Cybersecurity terminology · MLC-0102
Cybersecurity terms: P (370)
- p1. An FFC domain parameter; an odd prime number that determines the size of the finite field GF(p).
- (p, q, d)RSA private key in the prime-factor format.
- (p, t)-completenessFor a given set of n variables, (p, t)-completeness is the proportion of the C(n, t) combinations that have...
- P1First parameter of a card command
- P1,…,P64Bits of the Plaintext Block
- P2Second parameter of a card command
- PaaS, see Platform as a Service (PaaS)
- package management systemAn administrative tool or utility that facilitates the installation and maintenance of software on a given...
- package manifestA listing of the contents of a software package.
- PacketThe logical unit of network communications produced by the transport layer.
- Packet Filter1. A routing device that provides access control functionality for host addresses and communication sessions.
- Packet Number, see Pn
- packet sniffer1. Software that observes and records network traffic.
- packet sniffer and passive wiretappingSee packet sniffer and passive wiretapping.
- PACSAn automated system that manages the passage of people or assets through an opening(s) in a secure...
- PAD, see Presentation Attack Detection (PAD)
- paddingA string consisting of a single “1” bit, followed by zero or more “0” bits.
- page checkThe verification of the presence of each required page in a physical publication.
- pairing codeAn 8-digit code used to establish a relationship between the PIV Card and a device for the purpose of...
- Pairwise Pseudonymous Identifier1. A pseudonymous identifier generated by an IdP for use at a specific RP.
- Pairwise TrustEstablishment of trust by two entities that have direct business agreements with each other.
- Pandemic Influenza, see PI
- PAO, see principal authorizing official (PAO)
- PAPProvides a user interface for creating, managing, testing, and debugging digital policies and metapolicies...
- Paperwork Reduction Act, see PRA
- parallel file system, see PFS
- parameter1. A value that is used to control the operation of a function or that is used by a function to compute one...
- ParavirtualizationA method for a hypervisor to offer interfaces to a guest OS that the guest OS can use instead of the normal...
- parent assessment elementThe assessment element in a prior process step from which the current element was derived.
- parity bitA checksum that is computed on a block of bits by computing the binary sum of the individual bits in the...
- Participant GuideAn exercise document that typically contains the exercise’s purpose, scope, objectives, and scenario, and a...
- PartitionA logical portion of a media that functions as though it were physically separate from other logical portions...
- PartitioningManaging guest operating system access to hardware so that each guest OS can access its own resources but...
- party1. An individual (person), organization, device, or a combination thereof. In this Recommendation, an entity...
- passive attack1. An attack that does not alter systems or data.
- Passive Security TestingSecurity testing that does not involve any direct interaction with the targets, such as sending packets to a...
- Passive TagA tag that does not have its own power supply. Instead, it uses RF energy from the reader for power. Due to...
- passive wiretappingThe monitoring or recording of data that attempts only to observe a communication flow and gain knowledge of...
- Passphrase1. A password that consists of a sequence of words or other text that a claimant uses to authenticate their...
- password1. A string of characters (letters, numbers, and other symbols) used to authenticate an identity or to verify...
- Password Authentication Protocol, see PAP
- Password CrackingThe process of recovering secret passwords stored in a computer system or transmitted over a network.
- Password Protected1. The ability to protect the contents of a file or device from being accessed until the correct password is...
- patch1. Software component that, when installed, directly modifies files or device settings related to a different...
- patch levelDenotes either a patch level or a patch set. More specifically, when patches must be applied in order, the...
- patch managementThe systematic notification, identification, deployment, installation, and verification of operating system...
- patch setWhen patches do not need to be applied in any particular order, the patch set includes all (and only) the...
- patchingThe act of applying a change to installed software - such as firmware, operating systems, or applications -...
- Path ValidationThe process of verifying the binding between the subject identifier and subject public key in a certificate...
- payload1. Consists of the information passed down from the previous layer.
- payload control centerA facility that provides C2 for satellite payloads.
- Payment Card Industry Data Security StandardAn information security standard administered by the Payment Card Industry Security Standards Council that is...
- PBAC, see policy based access control (PBAC)
- PCCA facility that provides C2 for satellite payloads.
- PCI DSSAn information security standard administered by the Payment Card Industry Security Standards Council that is...
- PCM, see positive control material; Privacy Continuous Monitoring; privilege certificate manager (PCM)
- PDA, see Personal Digital Assistant (PDA)
- PDPComputes access decisions by evaluating the applicable digital policies and metapolicies. One of the main...
