Cybersecurity terminology · MLC-0102
Cybersecurity terms: C (672)
- C1. Ciphertext
- C, CU, CVCiphertext (expressed as a byte string).
- C1,…,C64Bits of the Ciphertext Block
- C21. Command and Control' is the exercise of authority and direction by a properly designated commander over...
- CA1. The entity in a public-key infrastructure (PKI) that is responsible for issuing certificates and exacting...
- CA Technologies, see CA
- CAAA record associated with a Domain Name Server (DNS) entry that specifies the CAs that are authorized to issue...
- CAC, see common access card (CAC)
- CAISAny system incorporating critical software and in which failure can cause substantial harm to the public.
- CALDA process that is responsible for receiving audit and log events from system components, syntactically and...
- calibrationA comparison between a device under test and an established standard, such as UTC(NIST). When the calibration...
- Call Processorcomponent that sets up and monitors the state of calls, and provides phone number translation, user...
- callibrationA comparison between a device under test and an established standard, such as Coordinated Universal Time UTC...
- Canadian Standards Association, see CSA
- Candidate Checklist1. Checklist that has been screened and approved by NIST for public review.
- Capabilities Catalog1. Comprehensive list of device cybersecurity capabilities derived from analysis of comprehensive list of...
- capability1. A person’s potential to accomplish something.
- Capability, Anomalous Event Detection ManagementAn ISCM capability that identifies routine and unexpected events that can compromise security within a time...
- Capability, Anomalous Event Response and Recovery Management1. See Capability, Anomalous Event Response and Recovery Management.
- Capability, Behavior Management1. See Capability, Behavior Management.
- Capability, Boundary Management1. An ISCM capability that addresses the following network and physical boundary areas: Physical Boundaries -...
- Capability, Configuration Settings Management1. An ISCM capability that identifies configuration settings (Common Configuration Enumerations [CCEs]) on...
- Capability, Credentials and Authentication Management1. An ISCM capability that ensures that people have the credentials and authentication methods necessary (and...
- Capability, Event Preparation Management1. An ISCM capability that ensures that procedures and resources are in place to respond to both routine and...
- Capability, Hardware Asset Management1. An ISCM capability that identifies unmanaged devices that are likely to be used by attackers as a platform...
- Capability, ISCM1. See ISCM Capability.
- Capability ListA list attached to a subject ID specifying what accesses are allowed to the subject.
- Capability, Manage and Assess Risk1. The program and supporting processes to manage information security risk to organizational operations...
- Capability, Perform Resilient Systems EngineeringAn ISCM capability that • Focuses on reducing successful exploits of the other non-meta capabilities that...
- Capability, Privilege and Account Management1. An ISCM capability that ensures that people have the privileges necessary (and only those necessary) to...
- capability requirementA type of requirement describing the capability that the organization or system must provide to satisfy a...
- Capability, Security1. See capability.
- Capability, Software Asset Management1. An ISCM capability that identifies unauthorized software on devices that is likely to be used by attackers...
- Capability, Trust Management1. The willingness to take actions expecting beneficial outcomes, based on assertions by other parties.
- Capability, Vulnerability Management1. An ISCM capability that identifies vulnerabilities [Common Vulnerabilities and Exposures (CVEs)] on...
- capacityThe width of the underlying permutation minus the rate.
- Capacity PlanningSystematic determination of resource requirements for the projected output, over a specific period.
- CAPIAn application programming interface included with Microsoft Windows operating systems that provides services...
- Capstone PoliciesThose policies that are developed by governing or coordinating institutions of HIEs. They provide overall...
- Capture1. Series of actions undertaken to obtain and record, in a retrievable form, signals of biometric...
- cardAn integrated circuit card.
- card applicationA set of data objects and card commands that can be selected using an application identifier.
- Card Design Standard, see CDS
- card interface deviceAn electronic device that connects an integrated circuit card and the card applications therein to a client...
- card management operationAny operation involving the PIV Card Application Administrator.
- card management system1. The system that manages the lifecycle of a PIV Card application.
- card readerAn electronic device that connects an integrated circuit card and the card applications therein to a client...
- Card Verifiable Certificate1. A certificate stored on the PIV Card that includes a public key, the signature of a certification...
- cardholder1. An individual who possesses an issued PIV Card.
- cascadingAn approach for deploying CDS where two identical CDSs are placed in series to transfer information across...
- catalogThe collection of all assessment elements.
- categorization1. The process of determining the security category for information or an information system. Security...
- Category1. Restrictive label applied to classified or unclassified information to limit access.
- CAW, see Certification Authority Workstation
- CBEFF Basic StructureThe basic CBEFF structure consists of a single Standard Biometric Header followed by a Biometric Data Block...
- CBEFF ClientAn entity that defines a biometric data block (BDB) structure (e.g., a BDB format owner) that is CBEFF com...
- CBEFF Nested StructureA CBEFF Nested Structure consists of a Root Header followed by Sub-Headers, one or more CBEFF Basic...
- CBEFF PatronAn organization that has defined a standard or specification incorporating biometric data objects that is...
- CBEFF Root HeaderThe CBEFF Standard Biometric Header that precedes all others in a CBEFF nested structure
- CBEFF Sub-HeaderAny CBEFF Standard Biometric Header in a CBEFF nested structure that follows the Root Header and pre cedes...
- CC1. Governing document that provides a comprehensive, rigorous method for specifying security function and...
- CCBA group of qualified people with responsibility for the process of regulating and approving changes to...
