Cybersecurity terminology · MLC-0102
Cybersecurity terms: R (266)
- r1. An integer that is less than or equal to 32, whose value is the bit length of the agreed-upon binary...
- (r, s)Digital signature for DSA or ECDSA.
- RA1. The process of identifying risks to organizational operations (including mission, functions, image...
- RAdAC, see Risk Adaptive (Adaptable) Access Control
- RAGA type of GenAI system in which a model is paired with a separate information retrieval system (or ”knowledge...
- RANDFor the purposes of this Recommendation, a value in a set that has an equal probability of being selected...
- Random Binary SequenceA sequence of bits for which the probability of each bit being a “0” or “1” is ½. The value of each bit is...
- Random bit1. A bit for which an attacker has exactly a 50% probability of success of guessing the value of the bit as...
- Random Bit Generator (RBG)1. A device or algorithm that can produce a sequence of bits that appear to be both statistically independent...
- Random Excursion TestThe purpose of this test is to determine if the number of visits to a state within a random walk exceeds what...
- Random Excursion Variant TestThe purpose of this test is to detect deviations from the distribution of the number of visits of a random...
- Random FieldIn the RBG-based construction of IVs, either a direct random string or one of its successors.
- random forest classification, see RFC
- Random nonceA nonce containing a random-value component that is generated anew for each nonce.
- Random Number1. A value in a set of numbers that has an equal probability of being selected from the total population of...
- random number generator (RNG)1. A process that generates a random sequence of values (usually a sequence of bits) or an individual random...
- random oracle modelSee Read-Only Memory.
- Random Parameter, see RAND
- random samplingA method of sampling where each sample has an equal chance of selection in hopes of gathering an unbiased...
- Random valueA sufficient entropy bit string.
- Random VariableRandom variables differ from the usual deterministic variables (of science and engineering) in that random...
- Randomized hashing1. A technique for randomizing the input to a cryptographic hash function.
- Randomized messageA message that has been modified using a random value.
- Randomness extraction1. The first step in the two-step key-derivation procedure specified in this Recommendation; during this...
- Randomness Source1. A component of a DRBG (which consists of a DRBG mechanism and a randomness source) that outputs bitstrings...
- RangeThe maximum possible distance for communicating with a wireless network infrastructure or wireless client.
- Rank (of a matrix)Refers to the rank of a matrix in linear algebra over GF(2). Having reduced a matrix into row-echelon form...
- Rank TestThe purpose of this test is to check for linear dependence among fixed length substrings of the original...
- Rapid elasticityCapabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly...
- RARThe report which contains the results of performing a risk assessment or the formal output from the process...
- Rate1. The number of input bits processed or output bits generated per invocation of the underlying permutation.
- ratio scaleFrom the Stevens Scale of Measurement, a quantitative measurement scale with a true zero using variables that...
- Rationale1. The explanation for why a Reference Document Element and a Focal Document Element are related within a set...
- Raw dataDigitized output of the noise source.
- RbThe constant string for subkey generation for a cipher with block size b.
- RBACAccess control based on user roles (i.e., a collection of access authorizations a user receives based on an...
- RBGRandom Bit Generator
- RBG seed1. The input to a pseudorandom number generator. Different seeds generate different pseudorandom sequences.
- RCDevelop and implement the appropriate activities to maintain plans for resilience and to restore any...
- RDAll data concerning (i) design, manufacture, or utilization of atomic weapons; (ii) the production of special...
- RE, see Rapid elasticity
- ReaderA device that can wirelessly communicate with tags. Readers can detect the presence of tags as well as send...
- Reader SpoofingThe act of impersonating a legitimate reader of an RFID system to read tags.
- Reader Talks FirstAn RF transaction in which the reader transmits a signal that is received by tags in its vicinity. The tags...
- Read-Only Memory1. A pre-recorded ISM that can only be read from and not written to.
- Real ModeA legacy high-privilege operating mode in x86-compatible processors.
- real timePertaining to the performance of a computation during the actual time that the related physical process...
- real time reactionImmediate response to a penetration attempt that is detected and diagnosed in time to prevent access.