- PDS, see protected distribution system (PDS)
- pebibyte2^(50) bytes.
- PEDAn electronic device used in a debit, credit, or smart card-based transaction to accept and encrypt the...
- pedigreeThe validation of the composition and provenance of technologies, products, and services is referred to as...
- peer entity authenticationThe corroboration that a peer entity in an association is the one claimed.
- peer entity authentication serviceA security service that verifies an identity claimed by or for a system entity in an association.
- PeersEntities at the same tier in a CKMS hierarchy (e.g., all peers are client nodes).
- Pending transaction poolA distributed queue where candidate transactions wait until they are added to the blockchain. Also known as...
- penetration1. Unauthorized access to a Federal Government or critical infrastructure network, information system, or...
- penetration testing1. Testing used in vulnerability analysis for vulnerability assessment, trying to reveal vulnerabilities of...
- penetration-resistant architecture1. An architecture that uses technology and procedures to limit the opportunities for an adversary to...
- PEP1. Enforces policy decisions in response to a request from a subject requesting access to a protected object...
- per-call keyUnique traffic encryption key generated automatically by certain secure telecommunications systems to secure...
- Perceived Target Valuemeasures the likelihood of attack using the misuse vulnerability in an environment relative to vulnerable...
- Perfect Forward Secrecy (PFS)1. An option available during quick mode that causes a new shared secret to be created through a...
- performance reference model (PRM)Framework for performance measurement providing common output measurements throughout the Federal Government...
- Period of protection1. The period of time during which the integrity and/or confidentiality of a key needs to be maintained.
- Periodic Template TestThe purpose of this test is to reject sequences that show deviations from the expected number of runs of ones...
- periods processing1. A mode of system operation in which information of different sensitivities is processed at distinctly...
- perishable dataInformation whose value can decrease substantially during a specified time. A significant decrease in value...
- PermalockA security feature that makes the lock status of an area of memory permanent. If the area of memory is locked...
- permanent connectionA perpetual communication channel. Permanent connections are most often made via a dedicated circuit.
- Per-message secret numberA secret random number that is generated prior to the generation of each digital signature.
- PermissionAuthorization to perform some action on a system.
- PermissionedA system where every node, and every user must be granted permissions to utilize the system (generally...
- PermissionlessA system where all users’ permissions are equal and not set by any administrator or consortium.
- PermissionsAllowable user actions (e.g., read, write, execute).
- Permutation1. An ordered (re)arrangement of the elements of a (finite) set; a function that is both a one-to-one and...
- PersonAny person considered as an asset by the management domain.
- personaAn electronic identity that is unambiguously associated with a single person or non-person entity (NPE). A...
- Personal accountabilityA policy that requires that every person who accesses sensitive information be held accountable for his or...
- personal data1. Information that can be used to distinguish or trace an individual’s identity, either alone or when...
- Personal Digital Assistant (PDA)1. A handheld computer that serves as a tool for reading and conveying documents, electronic mail, and other...
- Personal Firewall1. A software application residing on a client device that increases device security by offering some...
- Personal Firewall ApplianceA device that performs functions similar to a personal firewall for a group of computers on a home network.
- personal identification number (PIN)1. A numeric secret that a cardholder memorizes and uses as part of authenticating their identity.
- personal identifier1. Information with the purpose of uniquely identifying a person within a given context.
- personal identity verification (PIV)A physical artifact (e.g., identity card, "smart" card) issued to a government individual that contains...
- personal identity verification (PIV) authorizationThe official management decision to authorize operation of a PIV Card Issuer after determining that the...
- personal identity verification (PIV) authorizing officialAn individual who can act on behalf of an agency to authorize the issuance of a credential to an applicant.
- Personal Identity Verification (PIV) Identity AccountThe logical record containing credentialing information for a given PIV cardholder. This is stored within the...
- Personal Information1. Any information relating to an identified or identifiable natural person (data subject).
- Personal Information Managementdata types such as contacts, calendar entries, tasks, notes, memos and email that may be synchronized from PC...
- Personal Information Management (PIM) Applications1. A core set of applications that provide the electronic equivalents of such items as an agenda, address...
- Personal Information Management (PIM) DataThe set of data types such as contacts, calendar entries, phonebook entries, notes, memos, and reminders...
- Personalization StringAn optional string of bits that is combined with a secret entropy input and (possibly) a nonce to produce a...
