Cybersecurity terminology · MLC-0102
Cybersecurity terms: C (672)
- counterfeitAn unauthorized copy or substitute that has been identified, marked, and/or altered by a source other than...
- counterintelligence1. Information gathered and activities conducted to identify, deceive, exploit, disrupt, or protect against...
- countermeasures1. Any action, device, procedure, technique, or other measure that reduces the vulnerability of or threat to...
- counting queryA query that counts the number of rows in a dataset with a particular property.
- courierA duly authorized and trustworthy individual who has been officially designated to transport/carry material...
- Course of ActionA time-phased or situation-dependent combination of risk response measures.
- cover (TRANSEC)1. Result of measures used to obfuscate message externals to resist traffic analysis.
- coverage1. The surface area or space volume in which the signals are adequate to permit the user to determine a...
- Cover-CodingA technique to reduce the risks of eavesdropping by obscuring the information that is transmitted. The...
- covered entity1. Under HIPAA, a health plan, a health care clearinghouse, or a health care provider that conducts certain...
- covert channelAn unintended or unauthorized intra-system channel that enables two cooperating entities to transfer...
- covert channel analysis1. Determination of the extent to which the security policy model and subsequent lower- level program...
- covert storage channel1. Covert channel involving the direct or indirect writing to a storage location by one process and the...
- Covert TestingTesting performed using covert methods and without the knowledge of the organization’s IT staff, but with...
- covert timing channelA system feature that enables one system entity to signal information to another by modulating its own use of...
- CP1. A named set of rules that indicates the applicability of a certificate to a particular community and/or...
- CPE, see common platform enumeration (CPE)
- CPE Attribute ComparisonThe first phase of CPE name matching, where a matching engine compares each of the A-V pairs of a source CPE...
- CPE DictionaryA repository of identifier CPE names (WFNs in bound form) and associated metadata.
- CPE NameAn identifier for a unique uniform resource identifier (URI) assigned to a specific platform type that...
- CPE Name ComparisonThe second phase of CPE name matching, where the individual attribute comparison results from the first phase...
- CPE Name MatchingA one-to-one source-to-target comparison of CPE names. CPE name matching has two phases
- CPO1. A senior official designated by the head of each agency to have agency-wide responsibilities for privacy...
- CPS1. A statement of the practices which a Certification Authority employs in issuing certificates.
- CR, see capability requirement
- Cradle1. A docking station, which creates an interface between a user’s PC and PDA and enables communication and...
- CRCA method to ensure data has not been altered after being sent through a communication channel.
- credential1. Evidence attesting to one’s right to credit or authority. In this Standard, it is the PIV Card or derived...
- Credential ManagementTo manage the life cycle of entity credentials used for authentication.
- credential service provider (CSP)1. A trusted entity whose functions include identity proofing applicants to the identity service and...
- credible sourceAn entity that can provide or validate the accuracy of identity evidence and attribute information. A...
- criticalThe designation assigned to a capability, system, or asset that without which will significantly degrade or...
- critical AI systemAny system incorporating critical software and in which failure can cause substantial harm to the public.
- critical assetAn asset of such extraordinary importance that its incapacitation or destruction would have a very serious...
- critical component1. A component which is or contains information and communications technology (ICT), including hardware...
- critical infrastructure1. The essential services that support a society and serve as the backbone for the society's economy...
- critical infrastructure sectorsThe 16 sectors designated by PPD-21 as vital to the United States, namely: chemical; commercial facilities...
- critical program (or technology)1. A program which significantly increases capability, mission effectiveness, or extends the expected...
- Critical ServicesThe subset of mission essential services required to conduct manufacturing operations. Function or capability...
- critical softwareAny software that has, or has direct software dependencies upon, one or more components with at least one of...
- Critical ValueThe value that is exceeded by the test statistic with a small probability (significance level). A "look-up"...
- criticality1. Degree of impact that a requirement, module, error, fault, failure, or other item has on the development...
- criticality analysisAn end-to-end functional decomposition performed by systems engineers to identify mission critical functions...
- criticality level1. Degree of impact that a requirement, module, error, fault, failure, or other item has on the development...
- Criticality ReviewsA determination of the ranking and priority of manufacturing system components, services, processes, and...
- CRL1. A list of revoked public key certificates created and digitally signed by a certification authority.
- cross certificateA certificate issued from a certification authority (CA) that signs the public key of another CA not within...
- cross domainThe act of manually and/or automatically accessing and/or transferring information between different security...
- cross domain capabilitiesThe set of functions that enable the transfer of information between security domains in accordance with the...
