Cybersecurity terminology · MLC-0102
Cybersecurity terms: O (119)
- OOutput Block
- O1,…,O64Bits of the Output Block
- object1. Passive system-related entity, including bits, bytes, words, fields, devices, files, records, programs...
- Object, Assessment1. The item (i.e., specifications, mechanisms, activities, individuals) upon which an assessment method is...
- Object Identification, see OID
- Object Naming ServiceAn inter-enterprise subsystem for the EPCglobal Network that provides network resolution services that direct...
- object reuseThe reassignment to some subject of a storage medium (e.g., page frame, disk sector, magnetic tape) that...
- ObligationAn operation specified in a policy or policy set that should be performed by the PEP in conjunction with the...
- obscured datadata that has been distorted by cryptographic or other means to hide information. It is also referred to as...
- ObservableAn event (benign or malicious) on a network or system.
- observational dataData captured through the observation of an activity or behavior without the direct involvement of the...
- OCIL, see Open Checklist Interactive Language (OCIL)
- OCO, see offensive cyberspace operations (OCO)
- OCSP, see Online Certificate Status Protocol (OCSP)
- octet1. A string of eight bits.
- Octet LengthThe number of octets in an octet string.
- Octet StringAn ordered sequence of octets.
- OD, see On-demand self-service
- ODP1. The variable part of a control or control enhancement that is instantiated by an organization during the...
- Off-CardRefers to data that is not stored within the PIV Card or to a computation that is not performed by the...
- Off-ChainRefers to data that is stored or a process that is implemented and executed outside of any blockchain system.
- offensive cyberspace operations (OCO)Missions intended to project power in and through cyberspace.
- Official CPE DictionaryThe authoritative repository of identifier names, which is hosted by NIST.
- Official Identifier CPE NameAny bound representation of a CPE WFN that uniquely identifies a single product class and is contained within...
- official informationAll information of any kind, however stored, that is in the custody and control of the Department/Agency...
- Offline TestOffline tests use previously captured images as inputs to core biometric implementations. Such tests are...
- OIDA globally unique identifier of a data object as defined in ISO/IEC 8824-2.
- OIMOOrganization Identity Management Official; The individual responsible for overseeing the operations of an...
- OjThe jth output block.
- OLIRRelationships between elements of two documents that are recorded in a NIST IR 8278A-compliant format and...
- OLIR Catalog1. The Online Informative References (OLIR) Catalog, which provides information about the Informative...
- OLIR Developer1. A person, team, or organization that creates an OLIR and submits it to the National OLIR Program.
- OLIR ProgramNIST’s Cybersecurity Framework (CSF) Online Informative References Program.
- OLIR Template1. A spreadsheet that contains the fields necessary for creating a well-formed OLIR for submission to the...
- OnBlock of data representing Output Block n
- on behalf of (an agency)1. A situation that occurs when (i) a non-executive branch entity uses or operates an information system or...
- On-Access Scanning1. Performing real-time scans on a computer of each file as it is downloaded, opened, or executed.
- OnboardingThe process by which a device obtains the credentials (e.g., network SSID and password) that it needs in...
- onboarding credentialsThe unique credentials that the IoT device requires to connect securely to the local network (e.g., network...
- onboarding solutionA product/technology/service combination that an organization will deploy to onboard devices to its network...
- On-CardRefers to data that is stored within the PIV Card or to a computation that is performed by the Integrated...
- On-ChainRefers to data that is stored or a process that is implemented and executed within a blockchain system.
- On-Demand Scanning1. Launching scans of a computer manually as needed.
- On-demand self-serviceA consumer can unilaterally provision computing capabilities, such as server time and network storage, as...
- On-demand testA type of health test that is available to be run whenever a user or a relying component requests it.
- one-source mappingA mapping between concepts within a single concept source.
- One-to-one1. The process in which a biometric sample from an individual is compared to a biometric reference to produce...
- one-way hash algorithmHash algorithms which map arbitrarily long inputs into a fixed-size output such that it is very difficult...
- one-way transferPermitting the flow of data to move in one direction only.
- one-way transfer deviceA mechanism, usually implemented in hardware, which enforces a unidirectional data flow with varying degrees...
- ongoing assessment and authorization1. Maintaining ongoing awareness of information security, vulnerabilities, and threats to support...
- Online Certificate Status Protocol (OCSP)An online protocol used to determine the status of a public key certificate.
- Online Certificate Status Protocol responderA PKI entity that verifies the revocation status of certificates following the Online Certificate Status...
- online serviceA service that is accessed remotely via a network, typically the internet.
- ONSAn inter-enterprise subsystem for the EPCglobal Network that provides network resolution services that direct...
- OOBCommunication between parties utilizing a means or method that differs from the current method of...
- OPCODE, see operations code (OPCODE)
- Open Checklist Interactive Language (OCIL)SCAP language for expressing security checks that cannot be evaluated without some human interaction or...
- Open Pretty Good Privacy (OpenPGP)A protocol defined in IETF RFCs 2440 and 3156 for encrypting messages and creating certificates using public...
- open storageAny storage of classified national security information outside of General Services Administration-approved...
- Open SystemA system that allows entities from different enterprises to access information related to tags used in the...
- Open Vulnerability and Assessment Language (OVAL)1. A language for representing system configuration information, assessing machine state, and reporting...
- OpenPGP, see Open Pretty Good Privacy (OpenPGP)
- operating system1. The software “master control application” that runs the computer. It is the first program loaded when the...
- Operating System (OS) FingerprintingAnalyzing characteristics of packets sent by a target, such as packet headers or listening ports, to identify...
- Operating system virtualization1. A virtual implementation of the operating system interface that can be used to run applications written...
- Operation1. the set of access modes or types permitted on objects of the system.
