Cybersecurity terminology · MLC-0102
Cybersecurity terms: S (553)
- s1. The standard deviation of a random variable =Öò(x-m)2f ( x )dx.
- s2The variance of a random variable = (standard deviation)2.
- SA1. Individual responsible for the installation and maintenance of an information system, providing effective...
- SaaS, see Software as a Service (SaaS)
- SAD, see Security Association Database (SAD)
- Safe HarborWithin the context of de-identification, refers to the Safe Harbor method for de-identifying protected health...
- safeguards1. Actions, devices, procedures, techniques, or other measures that reduce the vulnerability of an...
- safety1. Expectation that a system does not, under defined conditions, lead to a state in which human life, health...
- safety critical systemA system whose failure, malfunction, design flaw, or manufacturing flaw may result in one (or more) of the...
- safety instrumented systemA system that is composed of sensors, logic solvers, and final control elements whose purpose is to take the...
- Safety RequirementsAC properties, business requirements, specifications of expected/unexpected system security features, or...
- SAISO1. Official responsible for carrying out the Chief Information Officer responsibilities under FISMA and...
- salt1. As used in this Recommendation, a byte string (which may be secret or non-secret) that is used as a MAC...
- SAML, see security assertion markup language (SAML)
- SampleAn observation of the raw data output by a noise source. Common examples of output values obtained by...
- samplingThe process of taking samples of something for the purpose of analysis.
- SANA field in an X.509 certificate that identifies one or more fully qualified domain names, IP addresses, email...
- Sandbox1. A system that allows an untrusted application to run in a highly controlled environment where the...
- sanitization1. Actions taken to render data written on media unrecoverable by ordinary and - for some forms of...
- sanitization methodActions that can be taken to sanitize media, such as clear, purge, and destroy.
- sanitization techniqueA technology-specific approach associated with a sanitization method that can be used to sanitize a specific...
- sanitize1. The removal of extraneous or potentially harmful data (e.g., malware) within a file or other information...
- SAOSenior Authorizing Official; A senior organization official that has budgetary control, provides oversight...
- SAOP1. The senior official designated by the head of each agency who has agency-wide responsibility for privacy...
- SAORM, see senior accountable official for risk management
- SAPA program established for a specific class of classified information that imposes safeguarding and access...
- SAPF, see special access program facility
- SAR, see security assessment report (SAR)
- satelliteBus and payload combined into one operational asset.
- SatisfactionFreedom from discomfort, and positive attitudes towards the use of the product.
- SBOMA formal record containing the details and supply chain relationships of various components used in building...
- S-boxA non-linear substitution table used in SUBBYTES() and KEYEXPANSION() to perform a one-to-one substitution of...
- SC1. The process of determining the security category for information or an information system. Security...
- SC 37The Biometrics standardization subcommittee under ISO/IEC Joint Technical Committee
- SCA1. The individual, group, or organization responsible for conducting a security control assessment.
- SCADAA generic name for a computerized system that is capable of gathering and processing data and applying...
- SCADA serverThe device that acts as the master in a SCADA system.
- SCADSA generic name for a computerized system that is capable of gathering and processing data and applying...
- ScalabilityThe ability to support more users, concurrent sessions, and throughput than a single SSL VPN device can...
- Scalability testingTesting the ability of a system to handle an increasing amount of work correctly.
- scanningSending packets or requests to another system to gain information to be used in a subsequent attack.
- SCAP, see security content automation protocol (SCAP)
- SCAP CapabilityA specific function or functions of a product as defined below: Authenticated Configuration Scanner: the...
- SCAP component1. A logical unit of data expressed using one or more of the SCAP component specifications.
- SCAP conformantA product or SCAP data stream that meets the requirements of this specification.
- SCAP contentPart or all of one or more SCAP data streams.
- SCAP Content ChecklistAn automated checklist that adheres to the SCAP specification in NIST SP 800-126 for documenting security...
- SCAP data streamA specific instantiation of SCAP content.
- SCAP data stream collectionA container for SCAP data streams and components.
- SCAP result data stream1. An SCAP data stream that holds output (result) content.
- SCAP RevisionA version of the SCAP specification designated by a revision number in the format nn.nn.nn, where the first...
