value1. A complete statement that asserts an identity attribute of a subscriber, independent of format. For...
- attribute-based access control (ABAC)1. An access control method where subject requests to perform operations on objects are granted or denied...
- Attribute-Value PairA tuple a=v in which a (the attribute) is an alphanumeric label representing a property or state, and v (the...
- AUCA measure of the ability of a classifier to distinguish between classes in machine learning. A higher AUC...
- Audience1. The application or system that is meant to receive an assertion.
- audience restrictionThe restriction of a message to a specific target audience to prevent a receiver from unknowingly processing...
- audit1. Systematic, independent and documented process for obtaining audit evidence and evaluating it objectively...
- Audit administrator1. An FCKMS role that is responsible for establishing and reviewing an audit log, assuring that the log is...
- audit (data)Examination of data for quality and accuracy.
- audit log1. A chronological record of information system activities, including records of system accesses and...
- audit recordAn individual entry in an audit log related to an audited event.
- audit record reductionA process that manipulates collected audit information and organizes it into a summary format that is more...
- audit reduction toolsPreprocessors designed to reduce the volume of audit records to facilitate manual review. Before a security...
- audit (supplier process)Review of an organization's capacity to meet, or continue to meet, initial and ongoing requirements as a...
- audit trail1. A chronological record that reconstructs and examines the sequence of activities surrounding or leading to...
- Auditor1. An FCKMS role that is responsible for establishing and reviewing an audit log, assuring that the log is...
- authenticable entityAn entity that can successfully participate in an authentication protocol with a card application.
- authenticate1. The process of establishing confidence of authenticity; in this case, the validity of a person’s identity...
- Authenticated Code Module, see ACM
- Authenticated Configuration ScannerA product that runs with administrative or root privileges on a target system to conduct its assessment.
- Authenticated DecryptionThe function of GCM in which the ciphertext is decrypted into the plaintext, and the authenticity of the...
- Authenticated EncryptionThe function of GCM in which the plaintext is encrypted into the ciphertext, and an authentication tag is...
- authenticated- encryption functionA function that encrypts plaintext into ciphertext and provides a means for the associated...
- authenticated protected channel1. An encrypted communication channel that uses approved cryptography in which the connection initiator...
- Authenticated RFIDThe use of digital signature technology to provide evidence of the authenticity of a tag and possibly chain...
- authenticated sessionA session in which messages between two participants are encrypted and integrity is protected using a set of...
- authenticated-decryption functionA function that decrypts purported ciphertext into corresponding plaintext and verifies the authenticity and...
- authentication1. Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to...
- authentication assurance levelA category that describes the strength of the authentication process.
- Authentication Center, see AUC
- Authentication code1. A keyed cryptographic checksum based on an approved security function (also known as a Message...
- authentication eventAn attempt by a user to authenticate to an online service that ends in overall success or failure.
- Authentication Factor1. The three types of authentication factors are something you know, something you have, and something you...
- Authentication Header (AH)A deprecated IPsec security protocol that provides integrity protection (but not confidentiality) for packet...
- Authentication InformationInformation used to establish the validity of a claimed identity.
- Authentication Key1. A private or symmetric key used by an authenticator to generate the authenticator output.
- authentication periodThe period between any initial authentication process and subsequent re-authentication processes during a...
- authentication protocol1. A defined sequence of messages between a claimant and a verifier that demonstrates that the claimant has...
- Authentication Server, see AS
- Authentication Tag1. A cryptographic checksum on data that is designed to reveal both accidental errors and the intentional...
- authenticator1. Something the cardholder possesses and controls (e.g., PIV Card or derived PIV credential) that is used to...
- Authenticator Assurance Level (AAL)1. A measure of the strength of an authentication mechanism and, therefore, the confidence in it, as defined...
- authenticator bindingThe establishment of an association between a specific authenticator and a subscriber account that allows the...
- authenticity1. The property of being genuine and being able to be verified and trusted; confidence in the validity of a...
- AuthorThe organization responsible for creating the checklist in its current format. In most cases an organization...
- authoritative attribute sourceThe official source that originates and maintains the attributes of entities.
- authority1. Person(s) or established bodies with rights and responsibilities to exert control in an administrative...
- Authority to OperateAuthorization to Operate; One of three possible decisions concerning an issuer made by a Designated...
- Authority Type1. The type of organization that is the authority for the checklist. The three types are Governmental...
- authorization1. Access privileges granted to a user, program, or process or the act of granting those privileges. Formerly...
- authorization boundary1. All components of an information system to be authorized for operation by an authorizing official. This...
- authorization package1. The essential information that an authorizing official uses to determine whether to authorize the...
- Authorization Server, see AS
- authorization to operate1. Official management decision given by a senior Federal official or officials to authorize operation of an...
- authorization to useThe official management decision given by an authorizing official to authorize the use of an information...
- authorize processing1. The official management decision of the Designated Authorizing Official to permit operation of an issuer...
- Authorized1. Entitled to a specific mode of access.
- Authorized EntityAn entity that has implicitly or explicitly been granted approval to interact with a particular IoT device...
- authorized IDThe key management entity (KME) authorized to order against a traditional short title.
- Authorized individuals, services, and other IoT product componentsAn entity (i.e., a person, device, service, network, domain, developer, or other party who might interact...
- Authorized KeyA public key that has been configured as authorizing access to an account by anyone capable of using the...
- Authorized Keys FileThe file associated with a specific account where one or more authorized keys and optional restrictions are...
- authorized partyIn federation, the organization, person, or entity that is responsible for making decisions regarding the...
- authorized user1. Any appropriately cleared individual with a requirement to access an information system (IS) for...
- authorizing official1. Official with the authority to formally assume responsibility for operating an information system at an...
- authorizing official designated representative1. An organizational official acting on behalf of an authorizing official in carrying out and coordinating...
- Automated AccessAccess to a computer by an automated process without an interactive user, generally machine-to-machine...
- Automated CertificateA protocol defined in IETF RFC 8555 that provides for the automated enrollment of certificates.
- Automated Certificate Management EnvironmentA protocol defined in IETF RFC 8555 that provides for the automated enrollment of certificates.
- Automated ChecklistA checklist that is used through one or more tools that automatically alter or verify settings based on the...
- Automated ProcessAn application, script, or management system that leverages SSH to execute commands or transfer data to/from...
- automated security monitoring1. Use of automated procedures to ensure security controls are not circumvented or the use of these tools to...
- automatic remote rekeyingProcedure to rekey distant cryptographic equipment electronically without specific actions by the receiving...
- Autonomous System (AS)1. An Autonomous System specifies a network, mostly an organization that can own or announce network...
- Autonomous System Number (ASN)A two-byte number that identifies an AS.
- availability1. measures an attacker’s ability to disrupt or prevent access to services or data. Vulnerabilities that...
- availability breakdownIn the AML context, a disruption of the ability of other users or processes to obtain timely and reliable...
- Availability Impactmeasures the potential impact to availability of a successfully exploited misuse vulnerability. Availability...
- availability (PNT)The availability of a PNT system is the percentage of time that the services of the system are usable...
- average queryA query that determines the mean of some set of values.
- AVPA tuple a=v in which a (the attribute) is an alphanumeric label representing a property or state, and v (the...
- Awareness1. The ability of the user to recognize and avoid behaviors that could compromise cybersecurity and to act...
- Awareness and Training, see AT
- awareness contentContent that is designed and implemented to help employees understand how their actions may impact or...
- awareness trainingThe foundational cybersecurity or privacy training program for all personnel. It is designed to help learners...
366 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.