Cybersecurity terminology · MLC-0102
Cybersecurity terms: E (170)
- e1. The original input string of zero and one bits to be tested.
- EA1. The description of an enterprise’s entire set of information systems: how they are configured, how they...
- EAL, see Evaluation Assurance Level
- EAP, see emergency action plan (EAP); Extensible Authentication Protocol (EAP)
- Ease-of-useA metric of satisfaction in using a product as established by one or more individuals using the product.
- e-authentication assurance levelA measure of trust or confidence in an authentication mechanism defined in publications Office of Management...
- EavesdropperA party that secretly receives communications intended for others.
- eBGPA BGP operation communicating routing information between two or more ASes.
- eBits1. The bit length of the RSA exponent e.
- ebXML, see Electronic Business XML (ebXML)
- ECAny vulnerability disclosure entity that receives a vulnerability report that is not within the FCB or the...
- ECC1. Elliptic Curve Cryptography, the public-key cryptographic methods using operations in an elliptic curve...
- ECDS, see enterprise cross domain services (ECDS)
- ECDSA1. a digital signature algorithm that is an analog of DSA using elliptic curve mathematics and specified in...
- e-commerceThe use of network technology (especially the internet) to buy or sell goods and services.
- ECU, see end cryptographic unit (ECU)
- EDGEAn upgrade to GPRS to provide higher data rates by joining multiple time slots.
- Education1. The ‘Education’ level integrates all of the security skills and competencies of the various functional...
- EEMAwww.eema.org (pka European Electronic Messaging Association)
- EFD, see electronic fill device (EFD)
- effective periodTime span during which each COMSEC key edition (i.e., multiple key segments) remains in effect.
- effectiveness1. The extent to which planned activities are realized and planned results achieved.
- efficient (cryptographic) algorithmAn algorithm whose running time is practical for the relevant security strength.
- EFI, see Extensible Firmware Interface (EFI)
- Egress FilteringFiltering of outgoing network traffic.
- eiThe ith bit in the original sequencee.
- EiB2^(60) bytes
- EIT, see enterprise information technology
- EKEYx(Y)Encrypt Y with the key KEYx
- EKMS, see electronic key management system (EKMS)
- Electromagnetic Interference1. An electromagnetic disturbance that interrupts, obstructs, or otherwise degrades or limits the effective...
- Electronic Business XML (ebXML)Sponsored by UN/CEFACT and OASIS, a modular suite of specifications that enable enterprises of any size and...
- Electronic Commerce, see e-commerce
- electronic credentialsDigital documents used in authentication that bind an identity or an attribute to a subscriber's...
- Electronic EvidenceInformation and data of investigative value that is stored on or transmitted by an electronic device.
- electronic fill device (EFD)A COMSEC item used to transfer or store key in electronic form or to insert key into cryptographic equipment.
- electronic key management system (EKMS)An interoperable collection of systems that automate the planning, ordering, generating, distributing...
- electronic messaging servicesServices providing interpersonal messaging capability; meeting specific functional, management, and technical...
- electronic PHI, see Electronic Protected Health Information
- Electronic Product Code (EPC) IdentifierOne of the available formats for encoding identifiers on RFID tags. The EPC is a globally unique number that...
- Electronic Product Code Information Services (EPCIS)An inter-enterprise subsystem that facilitates information sharing using the EPCglobal network. EPCISs...
- Electronic Protected Health Information1. Information that comes within paragraphs (1)(i) or (1)(ii) of the definition of protected health...
- Electronic Serial Number (ESN)A unique 32-bit number programmed into CDMA phones when they are manufactured.
- electronic signatureA method of signing an electronic message that-
- electronically generated keyKey generated in a COMSEC device by introducing (either mechanically or electronically) a seed key into the...
- electronic/digital file transferTransmission of a file (information) between two systems via a file transfer (communications) protocol.
- Electrotechnical Commission, see EC
- element1. Organizations, entities, or tools employed for the research and development, design, manufacturing...
- Element ProcessesA series of operations performed in the making or treatment of an element; performing operations on...
- elephant diffuserA (now deprecated) component in BitLocker Drive Encryption to increase resistance against ciphertext...
- Elliptic Curve, see EC
- Elliptic Curve Cryptography1. Elliptic Curve Cryptography, the public-key cryptographic methods using operations in an elliptic curve...