- SCAP source data stream1. An SCAP data stream that holds input (source) content.
- SCAP source data stream collectionA container for SCAP data streams and components.
- SCAP use caseA pre-defined way in which a product can use SCAP. See Section 5 for the definitions of the SCAP use cases.
- ScatternetA chain of piconets created by allowing one or more Bluetooth devices to each be a slave in one piconet and...
- scavengingSearching through object residue to acquire data.
- ScenarioA sequential, narrative account of a hypothetical incident that provides the catalyst for the exercise and is...
- Scenario TestScenario testing is intended to mimic an operational application and simultaneously institute controls on the...
- SCEPA protocol defined in an IETF internet draft specification that is used by numerous manufacturers of network...
- scheduled data transferA connection used to transfer data on a regular, recurring basis.
- schemaAn object's defined organization and structure, including the syntax, semantics, and metadata about each...
- Scheme1. Set of rules and procedures that describes the objects of conformity assessment, identifies the specified...
- Scheme Owner1. Person or organization responsible for the development and maintenance of a conformity assessment system...
- SCIClassified information concerning or derived from intelligence sources, methods, or analytical processes...
- SCIF, see sensitive compartmented information facility (SCIF)
- scoping considerations1. A part of tailoring guidance providing organizations with specific considerations on the applicability and...
- ScriptA sequence of instructions, ranging from a simple list of operating system commands to full-blown programming...
- Scripting LanguageA definition of the syntax and semantics for writing and interpreting scripts.
- SCRMthe implementation of processes, tools or techniques to minimize the adverse impact of attacks that allow the...
- SCSIA magnetic media interface specification. Small Computer System Interface.
- SDC, see statistical disclosure control
- SDLThe set of methods to reduce the risk of disclosing information on individuals, businesses or other...
- SDLCA formal or informal methodology for designing, creating, and maintaining software (including code built into...
- SDOany organization that develops and approves standards using various methods to establish consensus among its...
- SDoCDeclaration where the conformity assessment activity is performed by the person or organization that provides...
- seal of approvalA single label indicating a product has met a baseline standard.
- SEC1. A condition that results from the establishment and maintenance of protective measures that enable an...
- SecDOP, see security design order of precedence
- Second byte of a two-byte status wordSecond byte of a two-byte status word
- Second preimage1. A message Ms’, that is different from a given message Ms , such that its message digest is the same as the...
- Second preimage resistance1. An expected property of a cryptographic hash function whereby it is computationally infeasible to find a...
- Secondary marketAn unofficial, unauthorized, or unintended distribution channel.
- secret key1. A single cryptographic key that is used with a symmetric-key algorithm; also called a secret key. A...
- Secret key informationThe key information that needs to be kept secret (i.e., symmetric keys, private keys, key shares and secret...
- Secret keying material1. The binary data that is used to form secret keys, such as AES encryption or HMAC keys.
- SectorThe smallest unit that can be accessed on media.
- secure1. To reduce the risks of intrusions and attacks as well as the effects of natural or manmade disasters on...
- secure association key (SAK)The secret key used by a MACsec Secure Association (SA).
- Secure channel1. A MACsec security relationship used to provide security guarantees for frames transmitted from one member...
- secure communicationsTelecommunications deriving security through use of National Security Agency (NSA)-approved products and/or...
- secure communications interoperability protocol (SCIP) productNational Security Agency (NSA) certified secure voice and data encryption devices that provide...
- Secure Digital eXtended Capacity (SDXC)Supports cards up to 2 TB, compared to a limit of 32 GB for SDHC cards in the SD 2.0 specification.
- Secure Hash Algorithm1. A hash algorithm with the property that it is computationally infeasible 1) to find a message that...
- Secure Hash Algorithm 2561. A hash algorithm that can be used to generate digests of messages. The digests are used to detect whether...
- Secure Hash Algorithm 3Secure Hash Algorithm-3.
- Secure Messaging Key Authentication (SM-AUTH)An authentication mechanism where the secure messaging key and associated certificate are used for...
- Secure Multipurpose Internet Mail Extensions (S/MIME)1. A set of specifications for securing electronic mail. S/MIME is based upon the widely used MIME standard...