- cross domain dataflowThe combination of a transport protocol, data format(s), direction(s) of the data transfer, source and...
- cross domain dataflow filtering processA policy that describes the transport protocol, allowed content types, and the content filtering actions...
- cross domain dataflow identifierA unique alphanumeric sequence (usually a universally unique identifier (UUID)) that indicates a specific...
- cross domain enabledApplications/services that exist on and are capable of interacting across two or more different security...
- cross domain filterA process or set of processes that applies cross domain dataflow filtering policy to content. Filters...
- cross domain routerThe CDS filter process responsible for the transfer of data between assured pipelines/filter orchestration...
- cross domain serviceAn IT service that provides that provides access or transfer of information solutions between different...
- cross domain solution baseline listA list managed by the National Cross Domain Strategy and Management Office (NCDSMO) that identifies CDSs that...
- cross domain solution (CDS)A form of controlled interface that provides the ability to manually and/or automatically access and transfer...
- cross domain solution (CDS) filtering1. The process of inspecting data as it traverses a cross domain solution and determining if the data meets...
- cross domain solution processA software program written or integrated by a CDS developer to perform a specific set of functions on a CDS...
- cross domain solution sunset listA list managed by the National Cross Domain Strategy and Management Office (NCDSMO) that identifies cross...
- cross domain transferThe act of manually or automatically accessing or transferring information between different security domains.
- Cross-certificationA process whereby two CAs establish a trust relationship between them by each CA signing a certificate...
- Cross-certifyThe establishment of a trust relationship between two Certification Authorities (CAs) through the signing of...
- Cross-Domain Solutions, see CDS
- crosslinksCommunication between satellites.
- CRTM, see Core Root of Trust for Measurement (CRTM)
- cryptanalytically relevant quantum computerA device capable of using quantum algorithms to break a cryptosystem that is secure against classical (i.e...
- CRYPTOThe marking or designator identifying unencrypted COMSEC keying material used to secure or authenticate...
- crypto agilityThe capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software...
- crypto agility for a communication protocolThe ability to maintain interoperability when introducing new cryptographic algorithms and preventing the use...
- crypto agility for a computing systemThe ability to adopt new cryptographic algorithms and stop the use of vulnerable algorithms in applications...
- crypto agility for an enterpriseA capacity to seamlessly and rapidly transition away from vulnerable cryptographic algorithms and adopt new...
- Crypto as ITSet of high assurance, government cryptographic services, hardware, and software that is accounted for...
- Cryptocurrency1. A digital asset/credit/unit within the system, which is cryptographically sent from one blockchain network...
- cryptographicPertaining to, or concerned with, cryptography.
- Cryptographic AcceleratorA specialized separate coprocessor chip from the main processing unit where cryptographic tasks are offloaded...
- cryptographic alarmCircuit or device that detects failures or aberrations in the logic or operation of cryptographic equipment...
- Cryptographic algorithm1. 1. A well-defined computational procedure that takes variable inputs, including a cryptographic key, and...
- cryptographic ancillary equipment (crypto-ancillary equipment)Equipment designed specifically to facilitate efficient or reliable operation of cryptographic equipment, but...
- Cryptographic API: Next GenerationThe long-term replacement for the Cryptographic Application Programming Interface (CAPI).
- Cryptographic applicationAn application that performs a cryptographic function.
- Cryptographic Application Programming InterfaceAn application programming interface included with Microsoft Windows operating systems that provides services...
- cryptographic bindingAssociating two or more related elements of information using cryptographic techniques.
- cryptographic boundary1. Explicitly defined continuous perimeter that establishes the physical and/or logical bounds of a...
- Cryptographic checksumA mathematical value created using a cryptographic algorithm that is assigned to data and later used to test...
- cryptographic componentThe hardware or firmware embodiment of the cryptographic logic in a secure telecommunications or automated...
- Cryptographic deviceA physical device that performs a cryptographic function (e.g., random number generation, message...
- cryptographic equipment (cryptoequipment)Equipment that embodies a cryptographic logic.
- cryptographic erase1. A purge sanitization technique in which key sanitization is applied to one or more keys providing...
- Cryptographic functionCryptographic algorithms, together with modes of operation (if appropriate); for example, block ciphers...
- Cryptographic hash function1. A function that maps a bit string of arbitrary length to a fixed-length bit string. Depending upon the...
- Cryptographic Hash ValueThe result of applying a cryptographic hash function to data (e.g., a message).