- Elliptic Curve Digital Signature Algorithm1. a digital signature algorithm that is an analog of DSA using elliptic curve mathematics and specified in...
- emergenceThe behaviors and outcomes that result from how individual system elements compose to form the system as a...
- emergency action plan (EAP)A plan developed to prevent loss of national intelligence; protect personnel, facilities, and communications...
- Emergency Medical Services, see EMS
- Emergency revocationA revocation of keying material that is effected in response to an actual or suspected compromise of a key.
- EMIAn electromagnetic disturbance that interrupts, obstructs, or otherwise degrades or limits the effective...
- emission security (EMSEC)The component of communications security that results from all measures taken to deny unauthorized persons...
- EMMEnterprise Mobility Management (EMM) systems are a common way of managing mobile devices in the enterprise...
- EMSan improved message system for GSM mobile phones allowing picture, sound, animation and text elements to be...
- EMSEC, see emission security (EMSEC)
- enabling system1. A system that provides support to the life cycle activities associated with the system of interest...
- enc8(i)For an integer i ranging from 0 to 255, enc8(i) is the byte encoding of i, with bit 0 being the low-order bit...
- Encapsulating Security Payload (ESP)The core IPsec security protocol; can provide integrity protection and (optionally) encryption protection for...
- encapsulationThe process of applying the Encaps algorithm of a KEM. This algorithm accepts the encapsulation key as input...
- encapsulation key1. A cryptographic key produced by a KEM during key generation and used during the encapsulation process. The...
- encipher1. Cryptographically transform data to produce cipher text.
- enclaveA set of system resources that operate in the same security domain and that share the protection of a single...
- enclave boundaryPoint at which an enclave's internal network service layer connects to an external network's service layer...
- encodeUse a system of symbols to represent information, which might originally have some other representation...
- encryptCryptographically transform data to produce cipher text.
- encrypted key1. Key that has been encrypted in a system approved by the National Security Agency (NSA) for key encryption.
- encryption1. The process of transforming plaintext into ciphertext for the purpose of security or privacy.
- encryption algorithm1. Process which transforms plaintext into ciphertext.
- encryption certificateA certificate containing a public key that can encrypt or decrypt electronic messages, files, documents, or...
- encryption key1. A cryptographic key that is used with a PKE in order to encrypt plaintexts into ciphertexts. The...
- end cryptographic unit (ECU)Device that 1) performs cryptographic functions, 2) typically is part of a larger system for which the device...
- end-item accountingAccounting for all the accountable components of a COMSEC equipment configuration by a single short title.
- endpointAny device that is used to access a digital identity on a network, such as laptops, desktops, mobile phones...
- end-point protection platformSafeguards implemented through software to protect end-user machines such as workstations and laptops against...
- Endpoint Protection PlatformSafeguards implemented through software to protect end-user machines such as workstations and laptops against...
- end-to-end securitySafeguarding information in an information system from point of origin to point of destination.
- Energy Management System, see EMS
- energy-latency attackAn attack that exploits the performance dependency on hardware and model optimizations to negate the effects...
- engineered systemA system designed or adapted to interact with an anticipated operational environment to achieve one or more...
- engineered teamThe individuals on the systems engineering team with security responsibilities, systems security engineers...
- Enhanced Data for GSM Evolution (EDGE)An upgrade to GPRS to provide higher data rates by joining multiple time slots.
- Enhanced Messaging Service (EMS)1. An improved message system for GSM mobile devices allowing picture, sound, animation and text elements to...
- Enhanced OverlayOverlay that adds processes, controls, enhancements, and additional implementation guidance specific to the...
- enhanced security requirements1. Security requirements that are to be implemented in addition to the basic and derived security...
- Enrollment1. The process of making a person’s identity known to the PIV system, associating a unique identifier with...
- Enrollment Data SetA record that includes information about a biometric enrollment (i.e., name and role of the acquiring agent...
- enrollment managerThe management role that is responsible for assigning user identities to management and non-management roles.
- ensemble learningA type of a meta machine learning approach that combines the predictions of several models to improve...
- enterprise1. An organization with a defined mission/goal and a defined boundary, using information systems to execute...
- enterprise architecture (EA)1. A strategic information asset base that defines the mission, the information necessary to perform the...
- enterprise auditThe identification, collection, correlation, analysis, storage and reporting of audit information.