- CCE, see common configuration enumeration (CCE)
- CCE IDAn identifier for a specific configuration defined within the official CCE Dictionary and that conforms to...
- CCEP, see commercial COMSEC evaluation program (CCEP)
- CCI, see control correlation identifier (CCI); controlled cryptographic item (CCI)
- CCSS, see common configuration scoring system (CCSS)
- CD1. A Compact Disc(CD)is a class of media from which data are readby optical means.
- CDHThe cofactor ECC Diffie-Hellman key-agreement primitive.
- CDMSee Continuous Diagnostics and Mitigation.
- CDMAA spread spectrum technology for cellular networks based on the Interim Standard-95 (IS-95) from the...
- CDMA Subscriber Identity Module (CSIM)CSIM is an application to support CDMA2000 phones that runs on a UICC, with a file structure derived from the...
- CD-RACompact Disc Recordable(CD-R) is aCD thatcan be written on only once but read manytimes. Also known as WORM.
- CD-RecordableACompact Disc Recordable(CD-R) is aCD thatcan be written on only once but read manytimes. Also known as WORM.
- CD-RewritableACompact Disc Read/Write(CD-RW) isaCD that can be Purged and rewritten multiple times.
- CD-RWACompact Disc Read/Write(CD-RW) isaCD that can be Purged and rewritten multiple times.
- CDSA form of controlled interface that provides the ability to manually and/or automatically access and transfer...
- CE1. A purge sanitization technique in which key sanitization is applied to one or more keys providing...
- Cellular Network Isolation Card (CNIC)A SIM card that isolates the device from cell tower connectivity.
- Centimeter, see CM
- central audit and logging daemonA process that is responsible for receiving audit and log events from system components, syntactically and...
- central journal daemonA process that is responsible for receiving and securely wrapping the content filtered by the CDS and...
- Central Limit TheoremFor a random sample of size n from a population with meanm and variance s2, the distribution of the sample...
- central management1. The organization-wide management and implementation of selected security controls and related processes...
- central office of recordThe entity that keeps records of accountable COMSEC material held by COMSEC accounts subject to its oversight.
- Central Oversight Authority1. The Key Management Infrastructure (KMI) entity that provides overall KMI data synchronization and system...
- central services nodeThe Key Management Infrastructure core node that provides central security management and data management...
- Central Verification SystemA system operated by the Office of Personnel Management that contains information on security clearances...
- Centralized networkA network configuration where participants must communicate with a central authority to communicate with one...
- certificate1. A set of data that uniquely identifies a public key (which has a corresponding private key) and an owner...
- Certificate Authority AuthorizationA record associated with a Domain Name Server (DNS) entry that specifies the CAs that are authorized to issue...
- Certificate Authority (CA)1. A trusted entity that issues and revokes public key certificates.
- Certificate ChainAn ordered list of certificates that starts with an end-entity certificate, includes one or more certificate...
- Certificate classA CA-designation (e.g., "class 0" or "class 1") indicating how thoroughly the CA checked the validity of the...
- certificate management1. Process whereby certificates (as defined above) are generated, stored, protected, transferred, loaded...
- Certificate owner1. The human(s) responsible for the management of a given certificate.
- certificate policy1. A named set of rules that indicates the applicability of a certificate to a particular community and/or...
- certificate revocation list (CRL)1. A list of revoked public key certificates created and digitally signed by a certification authority.
- Certificate Signing RequestA request sent from a certificate requester to a certificate authority to apply for a digital identity...
- Certificate Status AuthorityA trusted entity that provides on-line verification to a relying party of a subject certificate's...
- certificate status serverAn authority that provides status information about certificates on behalf of the CA through online...
- Certificate TransparencyA framework for publicly logging the existence of Transport Layer Security (TLS) certificates as they are...
- Certificate-inventory management1. See Key-inventory management.
- certificate-related information1. Information, such as subscriber's postal address, that is not included in a certificate. May be used by a...
- certification1. Third-party attestation related to an object of conformity assessment, with the exception of accreditation.
- certification authority1. A trusted entity that issues and revokes public key certificates.
- Certification Authority WorkstationCommercial-off-the-shelf (COTS) workstation with a trusted operating system and special purpose application...
- certification test and evaluationSoftware, hardware, and firmware security tests conducted during development of an information system...
- certified TEMPEST technical authorityAn experienced, technically qualified U.S. Government employee who has met established certification...
- C.F.D., see common fill device (CFD)
- CFOA senior member responsible for managing the financial actions of an agency or organization.
- chain1. Two or more assessment elements that are linked by a common aspect of ISCM. Each chain has an assessment...
- chain of trust1. An interoperable data format for PIV enrollment records that facilitates the import and export of records...
- Chain-based proof of stake consensus modelA proof of stake consensus model where the blockchain network decides the next block through pseudo-random...
- chainingAn approach for deploying CDS where two different CDS on different operating systems are placed in series to...
- ChallengeFor this paper, a currently difficult or impossible task that is either unique to cloud computing or...
- Challenge-Response Protocol1. An authentication protocol in which the verifier sends the claimant a challenge (e.g., a random value or...
- Change Control Board, see CCB
- Change of Authorization, see COA
- ChannelAn information transfer path within a system. May also refer to the mechanism by which the path is effected.
- characteristicDistinguishing feature.
- characterizationAn extended test of the performance characteristics of a clock or oscillator. A characterization involves...
- Check Fact ReferenceAn expression that refers to a check (e.g., OVAL check, OCIL check).