- Secure Partition, see SP
- Secure Simple Pairing, see SSP
- Secure Sockets Layer (SSL)1. An authentication and security protocol that is widely implemented in browsers and web servers. TLS...
- secure stateState in which the system's data are consistent and the system continues correct enforcement of security and...
- Secure TransportTransfer of information using a transport layer protocol that provides security between applications...
- securely resilientThe ability of a system to preserve a secure state despite disruption, to include the system transitions...
- security1. A condition that results from the establishment and maintenance of protective measures that enable an...
- security architectIndividual, group, or organization responsible for ensuring that the information security requirements...
- security architecture1. Fundamental concepts or properties related to a system in its environment embodied in its elements...
- security assertion markup language (SAML)1. A protocol consisting of XML-based request and response message formats for exchanging security...
- security assessment1. The testing and/or evaluation of the management, operational, and technical security controls in an...
- Security Assessment and Authorization, see CA
- security assessment report (SAR)Provides a disciplined and structured approach for documenting the findings of the assessor and the...
- Security Association Database (SAD)A list or table of all IPsec SAs, including those that are still being negotiated.
- Security Association (SA)1. A relationship established between two or more entities to enable them to protect data they exchange.
- security attribute1. An abstraction representing the basic properties or characteristics of an entity with respect to...
- security audit1. Independent review and examination of records and activities to assess the adequacy of system controls, to...
- Security Audit Trail1. A set of records that collectively provide documentary evidence of processing used to aid in tracing from...
- security auditorA trusted role that is responsible for auditing the security of certification authority systems (CASs) and...
- Security Authorization1. The official management decision of the Designated Authorizing Official to permit operation of an issuer...
- Security Authorization Boundary1. All components of an information system to be authorized for operation by an authorizing official and...
- security authorization package1. Documents the results of the security control assessment and provides the authorizing official with...
- security authorization (to operate)1. The official management decision given by a senior organizational official to authorize operation of an...
- Security Automation DomainAn information security area that includes a grouping of tools, technologies, and data.
- security banner1. A persistent visible window on a computer monitor that displays the highest level of data accessible...
- Security boundaryA conceptual boundary that is used to assess the amount of entropy provided by the values output from an...
- Security Capability1. See capability.
- security categorization1. The process of determining the security category for information or an information system. Security...
- security category1. The characterization of information or an information system based on an assessment of the potential...
- security concept of operations (Security CONOP)1. A security-focused description of an information system, its operational policies, classes of users...
- security configuration management (SecCM)The management and control of configurations for an information system to enable security and facilitate the...
- security content automation protocol (SCAP)1. A suite of specifications that standardize the format and nomenclature by which software flaw and security...
- security control1. A safeguard or countermeasure prescribed for an information system or an organization designed to protect...
- security control and privacy control1. The means of managing risk, including policies, procedures, guidelines, practices, or organizational...
- security control assessment1. An evidence-based evaluation and judgement on the nature, characteristics, quality, effectiveness, intent...
- security control baseline1. The set of minimum security controls defined for a low-impact, moderate-impact, or high-impact information...
- Security Control EffectivenessThe measure of correctness of implementation (i.e., how consistently the control implementation complies with...
- security control extensionA statement, used in security control overlays, that extends the basic capability of a security control by...
- security control inheritance1. A situation in which an information system or application receives protection from security controls (or...
- Security Control Item1. See Security Control Item.
- security control providerAn organizational official responsible for the development, implementation, assessment, and monitoring of...
- security controls1. Actions, devices, procedures, techniques, or other measures that reduce the vulnerability of an...
- security criteriaCriteria related to a supplier’s ability to conform to security-relevant laws, directives, regulations...
- security design order of precedenceA design approach for minimizing the design basis for loss potential and using architectural features to...
- Security Development Lifecycle, see SDL
- security domain1. A domain operating at a single security level (which includes a unique combination of classification...
- security engineering1. An interdisciplinary approach and means to enable the realization of secure systems. It focuses on...
- Security Event Management SoftwareSoftware that imports security event information from multiple data sources, normalizes the data, and...
- Security Executive AgentIndividual responsible for the development, implementation, and oversight of effective, efficient, and...