- cryptographic high value product (CHVP)NSA-approved products incorporating only UNCLASSIFIED components and UNCLASSIFIED cryptographic algorithms...
- Cryptographic Ignition KeyA device or electronic key used to unlock the secure mode of cryptographic equipment.
- cryptographic incidentAny uninvestigated or unevaluated equipment malfunction or operator or COMSEC Account Manager error that has...
- cryptographic initializationFunction used to set the state of a cryptographic logic prior to key generation, encryption, or other...
- cryptographic key1. A parameter used in conjunction with a cryptographic algorithm that determines the specific operation of...
- Cryptographic key component1. One of at least two parameters that have the same security properties (e.g., randomness) as a...
- Cryptographic keying relationship1. Two or more entities share the same symmetric key.
- cryptographic logic1. A comprehensive and precisely defined sequence of steps or procedural rules used to produce cipher text...
- cryptographic material (cryptomaterial)All material, including documents, devices, or equipment that contains cryptographic information and is...
- Cryptographic mechanismAn element of a cryptographic application, process, module or device that provides a cryptographic service...
- cryptographic modernizationA DoD initiative to modernize the NSA-certified cryptographic product inventory.
- cryptographic modernization 2A phase of the broader DoD cryptographic modernization initiative started in 2016 to define and implement the...
- cryptographic modernization initiativeA DoD initiative to modernize the NSA-certified cryptographic product inventory.
- cryptographic module1. The set of hardware, software, and/or firmware that implements approved cryptographic functions (including...
- Cryptographic Module Security PolicyA specification of the security rules under which a cryptographic module is designed to operate.
- cryptographic net (cryptonet)Stations that hold a common key. This may include multiple communications networks.
- Cryptographic officerAn FCKMS role that is responsible for and authorized to initialize and manage all cryptographic services...
- Cryptographic operationThe execution of a cryptographic algorithm. Cryptographic operations are performed in cryptographic modules.
- cryptographic period (cryptoperiod)Time span during which each key setting remains in effect.
- Cryptographic primitiveA low-level cryptographic algorithm used as a basic building block for higher-level cryptographic algorithms.
- cryptographic product1. A cryptographic key (public, private, or shared) or public key certificate, used for encryption...
- cryptographic randomizationFunction that randomly determines the transmit state of a cryptographic logic.
- cryptographic security (cryptosecurity)The security or protection resulting from the proper use of technically sound cryptosystems.
- Cryptographic serviceA service that provides confidentiality, integrity, source authentication, entity authentication...
- cryptographic solutionThe generic term for a cryptographic device, COMSEC equipment, or combination of such devices/equipment...
- cryptographic synchronizationProcess by which a receiving decrypting cryptographic logic attains the same internal state as the...
- cryptographic system analysisProcess of establishing the exploitability of a cryptographic system, normally by reviewing transmitted...
- cryptographic system (cryptosystem)Associated CS items interacting to provide a single means of encryption or decryption.
- cryptographic system evaluationProcess of determining vulnerabilities of a cryptographic system and recommending countermeasures.
- cryptographic system reviewExamination of a cryptographic system by the controlling authority ensuring its adequacy of design and...
- cryptographic system surveyManagement technique in which actual holders of a cryptographic system express opinions on the system's...
- cryptography1. Art or science concerning the principles, means, and methods for rendering plain information...
- cryptology1. Originally the field encompassing both cryptography and cryptanalysis. Today, cryptology in the U.S...
- CryptoModA DoD initiative to modernize the NSA-certified cryptographic product inventory.
- cryptonet evaluation reportA free form message from the electronic key management system (EKMS) Tier 1 that includes the Controlling...
- Cryptoperiod1. The time span during which a specific key is authorized for use or in which the keys for a given system or...
- CS1. Prevention of damage to, protection of, and restoration of computers, electronic communications systems...
- CSAA trusted entity that provides on-line verification to a relying party of a subject certificate's...
- C-SCRM, see Cybersecurity Supply Chain Risk Management
- C-SCRM controlSafeguard or countermeasures prescribed for the purpose of reducing or eliminating the likelihood and/or...
- CSF CategoryA group of related cybersecurity outcomes that collectively comprise a CSF Function.
- CSF Community ProfileA baseline of CSF outcomes that is created and published to address shared interests and goals among a number...
- CSF CoreA taxonomy of high-level cybersecurity outcomes that can help any organization manage its cybersecurity...
- CSF Current ProfileA part of an Organizational Profile that specifies the Core outcomes that an organization is currently...
- CSF FunctionThe highest level of organization for cybersecurity outcomes. There are six CSF Functions: Govern, Identify...