- check wordCipher text generated by cryptographic logic to detect failures in cryptography.
- Checklist1. A document that contains instructions or procedures for configuring an IT product to an operational...
- Checklist DeveloperAn individual or organization that develops and owns a checklist and submits it to the National Checklist...
- Checklist GroupRepresents the grouping of checklists based on a common source material. Commonly used if an organization...
- Checklist Revision1. Represents a change to the checklist content that does not affect the underlying rule/value configuration...
- Checklist RoleThe primary use or function of the IT product as described by the checklist (e.g., client desktop host, web...
- Checklist TypeThe type of checklist, such as Compliance, Vulnerability, and Specialized.
- checksum1. A value computed on data to detect error or manipulation.
- Chief Artificial Intelligence OfficerA senior executive responsible for coordinating their agency’s use of artificial intelligence (AI), promoting...
- Chief Data OfficerA senior executive responsible for the utilization and governance of data across the agency or organization.
- Chief Financial OfficerA senior member responsible for managing the financial actions of an agency or organization.
- chief information officer1. Agency official responsible for: (i) providing advice and other assistance to the head of the executive...
- Chief Information Officers (CIO) CouncilThe CIO Council is the principal interagency forum for improving agency practices related to the design...
- chief information security officer1. See Senior Agency Information Security Officer.
- Chief Learning OfficerA senior-level executive who oversees all learning and employee development programs within an agency or...
- Chief Privacy Officer1. A senior official designated by the head of each agency to have agency-wide responsibilities for privacy...
- ChoreographyDefines the requirements and sequences through which multiple Web services interact.
- CI1. An aggregation of information system components that is designated for configuration management and...
- CIAC = Confidentiality assurance, I = Integrity assurance, A = Availability assurance
- CIK, see Cryptographic Ignition Key
- CIMA, see COMSEC Incident Monitoring Activity
- CIO1. Executive agency official responsible for: (1) providing advice and other assistance to the head of the...
- CIPH-1K(X)1. The inverse cipher function of the block cipher algorithm under the key K applied to the data block X.
- cipher1. Series of transformations that converts plaintext to ciphertext using the Cipher Key.
- cipher suiteA common set of cryptographic algorithms used for key establishment, signature generation, hash function...
- cipher textData in its encrypted form.
- cipher text auto-keyCryptographic logic that uses previous cipher text to generate a key stream.
- Cipher-based Message Authentication CodeCipher-based Message Authentication Code (as specified in NIST SP 800-38B).
- ciphertext1. Data in its encrypted form.
- Ciphertext Integrity, see CI
- Ciphertext Stealing, see CS
- CIPHK(X)1. The forward cipher function of the block cipher algorithm under the key K applied to the data block X.
- CIRC, see Cyber Incident Response Team
- CircuitA dedicated single connection between two endpoints on a network.
- CIRT, see Cyber Incident Response Team
- CISO1. See Senior Agency Information Security Officer.
- C#jThe jth ciphertext segment.
- CjThe jth ciphertext block.
- CJDA process that is responsible for receiving and securely wrapping the content filtered by the CDS and...
- CKG, see cooperative key generation (CKG)
- CKL, see compromised key list (CKL)
- CKMSA Cryptographic Key Management System that conforms to the requirements of [NIST SP 800-130].
- CKMS componentAny hardware, software, or firmware that is used to implement a CKMS. In this Recommendation, the major CKMS...
- CKMS designThe capabilities that were selected and specified by a CKMS designer to be implemented and supported in a...
- CKMS designerThe entity that selects the capabilities to be included in a CKMS, documents the design in accordance with...
- CKMS developerThe entity that assembles a CKMS as designed by the CKMS designer.
- CKMS hierarchyA system of key processing facilities whereby a key center or certification authority may delegate the...
- CKMS implementerThe entity that installs the CKMS for the FCKMS service provider.
- CKMS moduleA device that performs a set of key and metadata-management functions for at least one CKMS.
- CKMS productAn implementation of a CKMS design produced by a vendor that conforms to the requirements of [NIST SP...
- CKMS Security PolicyA security policy specific to a CKMS
- CKMS vendorThe entity that markets the CKMS to CKMS service providers.
- CLAClass (first) byte of a card command
- claimA true-false statement about the limitations on the values of an unambiguously defined property called the...
- claimant1. A subject whose identity is to be verified using one or more authentication protocols.
- Claimed signatoryFrom the verifier’s perspective, the claimed signatory is the entity that purportedly generated a digital...
- classical data analysisA data analysis technique where data collection is followed by the imposition of a model, and the analysis...
- classificationThe task of predicting which of a set of discrete categories an input belongs to.
- classified information1. Information that Executive Order 13526, "Classified National Security Information," December 29, 2009 (3...
- classified national security information1. Information that has been determined pursuant to Executive Order 13526 or any predecessor order to require...
- clean hostA host with an operating system installation that has never been accessed by end users, such as a host...
- clean word listList of words that are acceptable, but would normally be rejected because they contain a word on the dirty...
- clear1. A method of sanitization that applies logical techniques to sanitize data in all user-addressable storage...
- clearanceA formal security determination by an authorized adjudicative office that an individual is authorized access...
- cleartext1. Information that is not encrypted.
- ClenThe bit length of the ciphertext.
- client1. a machine or software application that accesses a cloud over a network connection, perhaps on behalf of a...
- client application1. A program running on a computer in communication with a card interface device.
- client node1. Enables customers to access primary services nodes (PRSNs) to obtain key management infrastructure (KMI)...