- personally identifiable information1. Information that can be used to distinguish or trace an individual’s identity - such as name, social...
- personally identifiable information processingAn operation or set of operations performed upon personally identifiable information that can include, but is...
- personally identifiable information processing permissionsThe requirements for how personally identifiable information can be processed or the conditions under which...
- personnel security1. The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of...
- Personnel-security compromiseThe accidental or intentional action of any person that reduces the security of the FCKMS and/or compromises...
- perturbation-based methodsPerturbation-based methods falsify the data before publication by introducing an element of error purposely...
- PFSAn option available during quick mode that causes a new shared secret to be created through a Diffie-Hellman...
- Pharming1. An attack in which an attacker causes the subscriber to be redirected to a fraudulent website, typically a...
- phaseThe position of a point in time (instant) on a waveform cycle. A complete cycle is defined as the interval...
- P_HASHA function that uses the HMAC-HASH as the core function in its construction. The specification of this...
- phenomenologiesPhysical phenomena such as radio frequencies, inertial sensors, and scene mapping, as well as diverse sources...
- PHI1. Individually identifiable health information: (1) Except as provided in paragraph (2) of this definition...
- phishing1. A technique for attempting to acquire sensitive data, such as bank account numbers, through a fraudulent...
- phishing resistanceThe ability of the authentication protocol to prevent the disclosure of authentication secrets and valid...
- physical access control system1. An automated system that manages the passage of people or assets through an opening(s) in a secure...
- physical authenticatorAn authenticator that the claimant proves possession of as part of an authentication process.
- Physical IdentifierA device identifier that is expressed physically by the device (e.g., printed onto a device’s housing...
- Physical non-deterministic random bit generatorAn entropy source that uses dedicated hardware or uses a physical experiment (noisy diode(s), oscillators...
- Physical partitioningThe hypervisor assigning separate physical resources to each guest OS.
- physical safeguardsPhysical measures, policies, and procedures to protect a covered entity's or business associate’s electronic...
- physically protected space (PPS)The space inside one physically protected perimeter. Separate spaces of equal protection may be considered to...
- Physical-security compromiseThe unauthorized access to sensitive data, hardware, and/or software by physical means.
- PI1. Information with the purpose of uniquely identifying a person within a given context.
- PIA1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and...
- PiB2^(50) bytes.
- PiconetA small Bluetooth network created on an ad hoc basis that includes two or more devices.
- Picture Archiving and Communication System, see PACS
- PII1. Personally Identifiable Information; Any representation of information that permits the identity of an...
- PII Confidentiality Impact LevelThe PII confidentiality impact level - low, moderate, or high - indicates the potential harm that could...
- PII ProcessingAn operation or set of operations performed upon PII that can include, but is not limited to, the collection...
- PIMdata types such as contacts, calendar entries, tasks, notes, memos and email that may be synchronized from PC...
- PIN1. A memorized secret typically consisting of only decimal digits.
- PIN Entry DeviceAn electronic device used in a debit, credit, or smart card-based transaction to accept and encrypt the...
- PIPServes as the retrieval source of attributes, or the data required for policy evaluation to provide the...
- PIV, see personal identity verification (PIV)
- PIV CardThe physical artifact (e.g., identity card, “smart” card) issued to an applicant by an issuer that contains...
- PIV Credential1. A credential that authoritatively binds an identity (and, optionally, additional attributes) to the...
- PIV Enrollment RecordA sequence of related enrollment data sets that is created and maintained by PIV Card issuers. The PIV...
- PIV Key TypeThe type of a key. The PIV Key Types are 1) PIV Authentication key, 2) Card Authentication key, 3) digital...
- PIV Visual Credential Authentication (VIS)An authentication mechanism where a human guard inspects the PIV Card and the person presenting it and makes...
- PivotThe act of an attacker moving from one compromised system to one or more other systems within the same or...
- PivotingA process where an attacker uses one compromised system to move to another system within an organization.
- Pixels Per Inch, see PPI
- P#jThe jth plaintext segment.
- PjThe jth plaintext block.
- PKC1. Encryption system that uses a public-private key pair for encryption and/or digital signature.
- PKE, see public key enabling (PKE)
- PKI1. The architecture, organization, techniques, practices, and procedures that collectively support the...
- PKI-Card Authentication (PKI-CAK)A PIV authentication mechanism that is implemented by an asymmetric key challenge/response protocol using the...
- PKI-PIV Authentication key (PKI-AUTH)A PIV Authentication mechanism that is implemented by an asymmetric key challenge/response protocol by using...