- reauthenticationThe process of confirming the subscriber’s continued presence and intent to be authenticated during an...
- ReceiverThe party that receives secret keying material via a key-transport transaction. Contrast with sender.
- Receiver Address, see RA
- receiver operating characteristicA curve that plots the true positive rate versus the false positive rate for a classifier.
- recipient1. A party that either (1) receives a public key; or (2) obtains assurance from an assurance provider (e.g...
- Recipient-usage period1. The period of time during which the protected information is processed (e.g., decrypted).
- Reciprocal AgreementAn agreement that allows two organizations to back up each other.
- reciprocity1. The mutual agreement among participating organizations to accept each other’s security assessments in...
- Recommendation1. A special publication of the ITL that stipulates specific characteristics of the technology to use or the...
- reconstitutionFollows recovery operations during contingency plan execution. Includes activities to return organizational...
- reconstruction attackA privacy attack that uses published statistics to reconstruct individual data points from the original...
- records1. The recordings (automated and/or manual) of evidence of activities performed or results achieved (e.g...
- Recover, see RC
- recover (CSF function)Develop and implement the appropriate activities to maintain plans for resilience and to restore any...
- recoveryRecovery is executing system contingency plan activities to restore organizational missions/business...
- recovery and reconstitution1. Actions taken during or after an incident or event to restore functions and capability to fully...
- Recovery Point ObjectiveThe point in time to which data must be recovered after an outage.
- recovery proceduresThe actions necessary to restore a system's computational capability and data files after a system failure.
- Recovery Time ObjectiveThe overall length of time an information system’s components can be in the recovery phase before negatively...
- REDInformation or messages that contain sensitive or classified information that is not encrypted.
- RED dataDate that is not protected by encryption.
- RED equipmentA term applied to equipment that processes unencrypted national security information that requires protection...
- RED keyKey that has not been encrypted in a system approved by NSA for key encryption or encrypted key in the...
- RED lineAn optical fiber or a metallic wire that carries a RED signal or that originates/terminates in a RED...
- RED optical fiber lineAn optical fiber that carries RED signal or that originates/terminates in RED equipment or system.
- RED signalAny electronic emission (e.g., plain text, key, key stream, subkey stream, initial fill, or control signal)...
- red teamA group of people authorized and organized to emulate a potential adversary's attack or exploitation...
- red team exercise1. An exercise, reflecting real-world conditions, that is conducted as a simulated adversarial attempt to...
- Red Team/Blue Team Approach1. A group of people authorized and organized to emulate a potential adversary’s attack or exploitation...
- red teamingIn the AI context, means a structured testing effort, often adopting adversarial methods, to find flaws and...
- RED wirelineA metallic wire that carries a RED signal or that originates/terminates in a RED equipment or system.
- redactionThe removal of information from a document or dataset for legal or security purposes.
- RED/BLACK conceptSeparation of electrical and electronic circuits, components, equipment, and systems that handle classified...
- redundant control serverA backup to the control server that maintains the current state of the control server at all times.
- RE(f), see risk executive (function)
- Reference1. Relationships between elements of two documents that are recorded in a NIST IR 8278A-compliant format and...
- Reference Architecture, see RA
- reference dataCryptographic material used in the performance of a cryptographic protocol, such as an authentication or a...
- Reference Document1. A document being compared to a Focal Document, such as traditional documents, products, services...
- Reference Document Element1. A discrete section, sentence, phrase, or other identifiable piece of content from a Reference Document.
- reference monitor1. The security engineering term for IT functionality that (1) controls all access, (2) cannot be by-passed...
- reference monitor conceptAn abstract model of the necessary and sufficient properties that must be achieved by any mechanism that...
- reference validation mechanismAn implementation of the reference monitor concept that validates each access to resources against a list of...
- Reference Version1. The version of the OLIR.
- registerA set of records (paper, electronic, or a combination) maintained by a Registration Authority containing...
- RegistrarAlso known as a Registration Agent, a person who performs the enrollment process.
- registration1. The process of making a person’s identity known to the PIV system, associating a unique identifier with...
- Registration agentAn FCKMS role that is responsible for registering new entities and perhaps other selected information.