- security fault analysis (SFA)An assessment usually performed on information system hardware, to determine the security properties of a...
- Security Fault Injection TestInvolves data perturbation (i.e., alteration of the type of data the execution environment components pass to...
- Security Features Users GuideGuide or manual explaining how the security mechanisms in a specific system work.
- security filterA secure subsystem of an information system that enforces security policy on the data passing through it.
- security function1. The capability provided by the system or a system element. The capability may be expressed generally as a...
- security functionality1. The security-related features, functions, mechanisms, services, procedures, and architectures implemented...
- security functions1. The hardware, software, or firmware of the system responsible for enforcing the system security policy and...
- security impact analysis1. The analysis conducted by an organizational official to determine the extent to which a change to an...
- security incident1. An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality...
- Security Industry Association, see SIA
- security informationInformation within the system that can potentially impact the operation of security functions or the...
- Security Information and Event ManagementA program that provides centralized logging capabilities for a variety of log types.
- Security Information and Event Management (SIEM) ToolApplication that provides the ability to gather security data from information system components and present...
- Security Information Management, see SIM
- security kernelHardware, firmware, and software elements of a trusted computing base implementing the reference monitor...
- security label1. A piece of information that represents the security level of an object.
- security levelIncludes the combination of classification level, releasability, and dissemination controls (e.g., sensitive...
- Security life of dataThe time period during which the security of the data needs to be protected (e.g., its confidentiality...
- Security Management DashboardA tool that consolidates and communicates information relevant to the organizational security posture in near...
- security marking1. The means used to associate a set of security attributes with objects in a human-readable form, to enable...
- security mechanism1. A device or function designed to provide one or more security services usually rated in terms of strength...
- Security Object, see SO
- security objectiveConfidentiality, integrity, or availability.
- security or privacy-relevant changeAny change to a system's configuration, environment, information content, functionality, or users which has...
- Security Parameters Index (SPI)1. Arbitrarily chosen value that acts as a unique identifier for an IPsec connection.
- security perimeter1. A physical or logical boundary that is defined for a system, domain, or enclave; within which a particular...
- security plan1. See System Security Plan.
- security policy1. The set of laws, rules, and practices that regulate how an organization manages, protects, and distributes...
- Security Policy Database (SPD)A prioritized list of all IPsec policies.
- security policy filter1. A hardware and/or software component that performs one or more of the following functions: (i) content...
- security posture1. The security status of an enterprise's networks, information, and systems based on CS resources (e.g...
- Security properties1. The security features (e.g., replay protection, or key confirmation) that a cryptographic scheme may, or...
- security protocolAn abstract or concrete protocol that performs security-related functions.
- security rangeHighest and lowest security levels that are permitted in or on an information system, system component...
- security relevance1. The functions or constraints that are relied upon to directly or indirectly meet protection needs.
- security requirement1. A requirement levied on an information system or an organization that is derived from applicable laws...
- security requirements baselineDescription of the minimum requirements necessary for an information system to maintain an acceptable level...
- security requirements guide (SRG)Compilation of control correlation identifiers (CCIs) grouped in more applicable, specific technology areas...
- security requirements traceability matrix (SRTM)Matrix documenting the system's agreed upon security requirements derived from all sources, the security...
- security risk1. The effect of uncertainty on objectives pertaining to asset loss and the associated consequences.
- security safeguardsProtective measures and controls prescribed to meet the security requirements specified for an information...
- security service1. A capability that supports one, or many, of the security goals. Examples of security services are key...
- security solution1. The key design, architectural, and implementation choices made by organizations to satisfy specified...
- security specification1. An assessment object that includes document-based artifacts (e.g., policies, procedures, plans, system...
- Security Status1. The security status of an enterprise’s networks, information, and systems based on information security...
- security strength1. A number associated with the amount of work (i.e., the number of operations) that is required to break a...
- security targetImplementation-dependent statement of security needs for a specific identified target of evaluation (TOE).
- security technical implementation guide (STIG)Based on Department of Defense (DoD) policy and security controls. Implementation guide geared to a specific...
- security test and evaluation (ST&E)Examination and analysis of the safeguards required to protect an information system, as they have been...