- CSF Implementation ExampleA concise, action-oriented, notional illustration of a way to help achieve a CSF Core outcome.
- CSF Informative ReferenceA mapping that indicates a relationship between a CSF Core outcome and an existing standard, guideline...
- CSF Organizational ProfileA mechanism for describing an organization’s current and/or target cybersecurity posture in terms of the CSF...
- CSF Quick Start GuideA supplementary resource that gives brief, actionable guidance on specific CSF-related topics.
- CSF SubcategoryA group of more specific outcomes of technical and management cybersecurity activities that comprise a CSF...
- CSF Target ProfileA part of an Organizational Profile that specifies the desired Core outcomes that an organization has...
- CSF TierA characterization of the rigor of an organization’s cybersecurity risk governance and management practices...
- CSfC, see commercial solutions for classified (CSfC)
- cSHAKEThe customizable SHAKE function.
- CSIM, see CDMA Subscriber Identity Module (CSIM)
- CSMSee Capability, Configuration Settings Management.
- CSNThe Key Management Infrastructure core node that provides central security management and data management...
- CSO, see computer security object
- CSPA trusted entity that issues or registers subscriber authenticators and issues electronic credentials to...
- CSRA request sent from a certificate requester to a certificate authority to apply for a digital identity...
- CSRFA type of Web exploit where an unauthorized party causes commands to be transmitted by a trusted user of a...
- CSS, see certificate status server
- CTA framework for publicly logging the existence of Transport Layer Security (TLS) certificates as they are...
- CTAK, see cipher text auto-key
- CT&ESoftware, hardware, and firmware security tests conducted during development of an information system...
- CTI, see Cyber Threat Intelligence
- CTR_DRBGA DRBG specified in SP 800-90A based on a block cipher algorithm.
- CtriThe ith counter block.
- CTS, see computerized telephone system (CTS)
- CTTAAn experienced, technically qualified U.S. Government employee who has met established certification...
- CUAS, see common user application software (CUAS)
- CUI1. A categorical designation that refers to unclassified information that does not meet the standards for...
- CUI categories1. Those types of information for which laws, regulations, or government-wide policies require or permit...
- CUI Executive AgentThe National Archives and Records Administration (NARA), which implements the executive branch-wide CUI...
- CUI programThe executive branch-wide program to standardize CUI handling by all federal agencies. The program includes...
- CUI registry1. The online repository for all information, guidance, policy, and requirements on handling CUI, including...
- Cumulative Distribution Function (CDF) F(x)A function giving the probability that the random variable X is less than or equal to x, for every value x...
- Cumulative Sums Forward TestThe purpose of the cumulative sums test is to determine whether the sum of the partial sequences occurring in...
- Current Profile1. the ‘as is’ state of system cybersecurity
- CustodianA third-party entity that holds and safeguards a user’s private keys or digital assets on their behalf...
- Custom Environment1. An environment containing systems in which the functionality and degree of security do not fit the other...
- customer1. Organization or person that receives a product.
- Customer and Others in the IoT Product EcosystemThe person receiving a product or service and third-parties (e.g., other IoT product developers, independent...
- Customer-SpecifiableThe features of the MSR-compliant system that are set with a default value by the manufacturer, but can be...
- CustomizationThe ability to control the appearance of the SSL VPN Web pages that the users see when they first access the...
- cuttingThe use of a tool or physical technique to break the surface of electronic storage media, potentially...
- CVC1. A certificate stored on the PIV Card that includes a public key, the signature of a certification...
- CVEA dictionary of common names for publicly known information system vulnerabilities.
- CVE equivalentA vulnerability - known by someone - that has been found in specific software - irrespective of whether that...
- CVE IDAn identifier for a specific software flaw defined within the official CVE Dictionary and that conforms to...
- CVE Record MetadataInformation attached to the CVE by the NVD Analyst and/or CNA. Comprised of CVSS v3.1, CVSS v2, CWE...
- CVSS, see common vulnerability scoring system (CVSS)
- CWE, see common weakness enumeration (CWE)
- Cyberrefers to both information and communications networks.
- Cyber Attack1. An attempt to gain unauthorized access to system services, resources, or information, or an attempt to...
- cyber ecosystemThe aggregation and interactions of a variety of diverse participants (such as private firms, non-profits...
- cyber effectThe manipulation, disruption, denial, degradation, or destruction of information systems, networks, or...
- cyber incident1. Any observable occurrence involving computing assets, including physical and virtual platforms, networks...