- Registration authority (RA)1. A trusted entity that establishes and vouches for the identity and authorization of a certificate...
- Registry1. A service that allows developers to easily store images as they are created, tag and catalog images for...
- regrader1. A trusted process explicitly authorized to re-classify and re-label data in accordance with a defined...
- regression1. A statistical technique used to predict the value of a variable based on the relationship between...
- Regular ExpressionA sequence of characters (or words) that forms a search pattern, mainly for use in pattern matching with...
- re-identification1. A process by which information is attributed to de-identified data in order to identify the individual to...
- re-identification precisionThe ratio of correct re-identifications to the sum of correct and incorrect apparent re-identifications.
- re-identification probabilityThe probability that an individual’s identity will be correctly inferred by an outside party using...
- re-identification rateThe percentage of records in a dataset that can be re-identified.
- re-identification risk1. The likelihood that a third party can re-identify data subjects in a de-identified dataset.
- reinforcement learningA type of machine learning in which a model learns to optimize its behavior according to a reward function by...
- Rekey1. A procedure in which a new cryptographic key is generated in a manner that is independent of the (old)...
- re-key (a certificate)1. The process of creating a new certificate with a new validity period, serial number, and public key while...
- Relationship1. The type of logical comparison that the Reference Document Developer asserts compared to the Focal...
- Relationship ExplanationA text description of the nature of the relationship between a Reference Document Element and a Focal...
- Relationship IdentifierIdentifying information where the value is a relationship to another asset.
- Relationship PropertyIndicates whether the supporting concept is necessary for achieving the supported concept within a supportive...
- relationship styleAn explicitly defined convention for characterizing relationships for a use case.
- Relationship TypeThe type of supportive relationship being specified between a Reference Document Element and a Focal Document...
- relative errorThe absolute error divided by the unaltered query output.
- Relatively primeTwo positive integers are relatively prime if their greatest common divisor is 1.
- relay1. An electromechanical device that completes or interrupts an electrical circuit by physically moving...
- ReleaseA collection of new and/or changed configuration items which are tested and introduced into a production...
- release prefixPrefix appended to the short title of U.S.- produced keying material to indicate its foreign releasability...
- reliability1. The probability of performing a specified function without failure under given conditions for a specified...
- relying party1. An entity that relies on the validity of the binding of the Subscriber's name to a public key to verify or...
- remanenceResidual information remaining on storage media after clearing.
- remediation1. The act of mitigating a vulnerability or a threat.
- remote access1. Access to an organizational information system by a user (or an information system) communicating through...
- Remote Access ServerDevices, such as virtual private network gateways and modem servers, that facilitate connections between...
- remote diagnosticsDiagnostic activities conducted by individuals who are outside of an information system security perimeter.
- remote maintenanceMaintenance activities conducted by individuals communicating through an external network.
- Remote Procedure Call, see RPC
- remote rekeyingProcedure by which a distant crypto-equipment is rekeyed electrically.
- remote terminal unitA computer with radio interfacing used in remote situations where communications via wire is unavailable...
- removable mediaPortable data storage medium that can be added to or removed from a computing device or network. Note...
- removable media device1. A system component that can be inserted into and removed from a system and that is used to store...
- Removable User Identity Module (R-UIM)A card developed for cdmaOne/CDMA2000 handsets that extends the GSM SIM card to CDMA phones and networks.
- RepeatabilityThe ability to repeat an assessment in the future, in a manner that is consistent with, and hence comparable...
- ReplaceThe process of installing a new certificate and removing an existing one so that the new certificate is used...
- replay attack1. An attack in which the attacker is able to replay previously captured messages between a legitimate...
- replay resistance1. The property of an authentication process to resist replay attacks, typically by the use of an...
- reporterAny entity that reports a vulnerability to the Government and that may be an entity outside of the...
- ReportingThe final phase of the computer and network forensic process, which involves reporting the results of the...
- Representational State Transfer (REST)A software architectural style that defines a common method for defining APIs for Web services.
- Representative (of a key owner)See Sponsor (of a key).
- ReproducibilityThe ability of different experts to produce the same results from the same data.
