MLchartDataset catalogue

Demilitarized zone (DMZ)

Term · Cybersecurity · MLC-T-CYB-001303

1. Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network's CS policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.

2. An interface on a routing firewall that is similar to the interfaces found on the firewall’s protected side. Traffic moving between the DMZ and other interfaces on the protected side of the firewall still goes through the firewall and can have firewall protection policies applied.

3. A host or network segment inserted as a “neutral zone” between an organization’s private network and the Internet.

4. A network created by connecting two firewalls. Systems that are externally accessible but need some protections are usually located on DMZ networks.

5. Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network's information assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding thei internal networks from external attacks.

6. A perimeter network or screened subnet separating an internal network that is more trusted from an external network that is less trusted.

Table 1. Record
IdentifierMLC-T-CYB-001303
FieldCybersecurity
AbbreviationDMZ
ReferencesCNSSI 4009-2022; NIST SP 1800-21C; NIST SP 800-41 Rev. 1; NIST SP 800-82r3 from NIST SP 800-41 Rev. 1; NIST SP 800-44 Version 2; NIST SP 800-45 Version 2; NIST SP 1800-21B from NISTIR 7711; NISTIR 7711; NIST SP 1800-12b; NIST SP 1800-16B; NIST SP 1800-16C; NIST SP 1800-16D; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-001303",
  "term": "Demilitarized zone (DMZ)",
  "field": "Cybersecurity",
  "definition": "1. Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network's CS policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.\n\n2. An interface on a routing firewall that is similar to the interfaces found on the firewall’s protected side. Traffic moving between the DMZ and other interfaces on the protected side of the firewall still goes through the firewall and can have firewall protection policies applied.\n\n3. A host or network segment inserted as a “neutral zone” between an organization’s private network and the Internet.\n\n4. A network created by connecting two firewalls. Systems that are externally accessible but need some protections are usually located on DMZ networks.\n\n5. Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network's information assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding thei internal networks from external attacks.\n\n6. A perimeter network or screened subnet separating an internal network that is more trusted from an external network that is less trusted.",
  "abbreviation": "DMZ",
  "references": [
    "CNSSI 4009-2022",
    "NIST SP 1800-21C; NIST SP 800-41 Rev. 1; NIST SP 800-82r3 from NIST SP 800-41 Rev. 1",
    "NIST SP 800-44 Version 2; NIST SP 800-45 Version 2",
    "NIST SP 1800-21B from NISTIR 7711; NISTIR 7711",
    "NIST SP 1800-12b",
    "NIST SP 1800-16B; NIST SP 1800-16C; NIST SP 1800-16D",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/demilitarized-zone-dmz/"
}

Record 1,298 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.