- PKI-PIV Authentication (PKI-AUTH)A PIV authentication mechanism that is implemented by an asymmetric key challenge/response protocol using the...
- plaintext1. Intelligible data that has meaning and can be understood without the application of cryptography.
- Plaintext dataIn this Recommendation, data that will be encrypted by an encryption algorithm or obtained from ciphertext...
- Plan CoordinatorA person responsible for all aspects of IT planning, including the TT&E element of maintaining the IT plans...
- Plan Of Action & Milestones3, see POA&M
- plan of action and milestones1. A tool that identifies tasks that need to be accomplished. It details resources required to accomplish the...
- Plan of Action and Milestones41. A document that identifies tasks needing to be accomplished. It details resources required to accomplish...
- Plan of Actions and Milestones1A document that identifies tasks needing to be accomplished. It details resources required to accomplish the...
- plantThe physical elements necessary to support the physical process. This can include many of the static...
- Platform1. A computer or hardware device and/or associated operating system, or a virtual environment, on which...
- Platform as a Service (PaaS)The capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or...
- platform IT (PIT)Information technology (IT), both hardware and software, that is physically part of, dedicated to, or...
- platform IT (PIT) systemA collection of PIT within an identified boundary under the control of a single authority and security...
- Platform TrustAn assurance in the integrity of the underlying platform configuration, including hardware, firmware, and...
- PLCA solid-state control system that has a user-programmable memory for storing instructions for the purpose of...
- PlenThe bit length of the payload.
- P*nThe last block of the plaintext, which may be a partial block.
- PnBlock of data representing Plaintext n
- PNT dataAll information used to form or disseminate PNT solutions, including signals, waveforms, and network packets.
- PNT solutionThe full solution provided by a PNT system or source, including time, position, and velocity. A PNT system or...
- PNT sourceA PNT system component that is used to produce a PNT solution. Examples include GNSS receivers, networked and...
- PNT systemThe components, processes, and parameters that collectively produce the final PNT solution for the consumer.
- POA&M1. A document that identifies tasks needing to be accomplished. It details resources required to accomplish...
- point at infinityIdentity element of a Montgomery curve or a curve in short-Weierstrass form.
- Point of Presence, see POP
- point orderSmallest non-zero multiple of a group element that results in the group’s identity element.
- point-to-point cross domain solution (CDS)A CDS purchased, implemented, and managed within the authorization boundary of the organization's own...
- poisoning attacksAdversarial attacks in which an adversary interferes with a model during its training stage, such as by...
- Poisson DistributionPoisson distributions model (some) discrete random variables. Typically, a Poisson random variable is a count...
- Policy1. The set of basic principles and associated guidelines, formulated and enforced by the governing body of an...
- policy administration pointProvides a user interface for creating, managing, testing, and debugging digital policies and metapolicies...
- policy based access control (PBAC)1. A form of access control that uses an authorization policy that is flexible in the types of evaluated...
- policy decision point1. Mechanism that examines requests to access resources, and compares them to the policy that applies to all...
- policy enforcement point1. Mechanism (e.g., access control mechanism of a file system or Web server) that actually protects (in terms...
- policy information pointServes as the retrieval source of attributes, or the data required for policy evaluation to provide the...
- POP1. A mailbox access protocol defined by IETF RFC 1939. POP is one of the most commonly used mailbox access...
- portThe entry or exit point from a computer for connecting communications or peripheral devices.
- port scanA technique that sends client requests to a range of service port addresses on a host.
- Port ScannerA program that can remotely determine which ports on a system are open (e.g., whether systems allow...
- port scanningUsing a program to remotely determine which ports on a system are open (e.g., whether systems allow...
- portable electronic device (PED)Electronic devices having the capability to store, record, and/or transmit text, images/video, or audio data...
- portable storage device1. A system component that can be inserted into and removed from a system and that is used to store...
- Portal VPNA single standard SSL connection to a Web site (the portal) that allows a remote user to securely access...
- positioning1. The ability to accurately and precisely determine one’s location and orientation two-dimensionally (or...
- positive control materialGeneric term referring to any material, system, or information (e.g. a sealed authenticator system or...
- positive control (security)Active form of security monitoring where an unexpected result generates an alarm. Note: The unexpected result...
- Post Office Protocol (POP)1. A mailbox access protocol defined by IETF RFC 1939. POP is one of the most commonly used mailbox access...