- Request for CommentsA Request For Comments is a formal standards-track document developed in working groups within the Internet...
- Request for Comments (IETF standards document), see RFC
- Requester1. The entity requesting to perform an operation upon the object.
- requiredAs applied to an implementation specification (see implementation specification, above), indicating an...
- requirement1. Statement that translates or expresses a need and its associated constraints and conditions.
- requirements engineering1. An interdisciplinary function that mediates between the domains of the acquirer and supplier to establish...
- Réseaux IP Européens Network Coordination CentreRegional Internet Registry for Europe, the Middle East, and parts of Central Asia that allocates and...
- reserve keying materialKey held to satisfy unplanned needs.
- resident alienA citizen of a foreign nation, legally residing in the United States on a permanent basis, who is not yet a...
- residual risk1. Portion of risk remaining after security measures have been applied.
- residueData left in storage after information processing operations are complete, but before degaussing or...
- resilience1. The ability to prepare for and adapt to changing conditions and withstand and recover rapidly from...
- Resilience RequirementsThe business-driven availability and reliability characteristics for the manufacturing system that specify...
- resilient otherwise1. Security considerations applied to enable system operation despite disruption while not maintaining a...
- resolutionThe process of collecting information about an applicant to uniquely distinguish an individual within the...
- Resolvable Private Address, see RP
- ResolverSoftware that retrieves data associated with some identifier.
- resource1. An entity to be protected from unauthorized use.
- Resource allocationA mechanism for limiting how much of a host’s resources a given container can consume.
- resource consumer, see RC
- resource controlA capability in which an attacker controls one or more external resources consumed by a machine learning...
- resource negotiationBuilt-in data management capabilities that provide the necessary support functions, such as operations...
- Resource poolingThe provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with...
- resource provider, see RP
- Resource Public Key InfrastructureThe Resource Public Key Infrastructure is a framework aimed to secure the Internet’s routing infrastructure...
- Resource Server, see RS
- Respond, see RS
- respond (CSF function)Develop and implement the appropriate activities to take action regarding a detected cybersecurity event.
- responsibility to provideAn information distribution approach whereby relevant essential information is made readily available and...
- RESTA software architectural style that defines a common method for defining APIs for Web services.
- restorationThe process of changing the status of a suspended (i.e., temporarily invalid) certificate to valid.
- restricted authenticatorAn authenticator type, class, or instantiation that has additional risk of false acceptance associated with...
- restricted dataAll data concerning (i) design, manufacture, or utilization of atomic weapons; (ii) the production of special...
- Result contentPart or all of one or more SCAP result data streams.
- RESULTnBlock of data representing Plaintext n, if encryption state, or Ciphertext n, if decryption state
- resultsAll data acquired from using a questionnaire, such as the answers to individual questions and the final...
- Retention period1. The minimum amount of time that a key or other cryptographically related information should be retained in...
- retirementWithdrawal of active support by the operation and maintenance organization, partial or total replacement by a...
- retrieval-augmented generationA type of GenAI system in which a model is paired with a separate information retrieval system (or ”knowledge...
- reusabilityThe ability to use a system, system component, or data for a different purpose or to achieve a different goal...
- Reverse ChannelSee back channel
- Review Status1. The status of the checklist within the internal NCP review process. Possible status options are...
- Review TechniquesPassive information security testing techniques, generally conducted manually, that are used to evaluate...
- revocation1. The process of permanently ending the binding between a certificate and the identity asserted in the...
- Revoked key notification (RKN)A report (e.g., a list) of one or more keys that have been revoked and the date(s) of revocation, possibly...
- Reward system1. See Incentive Mechanism
- RF SubsystemThe portion of the RFID system that uses radio frequencies to perform identification and related...
- RFCA Request For Comments is a formal standards-track document developed in working groups within the Internet...
- rightmost (V, a)The rightmost a bits of V.
- RijndaelThe block cipher that NIST selected as the winner of the AES competition.
- RIPE NCCRegional Internet Registry for Europe, the Middle East, and parts of Central Asia that allocates and...
- risk1. A measure of the extent to which an entity is threatened by a potential circumstance or event, and...