- Operation Security, see OPSEC
- operational concept1. Verbal and graphic statement, in broad outline, of an organization’s assumptions or intent in regard to an...
- Operational Controls1. The security controls (i.e., safeguards or countermeasures) for an information system that primarily are...
- operational environment1. Context determining the setting and circumstance of all influences on a delivered system.
- operational keyKey intended for use over-the-air for protection of operational information or for the production or secure...
- operational margin1. A spare amount or measure or degree allowed or given for contingencies or special situations. The...
- operational optimizationSelection of those risks from the register that are most valuable based upon leadership preferences, mission...
- Operational phase1. A phase in the lifecycle of keying material whereby keying material is used for standard cryptographic...
- operational resilience1. The ability of systems to resist, absorb, and recover from or adapt to an adverse occurrence during...
- Operational storage1. Storage within an FCKMS where the key can be accessed to perform cryptographic functions during normal...
- operational technology1. Programmable systems or devices that interact with the physical environment (or manage devices that...
- Operational TestOperational tests involve a deployed system and are usually conducted to measure in-the- field performance...
- operational waiverAuthority for continued use of unmodified COMSEC end-items pending the completion of a mandatory modification.
- OperationalizationPutting MUD implementations into operational service in a manner that is both practical and effective.
- operations code (OPCODE)Code composed largely of words and phrases suitable for general communications use.
- operations security (OPSEC)1. A process of identifying critical information and analyzing friendly actions attendant to military...
- operator1. An FCKMS role that is authorized to operate an FCKMS (e.g., initiate the FCKMS, monitor performance, and...
- OPM, see ordering privilege manager (OPM)
- OpportunityA condition that may result in a beneficial outcome.
- OPSECSystematic and proven process by which potential adversaries can be denied information about capabilities and...
- Option ROMFirmware that is called by the system BIOS. Option ROMs include BIOS firmware on add-on cards (e.g., video...
- optional modificationNSA-approved modification not required for universal implementation by all holders of a COMSEC end-item. This...
- ORA, see organizational registration authority (ORA)
- OracleA source of data from outside a blockchain that serves as input for a smart contract.
- OrchestrationDefines the sequence and conditions in which one Web service invokes other Web services to realize some...
- OrchestratorA tool that enables DevOps personas or automation working on their behalf to pull images from registries...
- ordering privilege manager (OPM)The key management entity (KME) authorized to designate other KME as a short title assignment requester...
- ordinal scaleFrom the Stevens Scale of Measurement, a scale that orders and ranks data without establishing a degree of...
- organization1. A federal agency or, as appropriate, any of its operational elements.
- Organizational Information Security Continuous MonitoringOngoing monitoring sufficient to ensure and assure effectiveness of security controls related to systems...
- organizational registration authority (ORA)Entity within the public key infrastructure (PKI) that authenticates the identity and the organizational...
- organizational user1. An organizational employee or an individual the organization deemed to have similar status of an employee...
- organizationally-tailored control baselineA control baseline tailored for a defined notional (type of) information system using overlays and/or...
- organization-defined control parameter1. See organization-defined parameter.
- organization-defined parameter1. The variable part of a control or control enhancement that is instantiated by an organization during the...
- OriginatorAn entity that initiates an information exchange or storage event.
- Originator-usage period1. The period of time in the cryptoperiod of a key during which cryptographic protection may be applied to...
- Orphan blockAny block that is not in the main chain after a temporary ledger conflict.
- OS1. A collection of software that manages computer hardware resources and provides common services for...
- oscillatorAn electronic device used to generate an oscillating signal. The oscillation is based on a periodic event...
- OT1. Programmable systems or devices that interact with the physical environment (or manage devices that...
- OTAD, see over-the-air key distribution (OTAD)
- OTAR, see over-the-air rekeying (OTAR)
- OTAT, see over-the-air key transfer (OTAT)
- other system1. A system that the system of interest interacts with in the operational environment. These systems may...
- OtherInputOther information for key derivation; a bit string.
- OutageA period when a service or an application is not available or when equipment is not operational.
- outcomeResult of the performance (or non-performance) of a function or process(es).
- outcome-specific utility metricsA way of measuring the utility of data for answering a specific question or class of questions.
- outliersAn observation that lies an abnormal distance from other values in a random sample from a population.
- out-of-distributionData that was collected at a different time and possibly under different conditions or in a different...
- Output BlockA data block that is an output of either the forward cipher function or the inverse cipher function of the...
- Output spaceThe set of all possible distinct bitstrings that may be obtained as samples from a digitized noise source.
- outside(r) threatAn unauthorized entity outside the security domain that has the potential to harm an information system...
- OVAL, see Open Vulnerability and Assessment Language (OVAL)
- OVAL IDAn identifier for a specific OVAL definition that conforms to the format for OVAL IDs.
- overlay1. A specification of security or privacy controls, control enhancements, supplemental guidance, and other...
- Overlay networkA software-defined networking component included in most orchestrators that can be used to isolate...
- overt channelCommunications path within a computer system or network designed for the authorized transfer of data.
- Overt TestingSecurity testing performed with the knowledge and consent of the organization’s IT staff.
- over-the-air key distribution (OTAD)Providing electronic key via over-the-air rekeying, over-the-air key transfer, or cooperative key generation.
- over-the-air key transfer (OTAT)Electronically distributing key without changing traffic encryption key used on the secured communications...
- over-the-air rekeying (OTAR)Changing traffic encryption key or transmission security key in remote cryptographic equipment by sending new...
- over-the-network keying (OTNK)A set of data items and messages (termed OTNK Service Messages) that a KMI- aware User Device processes to...
- overwrite1. Writing data on top of the physical location of data stored on the media.
- Owner1. A key pair owner is the entity authorized to use the private key of a key pair.
119 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.