- clippingThe general name for any algorithm that enforces a bound on the impact of one user’s data on an aggregate...
- clipping parameterThe specific choice of lower and upper bounds that are used when an algorithm performs clipping. The utility...
- CLOA senior-level executive who oversees all learning and employee development programs within an agency or...
- clockA device that generates periodic, accurately spaced signals for timekeeping applications. A clock consists of...
- Cloned TagA tag that is made to be a duplicate of a legitimate tag. A cloned tag can be created by reading data such as...
- closed security environmentEnvironment providing sufficient assurance that applications and equipment are protected against the...
- Closed Source Operating SystemSource code for an operating system is not publically available.
- closed storageThe storage of classified information in properly secured General Services Administration-approved security...
- Closed SystemA system that is self-contained within an enterprise. Closed systems do not have an inter-enterprise...
- Cloud AuditorA party that can conduct an independent assessment of cloud services, information system operations...
- Cloud BrokerAn entity that manages the use, performance, and delivery of cloud services and negotiates relationships...
- Cloud CarrierAn intermediary that provides connectivity and transport of cloud services from Cloud Providers to Cloud...
- cloud computing1. A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable...
- Cloud ConsumerA person or organization that maintains a business relationship with and uses service from Cloud Providers
- cloud consumer or customera person or organization that is a customer of a cloud; note that a cloud customer may itself be a cloud and...
- cloud infrastructurethe collection of hardware and software that enables the five essential characteristics of cloud computing...
- Cloud ProviderThe entity (a person or an organization) responsible for making a service available to interested parties
- cloud provider or provideran organization that provides cloud services.
- Cloud Security Alliance, see CSA
- Cloud Service Provider, see CSP
- Cloud workloadA logical bundle of software and data that is present in, and processed by, a cloud computing technology.
- ClusterA group of contiguous sectors.
- CM1. A collection of activities focused on establishing and maintaining the integrity of information technology...
- CMaaSSee Continuous Monitoring as a Service
- CMACCipher-based Message Authentication Code (as specified in NIST SP 800-38B).
- CMCS, see COMSEC material control system
- CMDAUTH, see Command Authority
- CMIA DoD initiative to modernize the NSA-certified cryptographic product inventory.
- C*nThe last block of the ciphertext, which may be a partial block.
- Cn1. Block of data representing the Ciphertext n
- CNA, see computer network attack (CNA)
- CND, see computer network defense (CND)
- CNE, see computer network exploitation (CNE)
- CNG, see Cryptographic API: Next Generation
- CNIC, see Cellular Network Isolation Card (CNIC)
- CNNA class of feed-forward neural networks that include at least one convolutional layer, referred to as CNNs...
- CNO, see computer network operations (CNO)
- CO, see cyberspace operations (CO)
- COA1. The cryptographic key management system (CKMS) entity that provides overall CKMS data synchronization and...
- coalition partnerA nation in an ad hoc defense arrangement with the United States.
- code1. System of communication in which arbitrary groups of letters, numbers, or symbols represent units of plain...
- code analysisThe act of reverse-engineering a program to understand the code that implements the software behavior. For...
- Code Division Multiple Access (CDMA)A spread spectrum technology for cellular networks based on the Interim Standard-95 (IS-95) from the...
- codebookDocument containing plain text and code equivalents in a systematic arrangement, or a technique of machine...
- Codeccoder/decoder, which converts analog voice into digital data and back again, and may also compress and...
- coded1. Identifying information (such as name or social security number) that would enable the investigator to...
- Coder-Decodercoder/decoder, which converts analog voice into digital data and back again, and may also compress and...
- coercivityA measure of the ability of a ferromagnetic material to withstand an external magnetic field without becoming...
- Cofactor Diffie-HellmanThe cofactor ECC Diffie-Hellman key-agreement primitive.
- COG, see continuity of government (COG)
- cognizant security officer/authority1. An entity charged with responsibility for physical, technical, personnel, and information security...
- COI, see community of interest (COI)
- Collaborative Research Cycle, see CRC
- Collateral Damage Potentialmeasures the potential for loss of life or physical assets through damage or theft of property or equipment.
- collateral informationNational security information (including intelligence information) classified Top Secret, Secret, or...
- Collecting and Communicating Audit TrailsTo define and identify security-relevant events and the data to be collected and communicated as determined...
- CollectionThe first phase of the computer and network forensics process, which involves identifying, labeling...
- Collection SystemA system that collects actual state data and compares the collected actual state data to the desired state...
- CollectorTypically, an automated sensor that gathers actual state data. Part of the collection system.
- collision1. For a given function, a pair of distinct input values that yield the same output value.
- Collision resistance1. An expected property of a cryptographic hash function whereby it is computationally infeasible to find a...
- Command and Control1. Command and Control' is the exercise of authority and direction by a properly designated commander over...
- Command AuthorityThe command authority is responsible for the appointment of user representatives for a department, agency, or...
- commercial COMSEC evaluation program (CCEP)Relationship between National Security Agency (NSA) and industry, in which NSA provides the COMSEC expertise...
- commercial national security algorithm compatibleA CS or CS-enabled information technology (IT) product that: a. Uses National Security Agency (NSA)-approved...
- commercial national security algorithm suiteA specific set of cryptographic algorithms and key strengths that may be used to protect classified and...
- commercial solutions for classified (CSfC)A COTS end-to-end strategy and process in which two or more COTS products can be combined into a solution to...