- Risk Adaptive (Adaptable) Access Control1. In RAdAC, access privileges are granted based on a combination of a user’s identity, mission need, and the...
- risk aggregationThe combination of several risks into one risk to develop a more complete understanding of the overall risk.
- risk analysis1. The process of identifying risks to organizational operations (including mission, functions, image...
- Risk Appetite1. The types and amount of risk, on a broad level, [an organization] is willing to accept in its pursuit of...
- risk assessment1. A systematic examination of risk using disciplined processes, methods, and tools. A risk assessment...
- Risk Assessment MethodologyA risk assessment process, together with a risk model, assessment approach, and analysis approach.
- risk criteria1. Terms of reference against which the significance of a risk is evaluated, such as organizational...
- Risk Detail ReportA report listing detailed risk scenario information supporting the contents of a risk register entry...
- risk elevationThe process of transferring the decisions on risk response to a more senior stakeholder when the factors...
- risk escalationOccurs when a particular threshold is reached, either based on a time frame or some other risk condition...
- risk evaluation1. Process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or...
- risk executive (function)1. An individual or group within an organization that helps to ensure that: (i) security risk-related...
- risk factor1. A characteristic used in a risk model as an input for determining the level of risk in a risk assessment.
- risk framing1. Risk framing is the set of assumptions, constraints, risk tolerances, and priorities/trade-offs that shape...
- risk governanceThe process by which risk management evaluation, decisions, and actions are connected to enterprise strategy...
- risk identificationProcess of finding, recognizing, and describing risks.
- risk management1. The process of managing risks to organizational operations (including mission, functions, image, or...
- risk management framework (RMF)1. A disciplined and structured process that integrates information security, privacy, and risk management...
- risk management framework (RMF) data elementsA basic unit of information that has a unique meaning and subcategories (data items) of distinct value...
- Risk Management Framework (RMF) stepA reference to one of the 6 steps in the Risk Management Framework process defined in SP 800-37.
- risk management levelOne of three organizational levels defined in NIST SP 800-39: Level 1 (organizational level), Level 2...
- risk management strategyStrategy that addresses how organizations intend to assess risk, respond to risk, and monitor risk - making...
- risk mitigation1. Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures...
- risk mitigation plan (RMP)A plan that describes the risks to a mission arising from an asset's operational factors and the decisions...
- risk modelA key component of a risk assessment methodology (in addition to assessment approach and analysis approach)...
- risk optimizationA risk-related process to minimize negative and maximize positive consequences and their respective...
- Risk ProfileA prioritized inventory of the most significant risks identified and assessed through the risk assessment...
- Risk Register1. A repository of risk information including the data understood about risks over time.
- Risk ReserveA types of management reserve where funding or labor hours are set aside and employed if a risk is triggered...
- risk response1. Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations...
- Risk Response MeasureA specific action taken to respond to an identified risk.
- risk response planA summary of potential consequence(s) of the successful exploitation of a specific vulnerability or...
- risk tolerance1. The level of risk an entity is willing to assume in order to achieve a potential desired result.
- risk treatmentProcess to modify risk.
- Rivest-Shamir-Adleman1. For the purposes of this specification, RSA is a public-key signature algorithm specified by PKCS #1. As a...
- RMF1. A disciplined and structured process that integrates information security and risk management activities...
- RNG, see random number generator (RNG)
- RNG seedA seed that is used to initialize a deterministic random bit generator. Also called an RBG seed.
- ROAA Route Origin Attestation is a cryptographically verifiable attestation that a given Internet prefix can be...
- robustness1. The ability of a CS entity to operate correctly and reliably across a wide range of operational...
- ROCA curve that plots the true positive rate versus the false positive rate for a classifier.
- ROE, see Rules of Engagement (ROE)
- Rogue DeviceAn unauthorized node on a network.
- role1. Predefined set of rules establishing the allowed interactions between a user and a system.
- role-based access control (RBAC)1. Access control based on user roles (i.e., a collection of access authorizations a user receives based on...
- Role-based authenticationA process that provides assurance of an entity’s role by means of an authentication mechanism that verifies...