- enterprise cross domain services (ECDS)A set of cross domain services implemented by a government agency or an authorized commercial provider that...
- enterprise cross domain services (ECDS) providerAn organization that establishes, manages and maintains the overall infrastructure and security posture...
- enterprise information technologyThe application of computers and telecommunications equipment to store, retrieve, transmit, and manipulate...
- Enterprise Mobility ManagementEnterprise Mobility Management (EMM) systems are a common way of managing mobile devices in the enterprise...
- enterprise patch managementThe process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches...
- Enterprise RiskThe effect of uncertainty on enterprise mission and objectives.
- enterprise risk management1. The methods and processes used by an enterprise to manage risks to its mission and to establish the trust...
- Enterprise Risk RegisterA risk register at the enterprise level that contains normalized and aggregated inputs from subordinate...
- enterprise serviceA set of one or more computer applications and middleware systems hosted on computer hardware that provides...
- Enterprise SubsystemThe portion of the RFID system that analyzes, processes, and stores information collected by the RF...
- enterprise-hosted cross domain solutionA cross domain solution (CDS) that is managed by an enterprise cross domain service provider (ECDSP), but...
- entity1. An individual (person), organization, device or process. Used interchangeably with “party.”
- Entity authentication1. The process of providing assurance about the identity of an entity interacting with a system (e.g., to...
- Entity registrationA function in the lifecycle of a cryptographic key; a process whereby an entity becomes a member of a...
- Entropy1. A measure of the randomness or uncertainty of a random variable.
- Entropy InputAn input bitstring that provides an assessed minimum amount of unpredictability for a DRBG mechanism. (See...
- Entropy rateThe rate at which a digitized noise source (or entropy source) provides entropy; it is computed as the...
- Entropy Source1. The combination of a noise source, health tests, and optional conditioning component that produce...
- environment1. Context determining the setting and circumstances of all influences upon a system.
- environment conditionsDynamic factors, independent of subject and object, that may be used as attributes at decision time to...
- environment of operation1. The physical surroundings in which an information system processes, stores, and transmits information.
- Environmental Support1. Any environmental factor for which the organization determines that it needs to continue to provide...
- Environmental testingEvaluating the behavior of a device or system to obtain assurance that it will not be compromised by...
- E.O., see Executive Order
- EO, see Executive Order
- EO-critical softwareAny software that has, or has direct software dependencies upon, one or more components with at least one of...
- EOPThe President's immediate staff, along with entities such as the Office of Management and Budget, the...
- EOTA method for strengthening adversarial examples to remain adversarial under image transformations that occur...
- EPCIS, see Electronic Product Code Information Services (EPCIS)
- Ephemeral Key1. A cryptographic key that is generated for each execution of a cryptographic process (e.g., key...
- Ephemeral key pair1. A key pair, consisting of a public key (i.e., an ephemeral public key) and a private key (i.e., an...
- ePHI, see Electronic Protected Health Information
- EPL, see Evaluated Products List
- EPP, see Endpoint Protection Platform
- Equivalent inverse cipherAn alternative specification of the inverse of CIPHER() with a structure similar to that of CIPHER() and with...
- Equivalent Process1. Two processes are equivalent if the same output is produced when the same values are input to each process...
- Equivalent security domainsTwo or more security domains that have FCKMS security policies that have been determined to provide...
- Erfc1. See Erfc.
- ERM1. The methods and processes used by an enterprise to manage risks to its mission and to establish the trust...
- ERRA risk register at the enterprise level that contains normalized and aggregated inputs from subordinate...
- errorThe difference between desired and actual performance or behavior of a system or system element.
- EscapeThe act of breaking out of a guest OS to gain access to the hypervisor, other guest OSs, or the underlying...
- ESNA unique 32-bit number programmed into CDMA phones when they are manufactured.
- ES(nBits)The estimated maximum security strength for an RSA modulus of length nBits (see Table 2).
- ESP, see Encapsulating Security Payload (ESP)
- EstimateThe estimated value of a parameter, as computed using an estimator.
- Estimated maximum security strengthAn estimate of the largest security strength that can be attained by a cryptographic mechanism given the...
- EstimatorA technique for estimating the value of a parameter.
- ethernet data encryption cryptographic interoperability specification (EDE-CIS)A standard defining the requirements for Ethernet encryption, similar to HAIPE but for layer 2 Ethernet...