- commercial-off-the-shelf (COTS)1. A software and/or hardware product that is commercially ready-made and available for sale, lease, or...
- Commit-ChainA scheme that enables the off-chain processing of transactions by one or more operators with on-chain state...
- Committee DraftA Compact Disc(CD)is a class of media from which data are readby optical means.
- commodity service1. An information system service (e.g., telecommunications service) provided by a commercial service provider...
- common access card (CAC)Standard identification/smart card issued by the Department of Defense (DoD) that has an embedded integrated...
- common carrier1. In a telecommunications context, a telecommunications company that holds itself out to the public for hire...
- common configuration enumeration (CCE)1. A nomenclature and dictionary of software security configurations.
- common configuration scoring system (CCSS)A SCAP specification for measuring the severity of software security configuration issues.
- common control1. A security control that is inherited by one or more organizational information systems.
- common control provider1. An organizational official responsible for the development, implementation, assessment, and monitoring of...
- common criteria1. Governing document that provides a comprehensive, rigorous method for specifying security function and...
- common fill device (CFD)A COMSEC item used to transfer or store key in electronic form or to insert key into cryptographic equipment.
- Common NameAn attribute type that is commonly found within a Subject Distinguished Name in an X.500 directory...
- common platform enumeration (CPE)1. A nomenclature and dictionary of hardware, operating systems, and applications.
- common secure configuration1. Recognized, standardized, and established benchmarks that stipulate secure configuration settings for...
- common services provider (CSP)A federal organization that provides National Security System-Public Key Infrastructure (NSS-PKI) support to...
- common user application software (CUAS)User application software developed to run on top of the local COMSEC management software (LCMS) on the local...
- common vulnerabilities and exposures (CVE)1. A list of entries-each containing an identification number, a description, and at least one public...
- Common Vulnerabilities and Exposures identifiersAn identifier for a specific software flaw defined within the official CVE Dictionary and that conforms to...
- Common Vulnerability Enumeration, see CVE
- common vulnerability scoring system (CVSS)1. A system for measuring the relative severity of software flaw vulnerabilities.
- common weakness enumeration (CWE)1. A taxonomy for identifying the common sources of software flaws (e.g., buffer overflows, failure to check...
- common weakness enumeration specificationA community-developed formal list or dictionary of common software weaknesses that can occur in software's...
- Communicate-P (Function)Develop and implement appropriate activities to enable organizations and individuals to have a reliable...
- Communicating groupA set of communicating entities that employ cryptographic services and need cryptographic keying...
- CommunicationsThe actions and associated activities that are used to exchange information, provide instructions, give...
- communications cover1. Result of measures used to obfuscate message externals to resist traffic analysis.
- Communications ModuleThe sub-component of a Smart Meter responsible for AMI communications between Smart Meters in the field and...
- communications profileAnalytic model of communications associated with an organization or activity. The model is prepared from a...
- Communications RouterA communications device that transfers messages between two networks. Common uses for routers include...
- communications security1. A component of Information Assurance that deals with measures and controls taken to deny unauthorized...
- Community cloudThe cloud infrastructure is provisioned for exclusive use by a specific community of consumers from...
- community of interest (COI)A collaborative group of users (working at the appropriate security level or levels) who exchange information...
- community riskProbability that a particular vulnerability will be exploited within an interacting population and adversely...
- Compact DiscA class of media from which data are read by optical means.
- Compact Disc-RecordableACompact Disc Recordable(CD-R) is aCD thatcan be written on only once but read manytimes. Also known as WORM.
- Comparison1. Estimation, calculation, or measurement of similarity or dissimilarity between biometric probe(s) and...
- compartmentalizationA nonhierarchical grouping of information used to control access to data more finely than with hierarchical...
- Compatible security domainsTwo Security Domains are compatible if they can exchange a key and its metadata without violating (or...
- compensating controls1. Alternative controls to the normative controls for the assessed and selected xALs of an organization based...
- Competency1. A mechanism for organizations to assess learners.
- competency areaA cluster of related Knowledge and Skill statements that correlates with one’s capability to perform Tasks in...
- competent security officialAny cognizant security authority or person designated by the cognizant security authority.
- Complementary Error Function1. See Erfc.
- complex systemA system in which there are non-trivial relationships between cause and effect: each effect may be due to...
- complex threatTwo or more separate attacks aimed at the same general or specific target(s) or objective(s).
- Compliance auditA comprehensive review of an organization's adherence to governing documents such as whether a Certification...
- Compliance MappingThe process of correlating CCE settings defined in a source data stream with the security control identifiers...
- component1. An element of a large system - such as an identity card, issuer, card reader, or identity verification...
- Component schemaThe schema for an SCAP component specification (e.g. XCCDF, CPE, CVSS). Within this document, this term is...
- Component specificationOne of the individual specifications that comprises SCAP.
- Component TestA test of individual hardware and software components or groups of related components.
- Comprehensive TestA test of all systems and components that support a particular IT plan, such as a contingency plan or...
- comprehensive testing1. A test methodology that assumes explicit and substantial knowledge of the internal structure and...
- Compressed File1. A file reduced in size through the application of a compression algorithm, commonly performed to save disk...
- compromise1. A judgment, based on the preponderance of the evidence, that a disclosure of information to unauthorized...
- Compromise recoveryThe procedures and processes of restoring a system, device or process that has been compromised back to a...
- compromised key list (CKL)1. The set of Key Material Identification Numbers (KMIDs) of all keys in a universal that have been reported...