- role-based trainingA multi-step process in the learning program that begins with defining the significant cybersecurity or...
- RollupA scheme that enables the off-chain processing of transactions by one or more operators with on-chain state...
- ROM1. ROM is a pre-recorded storage medium that can only be read from and not written to.
- Root Cause AnalysisA principle-based, systems approach for the identification of underlying causes associated with a particular...
- Root CertificateA self-signed certificate, as defined by IETF RFC 5280, issued by a root CA. A root certificate is typically...
- Root Certificate Authority (CA)1. In a hierarchical public key infrastructure (PKI), the certification authority (CA) whose public key...
- Root of Trust for Reporting, see RTR
- Root of Trust for Update, see RTU
- root user1. A user who is authorized (and, therefore, trusted) to perform security-relevant functions that ordinary...
- rootkit1. A set of tools used by an attacker after gaining root-level access to a host to conceal the attacker's...
- roots of trust1. A starting point that is implicitly trusted.
- RoTA starting point that is implicitly trusted.
- RotateThe process of renewing a certificate in conjunction with a rekey, followed by the process of replacing the...
- ROTs, see roots of trust
- Rough Order of MagnitudeSee Read-Only Memory.
- RoundA sequence of transformations of the state that is iterated Nr times in the specifications of CIPHER()...
- Round keyOne of the Nr+1 arrays of four words that are derived from the block cipher key using the key expansion...
- Round robin consensus modelA consensus model for permissioned blockchain networks where nodes are pseudo-randomly selected to create...
- Route Origin AttestationA Route Origin Attestation is a cryptographically verifiable attestation that a given Internet prefix can be...
- Route Origin Authorization, see ROA
- router1. A computer that is a gateway between two networks at OSI layer 3 and that relays and directs data packets...
- rowhammer attackA software-based fault-injection attack that exploits dynamic random-access memory disturbance errors via...
- RP1. An entity that relies upon the subscriber’s authenticator(s) and credentials or a verifier’s assertion of...
- RP subscriber accountAn account established and managed by the RP in a federated system based on the RP’s view of the subscriber...
- RPC1. An entity that relies upon the subscriber’s authenticator(s) and credentials or a verifier’s assertion of...
- RPKIThe Resource Public Key Infrastructure is a framework aimed to secure the Internet’s routing infrastructure...
- RPKI Validation CacheRPKI Validation Cache provides Validated ROA Payload (VRP) and public router keys.
- RPOThe point in time to which data must be recovered after an outage.
- RSDevelop and implement the appropriate activities to take action regarding a detected cybersecurity event.
- RSA1. For the purposes of this specification, RSA is a public-key signature algorithm specified by PKCS #1. As a...
- RT, see runtime
- RTFAn RF transaction in which the reader transmits a signal that is received by tags in its vicinity. The tags...
- RTOThe overall length of time an information system’s components can be in the recovery phase before negatively...
- RTR1. A computer that is a gateway between two networks at OSI layer 3 and that relays and directs data packets...
- RTU1. A computer with radio interfacing used in remote situations where communications via wire is unavailable...
- RuleAn element that holds check references and may also hold remediation information.
- Rule-Based Event CorrelationCorrelating events by matching multiple log entries from a single source or multiple sources based on logged...
- Rules of Engagement (ROE)Detailed guidelines and constraints regarding the execution of information security testing. The ROE is...
- ruleset1. A table of instructions used by a controlled interface to determine what data is allowable and how the...
- RunAn uninterrupted sequence of like bits (i.e., either all zeroes or all ones).
- Run (of output sequences)A sequence of identical values.
- Runs TestThe purpose of the runs test is to determine whether the number of runs of ones and zeros of various lengths...
- runtimeThe period during which a computer program is executing.
- rvThe random value that is combined with the message Ms to produce the randomized message M.
- rv[0…b]For bit string rv, rv[0…b] is a substring consisting of the leftmost b+1 bit(s) of rv, where b ≥ 0.
- RVCRPKI Validation Cache provides Validated ROA Payload (VRP) and public router keys.
- rv_length_indicatorA 16-bit binary representation of the length (in bits) of rv.
266 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.