- Evaluated Products ListList of validated products that have been successfully evaluated under the National Information Assurance...
- evaluating authorityThe official responsible for evaluating a reported COMSEC incident for the possibility of compromise.
- Evaluation Assurance LevelSet of assurance requirements that represent a point on the Common Criteria predefined assurance scale...
- evaluation criteriaThe standards by which accomplishments of technical and operational effectiveness or suitability...
- event1. Any observable occurrence involving computing assets, including physical and virtual platforms, networks...
- Event Aggregation1. See “Event Aggregation”.
- Event Correlation1. See “Event Correlation”.
- Event FilteringThe suppression of log entries from analysis, reporting, or long-term storage because their characteristics...
- Event ReductionRemoving unneeded data fields from all log entries to create a new log that is smaller.
- event-level privacyA unit of privacy that defines neighboring databases as those that differ in one event, for example, a single...
- evidenceGrounds for belief or disbelief; data on which to base proof or to establish truth or falsehood.
- Examination1. A technical review that makes the evidence visible and suitable for analysis; as well as tests performed...
- exbibyte2^(60) bytes
- exclusive-OR1. The bitwise addition, modulo 2, of two bit strings of equal length.
- Exculpatory EvidenceEvidence that tends to decrease the likelihood of fault or guilt.
- eXecute In PlaceA facility that allows code to be executed directly from flash memory without loading the code into RAM.
- executive agency1. An executive department specified in 5 U.S.C., SEC. 101; a military department specified in 5 U.S.C., SEC...
- Executive Office of the PresidentThe President's immediate staff, along with entities such as the Office of Management and Budget, the...
- Executive OrderLegally binding orders given by the President, acting as the head of the Executive Branch, to Federal...
- ExerciseA simulation of an emergency designed to validate the viability of one or more aspects of an IT plan.
- Exercise BriefingMaterial that is presented to participants during an exercise to outline the exercise’s agenda, objectives...
- Exercise DirectorA person responsible for all aspects of an exercise, including staffing, development, conduct, and logistics.
- exfiltration1. The unauthorized transfer of information from an information system.
- expectation over transformationA method for strengthening adversarial examples to remain adversarial under image transformations that occur...
- experimentationA systematic approach to the process of testing new ideas, methods, or activities that applies principles and...
- expert determinationWithin the context of de-identification, refers to the Expert Determination method for de-identifying...
- exploitable channelChannel that allows the violation of the security policy governing an information system and is usable or...
- exploratory data analysisA data analysis technique where data collection is immediately followed by analysis with the goal of...
- Exposure1. Extent to which an organization and/or stakeholder is subject to a risk.
- eXtendable-Output Function (XOF)1. A function on bit strings in which the output can be extended to any desired length. Approved XOFs (e.g...
- Extendable-Output Functions, see XOF
- Extended CPE DictionaryA dictionary that an organization may create to house identifier names not found in the Official CPE...
- Extended Sequence Number, see ESN
- Extended Validation Certificate1. A certificate used for HTTPS websites and software that includes identity information that has been...
- Extensible Authentication Protocol (EAP)A framework for adding arbitrary authentication methods in a standardized way to any protocol.
- extensible configuration checklist description format (XCCDF)SCAP language for specifying checklists and reporting checklist results.
- Extensible Firmware Interface (EFI)A specification for the interface between the operating system and the platform firmware. Version 1.10 of the...
- eXtensible HyperText Markup Languagea unifying standard that brings the XML benefits of easy validation and troubleshooting to HTML.
- ExtensionThe set of individual products to which a WFN refers.
- Extension IdentifierAny piece of identifying information provided in an asset identification element that is not explicitly...
- Exterior Border Gateway ProtocolA BGP operation communicating routing information between two or more ASes.
- external assessment engagement1. Formal engagement led by a third-party assessment organization.
- External BGP, see eBGP
- external coordinatorAny vulnerability disclosure entity that receives a vulnerability report that is not within the FCB or the...
- External KeyAn authorized key that is used from outside the organization (or outside the environment considered for SSH...
- external networkA network not controlled by the organization.
- external operational management roleA role intended to be performed by a manager who is typically a member of a key management infrastructure...
- External Security TestingSecurity testing conducted from outside the organization’s security perimeter.
- extranetA computer network that an organization uses for application data traffic between the organization and its...
170 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.