- Post-Market CapabilityA cybersecurity or privacy capability an organization selects, acquires, and deploys itself; any capability...
- post-processing invarianceA property of differential privacy. It says that the output of a differentially private mechanism remains...
- post-quantum algorithmA cryptographic algorithm that is believed to be secure, even against adversaries who possess a...
- potential impact1. The loss of confidentiality, integrity, or availability could be expected to have a limited adverse...
- potentially identifiable personal informationA new category of information proposed by Robert Gellman for information that has been de-identified but can...
- PPIAn opaque unguessable subscriber identifier generated by a CSP for use at a specific individual RP. This...
- PPS, see physically protected space (PPS)
- p,q ruleIt is assumed that out of publicly available information the contribution of one individual to the cell total...
- PRDevelop and implement the appropriate safeguards to ensure delivery of critical infrastructure services.
- PRAA privacy risk management sub-process for identifying and evaluating specific privacy risks.
- practitioner experienceA source of ISCM assessment elements based on the experience of individuals (practitioners) with experience...
- PRAM, see Privacy Risk Assessment Methodology (PRAM)
- Pre-activation state1. A lifecycle state of a key in which the key has been created, but is not yet authorized for use.
- precisionRefers to how closely individual PNT measurements agree with each other.
- precursor1. A sign that an attacker may be preparing to cause an incident. See indicator.
- Predictability1. Enabling reliable assumptions by individuals, owners, and operators about data and their processing by a...
- PredictorA function that predicts the next value in a sequence, based on previously observed values in the sequence.
- predisposing conditionA condition that exists within an organization, a mission/business process, enterprise architecture, or...
- Preimage1. A message Ms that produces a given message digest when it is processed by a hash function.
- Preimage resistance1. An expected property of a cryptographic hash function such that, given a randomly chosen message digest...
- Pre-Market CapabilityA cybersecurity or privacy capability built into an IoT device. Pre-market capabilities are integrated into...
- Prepare for Events1. An ISCM capability that ensures that procedures and resources are in place to respond to both routine and...
- prerequisiteA required input to an algorithm that has been established prior to the invocation of the algorithm.
- Presentation Attack Detection (PAD)1. Automated determination of a presentation attack. A subset of presentation attack determination methods...
- Presidential DirectiveA form of an executive order issued by the President of the United States with the advice and consent of the...
- pressure regulatorA device used to control the pressure of a gas or liquid.
- pressure sensorA sensor system that produces an electrical signal related to the pressure acting on it by its surrounding...
- pre-training1. In machine learning, a training step that trains a general-purpose model (sometimes called a foundation...
- PRF1. A function that can be used to generate output from a random seed and a data variable such that the output...
- PRF(s, x)A pseudorandom function with seed s and input data x.
- Primary facilityAn FCKMS facility that houses a primary system.
- primary services node (PRSN)A Key Management Infrastructure (KMI) core node that provides the users' central point of access to KMI...
- Primary systemAn FCKMS module that is currently active. Contrast with Backup (system).
- Prime number1. An integer greater than 1 that has no positive integer factors other than 1 and itself.
- Prime number generation seedA string of random bits that is used to begin a search for a prime number with the required characteristics.
- Primitive1. A low-level cryptographic algorithm that is used as a basic building block for higher-level cryptographic...
- Primitive algorithmA low-level cryptographic algorithm (e.g., an RSA encryption operation) used as a basic building block for...
- principal accrediting authority (PAA)Senior official with authority and responsibility for all intelligence systems within an agency.
- principal authorizing official (PAO)A senior (federal) official or executive with the authority to oversee and establish guidance for the...
- printerA device that converts digital data to human-readable text on a paper medium.
- privacy1. Assurance that the confidentiality of, and access to, certain information about an entity is protected.
- privacy architectIndividual, group, or organization responsible for ensuring that the system privacy requirements necessary to...
- privacy architectureAn embedded, integral part of the enterprise architecture that describes the structure and behavior for an...
- Privacy BreachThe loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence...
- privacy budgetAn upper bound on allowable cumulative privacy loss across all analyses that process a single dataset.
- Privacy Capability1. See capability.
- privacy compromiseIn the AML context, the unauthorized access of restricted or proprietary information that is part of an AI...
- Privacy Continuous MonitoringMaintaining ongoing awareness of privacy risks and assessing privacy controls at a frequency sufficient to...
- privacy continuous monitoring program1. An agency-wide program that implements the agency’s privacy continuous monitoring strategy and maintains...