- Compromised state1. A lifecycle state for a key that is known or suspected of being known by an unauthorized entity.
- compromising emanationsUnintentional signals that, if intercepted and analyzed, would disclose the information transmitted...
- computationally bounded adversaryAn adversarial algorithm that is constrained in running time and memory, and is thus unlikely to break a...
- Computed Tomography, see CT
- ComputerA device that accepts digital data and manipulates the information based on a program or sequence of...
- computer abuseIntentional or reckless misuse, alteration, disruption, or destruction of information processing resources.
- computer forensics1. In its strictest connotation, the application of computer science and investigative procedures involving...
- Computer Information Security Officer, see CISO
- computer network attack (CNA)1. An attack, via cyberspace, targeting an enterprise’s use of cyberspace for the purpose of disrupting...
- computer network defense (CND)1. Actions taken within protected cyberspace to defeat specific threats that have breached or are threatening...
- computer network exploitation (CNE)1. Actions taken in cyberspace to gain intelligence, maneuver, collect information, or perform other enabling...
- computer network operations (CNO)1. The employment of cyberspace capabilities where the primary purpose is to achieve objectives in or through...
- Computer Security Incident1. An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity...
- Computer Security Log ManagementLog management for computer security log data only.
- computer security object1. A resource, tool, or mechanism used to maintain a condition of security in a computerized environment...
- computerized telephone system (CTS)1. A generic term used to describe any telephone system that uses centralized stored program computer...
- Computing Device1. A functional unit that can perform substantial computations, including numerous arithmetic operations and...
- computing environmentWorkstation or server (host) and its operating system, peripherals, and applications.
- COMSEC, see communications security
- COMSEC accountAn administrative entity identified by an account number, used to maintain accountability, custody and...
- COMSEC account auditInventory and reconciliation of the holdings, records, and procedures of a COMSEC account ensuring all...
- COMSEC account managerAn individual designated by proper authority to be responsible for the receipt, transfer, accountability...
- COMSEC aidsAll COMSEC material other than equipment or devices, which assist in securing telecommunications and is...
- COMSEC assemblyGroup of parts, elements, subassemblies, or circuits that are removable items of COMSEC equipment. Rationale...
- COMSEC boundaryDefinable perimeter encompassing all hardware, firmware, and software components performing critical COMSEC...
- COMSEC chip setCollection of NSA approved microchips. Rationale: The term falls under the broader term “COMSEC material”.
- COMSEC control programComputer instructions or routines controlling or affecting the externally performed functions of key...
- COMSEC custodian1. An individual designated by proper authority to be responsible for the receipt, transfer, accountability...
- COMSEC demilitarization1. The act of eliminating the functional capabilities and/or inherent military design features [from DoD...
- COMSEC elementRemovable item of COMSEC equipment, assembly, or subassembly; normally consisting of a single piece or group...
- COMSEC emergencyA tactical operational situation, as perceived by the responsible person/officer in charge, in which the...
- COMSEC end-itemEquipment or combination of components ready for use in a COMSEC application.
- COMSEC equipmentEquipment designed to provide security to telecommunications by converting information to a form...
- COMSEC facilityThe space used for generating, storing, repairing, or using COMSEC material. The COMSEC material may be in...
- COMSEC incidentAny occurrence that potentially jeopardizes the security of COMSEC material or the secure transmission of...
- COMSEC Incident Monitoring ActivityThe office within a department or agency maintaining a record of COMSEC incidents caused by elements of that...
- COMSEC insecurityA COMSEC incident that has been investigated, evaluated, and determined to jeopardize the security of COMSEC...
- COMSEC manager1. An individual designated by proper authority to be responsible for the receipt, transfer, accountability...
- COMSEC materialItem(s) designed to secure or authenticate telecommunications. COMSEC material includes, but is not limited...
- COMSEC material control systemThe logistics and accounting system through which COMSEC material marked CRYPTO is distributed, controlled...
- COMSEC moduleRemovable component that performs COMSEC functions in a telecommunications equipment or system. Rationale...
- COMSEC monitoringThe act of listening to, copying, or recording transmissions of one's own official telecommunications to...
- COMSEC service authoritySee service authority.
- COMSEC softwareIncludes all types of COMSEC material, except key, in electronic or physical form. This includes all...
- COMSEC trainingTeaching of skills relating to COMSEC accounting and the use of COMSEC aids.
- CONAUTH, see controlling authority (CONAUTH)
- Concatenation1. The concatenation of bit strings A and B.
- conceptA "unit of knowledge created by a unique combination of characteristics."
- concept crosswalk1. A concept relationship style that identifies that a relationship exists between two concepts without any...
- concept mapping1. An indication that one concept is related to another concept.
- concept of operations1. Verbal and graphic statement, in broad outline, of an organization’s assumptions or intent in regard to an...
- concept of secure function1. A strategy for the achievement of secure system function that embodies the preemptive and reactive...
- concept relationship style1. An explicitly defined convention for characterizing relationships for a use case.
- concept sourceA document or other resource that contains definitions of concepts.
- concept systemA “set of concepts structured in one or more related domains according to the concept relations among its...
- concept typeA category of concepts found within a particular domain.
- concernMatter of interest or importance to a stakeholder.
- concern (system)Interest in a system relevant to one or more of its stakeholders.
- Condition coverageThe percentage of conditions within decision expressions that have been evaluated to both true and false...
- conditioning functionA deterministic function used to reduce bias and/or improve the entropy per bit.