- Cyber Incident Response TeamGroup of individuals usually consisting of security analysts organized to develop, recommend, and coordinate...
- cyber rangeThis technique provides a safe environment (i.e., “sandbox”) to deliver hands-on realistic training...
- cyber resiliency1. The ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or...
- cyber resiliency concept1. A concept related to the problem domain and/or solution set for cyber resiliency. Cyber resiliency...
- cyber resiliency constructElement of the cyber resiliency engineering framework (i.e., a goal, objective, technique, implementation...
- cyber resiliency control1. A control (i.e., a base control or a control enhancement), as defined in [NIST SP 800-53], that applies...
- cyber resiliency design principle1. A guideline for how to select and apply cyber resiliency analysis methods, techniques, approaches, and...
- cyber resiliency engineering practice1. A method, process, modeling technique, or analytical technique used to identify and analyze cyber...
- cyber risk1. The risk of depending on cyber resources (i.e., the risk of depending on a system or system elements that...
- Cyber SecurityThe ability to protect or defend the use of cyberspace from cyber attacks.
- cyber survivabilityThe ability of warfighter systems to prevent, mitigate, recover from and adapt to adverse cyber-events that...
- Cyber Survivability Attributes, see CSA
- Cyber Threat1. Any circumstance or event with the potential to adversely impact organizational operations and assets...
- Cyber Threat IntelligenceCyber threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide...
- cybersecurity1. Prevention of damage to, protection of, and restoration of computers, electronic communications systems...
- Cybersecurity and/or Privacy Learning Program managerThe person or people in the organization responsible for the development, procurement, integration...
- cybersecurity architectureA description of the structure and behavior for an enterprise's security processes, information security...
- cybersecurity componentAn application (hardware and/or software) that provides one or more CS capabilities in support of the overall...
- cybersecurity eventA cybersecurity change that may have an impact on organizational operations (including mission, capabilities...
- cybersecurity framework categoryThe subdivision of a Function into groups of cybersecurity outcomes, closely tied to programmatic needs and...
- cybersecurity framework coreA set of cybersecurity activities and references that are common across critical infrastructure sectors and...
- cybersecurity framework functionOne of the main components of the Framework. Functions provide the highest level of structure for organizing...
- cybersecurity framework profileA representation of the outcomes that a particular system or organization has selected from the Framework...
- cybersecurity framework subcategoryThe subdivision of a Category into specific outcomes of technical and/or management activities.
- Cybersecurity Incident1. An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity...
- cybersecurity infrastructureThe underlying security framework that lies beyond an enterprise's defined boundary, but supports its CS and...
- cybersecurity IT productProduct or technology whose primary purpose is to provide security services (e.g., confidentiality...
- cybersecurity outcomeStatement of what is expected either from a product or from an organization in support of a product related...
- Cybersecurity RiskAn effect of uncertainty on or within information and technology. Cybersecurity risks relate to the loss of...
- cybersecurity risks throughout the supply chainThe potential for harm or compromise arising from suppliers, their supply chains, their products, or their...
- Cybersecurity StateThe condition of a device’s cybersecurity expressed in a way that is meaningful and useful to authorized...
- cybersecurity supply chain risk assessment1. Systematic examination of cybersecurity risks throughout the supply chain, likelihoods of their...
- Cybersecurity Supply Chain Risk Management1. A systematic process for managing exposure to cybersecurity risks throughout the supply chain and...
- cybersecurity supply chain risk management planA formal document that describes the implementations, requirements, constraints, and implications of...
- cybersecurity-enabled information technology productA product or technology whose primary role is not security, but that provides security services as an...
- cyberspace1. The interdependent network of information technology infrastructures that includes the Internet...
- cyberspace attack1. Cyberspace actions that create various direct denial effects (i.e., degradation, disruption, or...
- cyberspace capabilityA device or computer program, including any combination of software, firmware, or hardware, designed to...
- cyberspace defenseActions taken within protected cyberspace to defeat specific threats that have breached or are threatening to...
- cyberspace exploitation1. Actions taken in cyberspace to gain intelligence, maneuver, collect information, or perform other enabling...
- cyberspace operations (CO)The employment of cyberspace capabilities where the primary purpose is to achieve objectives in or through...
- cyberspace superiorityThe degree of dominance in cyberspace by one force that permits the secure, reliable conduct of operations by...
- Cycle TimeThe time, usually expressed in seconds, for a controller to complete one control loop where sensor signals...
- cyclic redundancy check (CRC)1. A type of checksum algorithm that is not a cryptographic hash but is used to implement data integrity...
672 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.