- privacy continuous monitoring strategyFormal document that catalogs the available privacy controls implemented at an agency across the agency risk...
- privacy control1. The administrative, technical, and physical safeguards employed within an agency to ensure compliance with...
- privacy control assessment1. The assessment of privacy controls to determine whether the controls are implemented correctly, operating...
- Privacy Control Assessor1. The individual, group, or organization responsible for conducting a security or privacy control assessment.
- privacy control baseline1. A collection of controls specifically assembled or brought together by a group, organization, or community...
- privacy domainA domain that implements a privacy policy.
- Privacy engineeringA specialty discipline of systems engineering focused on achieving freedom from conditions that can create...
- Privacy Engineering Program, see PEP
- Privacy EventThe occurrence or potential occurrence of problematic data actions.
- privacy impact assessment (PIA)1. An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and...
- privacy informationInformation that describes the privacy posture of an information system or organization.
- privacy loss1. A measure of the extent to which a data release may reveal information that is specific to an individual.
- privacy loss budgetAn upper bound on the cumulative total privacy loss for individuals.
- privacy parameterA parameter of a differential privacy definition that partly or wholly determines privacy loss.
- privacy plan1. Formal document that provides an overview of the privacy requirements for an information system or program...
- privacy postureThe privacy posture represents the status of the information systems and information resources (e.g...
- privacy preserving data miningan [extension] of traditional data mining techniques to work with … data modified to mask sensitive...
- privacy preserving data publishingmethods and tools for publishing data in a more hostile environment, so that the published data remains...
- privacy program plan1. A formal document that provides an overview of an agency's privacy program, including a description of the...
- privacy requirement1. A requirement that applies to an information system or an organization that is derived from applicable...
- Privacy Requirements1. Requirements of an organization, information program, or system that are derived from applicable laws...
- Privacy RiskThe likelihood that individuals will experience problems resulting from data processing, and the impact...
- Privacy Risk AssessmentA privacy risk management sub-process for identifying and evaluating specific privacy risks.
- Privacy Risk Assessment Methodology (PRAM)The PRAM is a tool that applies the risk model from NISTIR 8062 and helps organizations analyze, assess, and...
- Privacy Risk ManagementA cross-organizational set of processes for identifying, assessing, and responding to privacy risks.
- privacy-utility tradeoffThe fundamental tension between privacy and accuracy. Adding more noise increases privacy but reduces...
- Private cloudThe cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple...
- private key1. The secret part of an asymmetric key pair that is typically used to digitally sign or decrypt data.
- Private Key Infrastructure, see PKI
- Private key/private signature keyA cryptographic key that is used with an asymmetric (public key) cryptographic algorithm and is associated...
- privilege1. A right that, when granted to an entity, permits the entity access and/or authorization to an otherwise...
- privilege certificate manager (PCM)The key management entity (KME) authorized to create the privilege certificate for another KME.
- privileged access account holderA user who is authorized (and therefore trusted) to perform security-relevant functions that ordinary users...
- privileged account1. An information system account with approved authorizations of a privileged user.
- privileged command1. A human-initiated command executed on an information system involving the control, monitoring, or...
- privileged network accountA network account with elevated privileges that is typically allocated to system administrators, network...
- privileged processA computer process that is authorized (and, therefore, trusted) to perform security- relevant functions that...
- privileged user1. A user that is authorized (and therefore, trusted) to have access to perform system control, monitoring...
- PrivKeyU, PrivKeyVPrivate key of party U or V, respectively.
- PRM, see performance reference model (PRM)
- PRNG1. A deterministic computational process that has one or more inputs called "seeds", and it outputs a...
- Probability Density Function (PDF)A function that provides the "local" probability distribution of a test statistic. From a finite sample size...
- Probability Distribution1. The assignment of a probability to the possible outcomes (realizations) of a random variable.
- Probability modelA mathematical representation of a random phenomenon.
- probability of occurrence1. A weighted factor based on a subjective analysis of the probability that a given threat is capable of...
- Probable primeAn integer that is believed to be prime based on a probabilistic primality test. There should be no more than...
- Probative DataInformation that reveals the truth of an allegation.
- probeA technique that attempts to access a system to learn something about the system.
- problemDifficulty, uncertainty, or otherwise realized and undesirable event, set of events, condition, or situation...
- Problematic Data Action1. A data action that could cause an adverse effect for individuals.
- process1. Set of interrelated or interacting activities that use inputs to deliver an intended result.