- Conditioning (of noise source output)A method of processing the raw data to reduce bias and/or ensure that the entropy rate of the conditioned...
- Confidence intervalAn interval estimate [low, high] of a population parameter. If the population is repeatedly sampled, and...
- confidential algorithmCryptographic algorithm that is not publicly available (e.g. proprietary or classified).
- Confidential ComputingHardware-enabled features that isolate and process encrypted data in memory so that the data is at less risk...
- confidentiality1. Preserving authorized restrictions on information access and disclosure, including means for protecting...
- Confidentiality Impactmeasures the potential impact on confidentiality of a successfully exploited misuse vulnerability...
- confidentiality, integrity, availabilityC = Confidentiality assurance, I = Integrity assurance, A = Availability assurance
- Confidentiality ModeA mode that is used to encipher plaintext and decipher ciphertext. The confidentiality modes in this...
- ConfigurableA characteristic of a system, device, or software that allows it to be changed by an entity authorized to...
- configuration1. A collection of an item's descriptive and governing characteristics, which can be expressed in functional...
- configuration baseline1. A documented set of specifications for an information system, or a configuration item within a system...
- configuration changeConfiguration change is a part of the Configuration Management (CM) process. Broadly, configuration change...
- configuration control1. Process of controlling modifications to hardware, firmware, software, and documentation to protect the...
- configuration control board (CCB)1. Establishment of and charter for a group of qualified people with responsibility for the process of...
- configuration item1. An aggregation of system components that is designated for configuration management and treated as a...
- configuration management1. A management process for establishing and maintaining consistency of a product's performance, functional...
- configuration management planA comprehensive description of the roles, responsibilities, policies, and procedures that apply when managing...
- Configuration Payload, see CP
- configuration settings1. The set of parameters that can be changed in hardware, software, or firmware that affect the security...
- Configuration Settings Management1. An ISCM capability that identifies configuration settings (Common Configuration Enumerations [CCEs]) on...
- ConfirmedState of a transaction or block when consensus has been reached about its status of inclusion into the...
- ConflictOne or more participants disagree on the state of the system.
- Conflict resolutionA predefined method for coming to a consensus on the state of the system. For example, when portions of the...
- Confluent Hypergeometric FunctionThe confluent hypergeometric function is defined as Φ(a;b;z)=(Γ(b))/(Γ(a)Γ(b-a)) ∫_0^1〖e^zt t^(a-1)...
- Conformance Testing1. A process established by NIST within its responsibilities of developing, promulgating, and supporting a...
- Conformity Assessment1. Demonstration that specified requirements are fulfilled.
- CONOP, see concept of operations
- Consensus model1. A process to achieve agreement within a distributed system on the valid state. Also known as a consensus...
- consent banner1. See security banner (also known as notice and consent banners)
- consequenceEffect (change or non-change), usually associated with an event or condition or with the system and usually...
- Console1. A visually oriented input and output device used to interact with a computational resource.
- ConsortiumA group of organizations or individuals with the objective of mutualizing resources for achieving a common...
- constraints1. Limitation on the system, its design, its implementation, or the process used to develop or modify a...
- consumer IoT productIoT products that are intended for personal, family, or household use.
- consumer-grade router deviceNetworking devices that are primarily intended for residential use and can be installed by the customer...
- consumer-grade router productConsumer-grade router device and any additional product components (e.g., backend, smartphone application)...
- Consuming Application1. The application (including middleware) that uses random numbers or bits obtained from an approved random...
- Contagion Research Center, see CRC
- ContainerA method for packaging and securely running an application within an application virtualization environment...
- Container runtimeThe environment for each container; comprised of binaries coordinating multiple operating system components...
- Container-specific operating systemA minimalistic host operating system explicitly designed to only run containers.
- contamination1. See spillage.
- Content consumerA product that accepts existing SCAP source data stream content, processes it, and produces SCAP result data...
- Content GeneratorA program on a Web server that will dynamically generate HyperText Markup Language (HTML) pages for users...
- Content producerA product that generates SCAP source data stream content.
- content signing certificateA certificate issued for the purpose of digitally signing information (content) to confirm the author and...
- Content TypeThe form of the checklist content in terms of the degree of automation and standardization. Examples include...
- contested cyber environmentAn environment in which APT actors, competing entities, and entities with similar resource needs contend for...
- Context1. The circumstances surrounding the system's processing of PII.
- context handlerExecutes the workflow logic that defines the order in which policy and attributes are retrieved and enforced.
- Context of Use1. The purpose for which PII is collected, stored, used, processed, disclosed, or disseminated.
- contingency keyKey held for use under specific operational conditions or in support of specific contingency plans.
- contingency plan1. Management policy and procedures used to guide an enterprise response to a perceived loss of mission...
- Contingency Planning1. See Information System Contingency Plan.
- continuityThe probability that the specified PNT system performance will be maintained for the duration of a phase of...
- continuity of government (COG)A coordinated effort within the Federal Government's executive branch to ensure that national essential...
- continuity of operations plan (COOP)1. A predetermined set of instructions or procedures that describe how an organization’s mission-essential...
- Continuous Diagnostics and Mitigation (CDM)1. See Continuous Diagnostics and Mitigation.
- continuous monitoring1. Use of automated procedures to ensure security controls are not circumvented or the use of these tools to...
- Continuous Monitoring as a ServiceSee Continuous Monitoring as a Service
- continuous monitoring programA program established to collect information in accordance with preestablished metrics, utilizing information...