- process assistantAn individual who provides support for the proofing process but does not support decision-making or...
- process controllerA type of computer system, typically rack-mounted, that processes sensor input, executes control algorithms...
- process hijackingA process checkpoint and migration technique that uses dynamic program re- writing techniques to add a...
- Process Information, see PI
- process outcomeObservable result of the successful achievement of the process purpose.
- process purposeHigh-level objective of performing the process and the likely outcomes of effective implementation of the...
- process step1. A reference to one of the 6 steps in the ISCM process defined in NIST SP 800-137.
- processing1. An operation or set of operations performed on personal information that can include, but is not limited...
- product1. Result of a process.
- Product CategoryThe main product category of the IT product (e.g., firewall, IDS, operating system, web server).
- Product Component HostThe organization, individual, and/or system that hosts the product component. Product component hosts may...
- product cybersecurity capabilityCybersecurity features or functions that computing devices provide through their own technical means (i.e...
- Product OutputInformation produced by a product. This includes the product user interface, human-readable reports, and...
- product ownerPerson or organization responsible for the development, modification, operation, and/or final disposition of...
- product source node (PSN)The Key Management Infrastructure core node that provides central generation of cryptographic key material.
- profile1. A document that provides an implementation-independent specification of CKMS security requirements for use...
- Profile augmentationsThe properties or characteristics that are recommended, but not required, by this Profile for FCKMSs.
- Profile featuresThe properties or characteristics that could be used by FCKMSs, but are not required or recommended by this...
- Profile requirementsThe properties or characteristics that shall be exhibited in FCKMSs in order to conform to, or comply with...
- program managerNote: Examples of systems or devices are workstations, guards, firewalls, routers, web server, database...
- program metricsTools designed to facilitate decision-making and improve performance and accountability through the...
- programmable logic controllerA solid-state control system that has a user-programmable memory for storing instructions for the purpose of...
- projectEndeavor with defined start and finish criteria undertaken to create a product or service in accordance with...
- prompt extractionAn attack that tries to divulge the system prompt or other information in the context of a large language...
- prompt injectionAn attack which exploits the concatenation of untrusted input with a prompt constructed by a higher-trust...
- Proof of possession (POP)A verification process whereby assurance is obtained that the owner of a key pair actually has the private...
- Proof of stake consensus modelA consensus model where the blockchain network is secured by users locking an amount of cryptocurrency into...
- Proof of work consensus modelA consensus model where a publishing node wins the right to publish the next block by expending time, energy...
- proofing agentAn agent of the CSP who is trained to attend identity proofing sessions and can make limited risk-based...
- proper working stateA condition in which the device or system contains no compromised internal components or data fields (e.g...
- property inferenceA data privacy attack that infers a global property about the training data of a machine learning model.
- property valueInstance of a specific value together with an identifier for a data dictionary entry that defines a property.
- PROPIN, see proprietary information (PROPIN)
- proprietary information (PROPIN)Material and information relating to or associated with a company's products, business, or activities...
- proscribed informationInformation that is classified as top secret (TS) information; communications security (COMSEC) information...
- Prose ChecklistA checklist that provides a narrative descriptions of how a person can manually alter a product’s...
- Protect, see PR
- protect (CSF function)Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services.
- protected distribution system (PDS)Wireline or fiber-optic distribution system used to transmit unencrypted classified national security...
- Protected ModeAn operational mode found in x86-compatible processors with hardware support for memory protection, virtual...
- Protected Storage, see PS
- protecting applicationAn application that controls access to protected resources.
- protectionIn the context of systems security engineering, a control objective that applies across all types of asset...
- Protection BitsA mechanism commonly included in UNIX and UNIX-like systems that controls access based on bits specifying...
- protection needs1. Informal statement or expression of the stakeholder security requirements focused on protecting...
- protection philosophyInformal description of the overall design of a system delineating each of the protection mechanisms...
- protection profileA minimal, baseline set of requirements targeted at mitigating well defined and described threats. The term...
- protective packagingPackaging techniques for COMSEC material that discourage penetration, reveal a penetration has occurred or...
- protective technologiesSpecial tamper-evident features, materials, and items employed for the purpose of detecting, delaying, and...
- Protect-P (Function)Develop and implement appropriate data processing safeguards.
- protocol1. A set of rules (i.e., formats and procedures) to implement and control some type of association (e.g...
- protocol adapter (PA)A process that communicates with entities external to a system. Protocol adapters typically implement Open...