- Continuous testA type of health test performed within an entropy source on the output of its noise source in order to gain...
- ContractA mutually binding legal relationship obligating the seller to furnish the supplies or services (including...
- Contract administration officeAn office that performs - (1) Assigned post-award functions related to the administration of contracts; and...
- Contracting Officer Representative, see COR
- control1. The part of the OT system used to monitor and control the physical process. This includes all control...
- Control AlgorithmA mathematical representation of the control action to be performed.
- control assessment1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent...
- control assessment report1. Documentation of the results of security and privacy control assessments, including information based on...
- control assessor1. The individual, group, or organization responsible for conducting a control assessment. See assessor.
- control baseline1. Hardware, software, databases, and relevant documentation for an information system at a given point in...
- Control CellA central location for exercise coordination, typically in a separate area from the exercise participants.
- Control CenterAn equipment structure or group of structures from which a process is measured, controlled, and/or monitored.
- control correlation identifier (CCI)Decomposition of a National Institute of Standards and Technology (NIST) control into a single, actionable...
- control designationThe process of assigning a control to one of three control types: common, hybrid, or system-specific.
- control effectiveness1. A measure of whether a given control is contributing to the reduction of information security or privacy...
- control enhancement1. Augmentation of a control to build in additional, but related, functionality to the control; increase the...
- control inheritance1. A situation in which a system or application receives protection from controls (or portions of controls)...
- Control Item1. See Security Control Item.
- Control LoopA control loop consists of sensors for measurement, controller hardware (e.g., PLCs), actuators (e.g...
- Control NetworkThose networks of an enterprise typically connected to equipment that controls physical processes and that is...
- control parameter1. See organization-defined parameter.
- Control Server1. A term that is used to imply that the output of a controller or computer program is used as input to other...
- Control SystemA system in which deliberate guidance or manipulation is used to achieve a prescribed value for a variable...
- controlled access areaThe complete building or facility area under direct physical control within which unauthorized persons are...
- controlled area1. Any area or space for which the organization has confidence that the physical and procedural protections...
- controlled cryptographic item (CCI)Secure telecommunications or information system, or associated cryptographic component, that is unclassified...
- controlled cryptographic item (CCI) assembly1. A device approved by the National Security Agency (NSA) as a controlled cryptographic item, that embodies...
- controlled cryptographic item (CCI) componentA device approved by the National Security Agency as a controlled cryptographic item that embodies a...
- controlled cryptographic item (CCI) equipmentA telecommunications or information handling equipment that embodies a CCI component and performs the entire...
- controlled environmentAny area or space an authorized holder deems to have adequate physical or procedural controls (e.g., barriers...
- controlled interface1. A boundary with a set of mechanisms that enforces the security policies and controls the flow of...
- controlled spaceThree-dimensional space surrounding information system equipment, within which unauthorized individuals are...
- controlled unclassified information (CUI)1. Information the Government creates or possesses, or that an entity creates or possesses for or on behalf...
- Controlled VariableThe variable that the control system attempts to keep at the set point value. The set point may be constant...
- Controller1. A device or program that operates automatically to regulate a controlled variable.
- controlling authority (CONAUTH)The official responsible for directing the operation of a cryptonet and for managing the operational use and...
- controlling domainThe domain that assumes the greater risk and thus enforces the most restrictive policy.
- Control-P (Function)Develop and implement appropriate activities to enable organizations or individuals to manage data with...
- controlsPolicies, procedures, guidelines, practices, or organizational structures that manage security, privacy, and...
- Conventional BIOSLegacy boot firmware used in many x86-compatible computer systems. Also known as the legacy BIOS.
- ConversationWhere Web services maintain some state during an interaction that involves multiple messages or participants.
- convolutional neural networksA class of feed-forward neural networks that include at least one convolutional layer, referred to as CNNs...
- cookie1. A piece of state information supplied by a web server to a browser that is temporarily stored and returned...
- COOP, see continuity of operations plan (COOP)
- cooperative key generation (CKG)Electronically exchanging functions of locally generated, random components, from which both terminals of a...
- cooperative remote rekeying1. Synonymous with manual remote rekeying.
- CoordinationRefers to the building, from a set of Web services, of something at a higher level, typically itself exposed...
- COPE, see Corporate-Owned Personally-Enabled (COPE)
- Copy (data)To replicate data in another location while maintaining it in its original location.
- CORThe entity that keeps records of accountable COMSEC material held by COMSEC accounts subject to its oversight.
- CoreA set of privacy protection activities and outcomes. The Framework Core comprises three elements: Functions...
- core attributesThe set of identity attributes that the CSP has determined and documented to be required for identity...
- Core Baseline1. A set of device cybersecurity capabilities and non-technical supporting capabilities needed to support...
- Core Root of Trust for Measurement (CRTM)The first piece of BIOS code that executes on the main processor during the boot process. On a system with a...
- Core SoftwareAn organizationally defined set of software that, at a minimum, includes firmware and root operating system...
- Core Specification Addendum, see CSA
- Corporate-Owned Personally-Enabled (COPE)A device owned by an enterprise and issued to an employee. Both the enterprise and the employee can install...
- correct re-identificationsPutative re-identifications that correctly infer an individual's identity and associated data.
- correctness proofFormal technique used to prove mathematically that a computer program satisfies its specified requirements.
- Correlation1. See “Event Correlation”.
- CoT1. A method for maintaining valid trust boundaries by applying a principle of transitive trust, where each...
- COTS1. A product that is commercially available.
672 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.