- protocol analyzer1. A device or software application that enables the user to analyze the performance of network data so as to...
- Provable primeAn integer that is either constructed to be prime or is demonstrated to be prime using a primality-proving...
- provenance1. The chronology of the origin, development, ownership, location, and changes to a system or system...
- Provider1. The entity (person or organization) that provides an appropriate agent, referred to as the “provider...
- provisional security impact valuesThe initial or conditional impact determinations made until all considerations are fully reviewed, analyzed...
- provisioningThe process of the network onboarding component providing onboarding credentials to an IoT device [in the...
- provisioning APIA protected API that allows an RP to access identity attributes for multiple subscribers for the purposes of...
- proxy agentA software application running on a firewall or on a dedicated proxy server that is capable of filtering a...
- proxy serverA server that services the requests of its clients by forwarding those requests to other servers.
- proxy validation and verificationUsing a non-critical system with comparable properties to a critical one as a testing substitute.
- PRSN, see primary services node (PRSN)
- PS1. The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of...
- ∇ψ2m(obs);∇2ψ2m(obs)A measure of how well the observed values match the expected value. See Sections 2.11 and 3.11.
- pseudonym1. A name assigned through a formal process by a federal department or agency to a federal employee for the...
- pseudonymization1. De-identification technique that replaces an identifier (or identifiers) for a data principal with a...
- Pseudorandom1. A process or data produced by a process is said to be pseudorandom when the outcome is deterministic yet...
- Pseudorandom function familyAn indexed family of (efficiently computable) functions, each defined for the same particular pair of input...
- Pseudorandom function (PRF)1. An indexed family of (efficiently computable) functions, each defined for the same input and output...
- Pseudorandom keyAs used in this Recommendation, a binary string that is taken from the output of a PRF.
- pseudorandom number generator1. An RBG that includes a DRBG mechanism and (at least initially) has access to a randomness source. The DRBG...
- PSK1. A single secret key used by IPsec endpoints to authenticate endpoints to each other.
- PSN, see product source node (PSN)
- PTT, see Push-To-Talk (PTT)
- PubKeyU, PubKeyVPublic key of party U or V, respectively.
- publicAny entity or person who might be impacted by or need to take action for a specific vulnerability; intended...
- Public and Private KeyPublic and private keys are two very large numbers that (through advanced mathematics) have a unique...
- Public CAA trusted third party that issues certificates as defined in IETF RFC 5280. A CA is considered public if its...
- public channel1. A communication channel between two parties. Such a channel can be observed and possibly also corrupted by...
- Public cloudThe cloud infrastructure is provisioned for open use by the general public. It may be owned, managed, and...
- public domain softwareSoftware not protected by copyright laws of any nation that may be freely used without permission of or...
- Public Information1. The term 'public information' means any information, regardless of form or format, that an agency...
- public key1. The public part of an asymmetric key pair that is typically used to verify signatures or encrypt data.
- public key certificate1. A digital document issued and digitally signed by the private key of a certification authority that binds...
- public key cryptography (PKC)1. Cryptography that uses two separate keys to exchange data - one to encrypt or digitally sign the data and...
- public key enabling (PKE)The incorporation of the use of certificates for security services such as authentication, confidentiality...
- public key infrastructure (PKI)1. A framework that is established to issue, maintain and revoke public key certificates.
- Public key/public signature verification keyA cryptographic key that is used with an asymmetric (public key) cryptographic algorithm and is associated...
- Public Reviewer1. A member of the general public who reviews a candidate checklist and sends comments to NIST.
- public seedA starting value for a pseudorandom number generator. The value produced by the random number generator may...
- public-key encryption schemeA set of three cryptographic algorithms (KeyGen, Encrypt, and Decrypt) that can be used by two parties to...
- Public-key validationThe procedure whereby the recipient of a public key checks that the key conforms to the arithmetic...
- Published Internet Protocol, see PIP
- Publishing node1. A node that, in addition to all responsibilities required of a full node, is tasked with extending the...
- purge1. A method of sanitization that applies physical or logical techniques to render target data recovery...
- purpose specification and use limitationA privacy principle (FIPP) that addresses an organization's notice to individuals regarding the specific...
- Push-To-Talk (PTT)A method of communicating on half-duplex communication lines, including two-way radio, using a...
- putative re-identificationsApparent re-identifications that may or may not be correct.
- P-value1. The probability (under the null hypothesis of randomness) that the chosen test statistic will assume...
370 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.