- Security testingTesting that attempts to verify that an implementation protects data and maintains functionality as intended.
- Security-Oriented Code ReviewA code review, or audit, investigates the coding practices used in the application. The main objective of...
- security-relevant event1. An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the...
- security-relevant information1. Information within the system that can potentially impact the operation of security functions or the...
- SED, see self-encrypting devices (SED)
- SEED1. An optional ECC domain parameter; an initialization value that is used during domain parameter generation...
- Seed PeriodThe period of time between instantiating or reseeding a DRBG with one seed and reseeding that DRBG with...
- SeedlifeThe length of the seed period.
- segmentIn the CFB mode, a sequence of bits whose length is a parameter that does not exceed the block size.
- select (V, a, b)A substring of string V consisting of bit a through bit b.
- selection operation1. See assignment operation and organization-defined parameter.
- selection statementA control parameter that allows an organization to select a value from a list of pre-defined values provided...
- Self testingTesting within a system, device or process during normal operation to detect misbehavior.
- Self-dual KeyA key with the property that when you encrypt twice with this key, the result is the initial input.
- self-encrypting devices (SED)A data storage device featuring always-on encryption that substantially reduces the likelihood that...
- self-protectionThe protection provided by an entity to ensure its own correct behavior and function despite adversity.
- Self-signed certificate1. A public-key certificate whose digital signature may be verified by the public key contained within the...
- self-supervised learningA type of machine learning that relies on generating implicit labels from unstructured data rather than...
- Semantic matchinguses contextual attributes of the digital object to interpret the artifact in a manner that more closely...
- semantic securityWhat can be efficiently computed about some plaintexts from their ciphertexts can be computed, just as...
- SemanticsThe intended meaning of acceptable sentences of a language.
- Semantics of a languageThe meanings of all the language's acceptable sentences.
- Semi-Active TagA tag that uses a battery to communicate but remains dormant until a reader sends an energizing signal...
- semiblockGiven a block cipher, a bit string whose length is half of the block size.
- semiblock stringFor a given block size, a string that can be represented as the concatenation of semiblocks.
- Semi-Passive TagA passive tag that uses a battery to power on-board circuitry or sensors but not to produce back channel...
- Semi-Qualitative Risk AnalysisA method for risk analysis with qualitative categories assigned numeric values to allow for the calculation...
- Semi-Quantitative Assessment1. The use of a set of methods, principles, or rules for assessing risk based on bins, scales, or...
- semi-supervised learningA type of machine learning in which a small number of training samples are labeled, while the majority are...
- Sender1. The party that sends secret keying material to the receiver in a key-transport transaction. Contrast with...
- senior accountable official for risk managementThe senior official, designated by the head of each agency, who has vision into all areas of the organization...
- senior agency information security officer (SAISO)1. Official responsible for carrying out the Chief Information Officer responsibilities under FISMA and...
- senior agency official for privacy1. A senior official designated by the head of each agency to have agency-wide responsibilities for privacy...
- senior information security officer (SISO)1. Official responsible for carrying out the Chief Information Officer responsibilities under FISMA and...
- Sensing CapabilityThe ability to provide an observation of an aspect of the physical world in the form of measurement data.
- SensitiveA descriptor of information whose loss, misuse, or unauthorized access or modification could adversely affect...
- sensitive compartmented information facility (SCIF)An area, room, group of rooms, buildings, or installation certified and accredited as meeting Director of...
- sensitive compartmented information (SCI)1. A subset of Classified National Intelligence concerning or derived from intelligence sources, methods, or...
- sensitive information1. Information where the loss, misuse, or unauthorized access or modification could adversely affect the...
- Sensitive Security Parameter, see SSP
- sensitivity1. A form of bias that results from failures in the heuristics humans use to make decisions.
- sensor1. An intrusion detection and prevention system component that monitors and analyzes network activity and may...
- Sentences, formalThe entire set of sentences that can be created or recognized as being valid using the formal syntax...
- Separation of ConcernsA design principle for breaking down an application into modules, layers, and encapsulations, the roles of...
- Separation of Duty (SOD)1. refers to the principle that no user should be given enough privileges to misuse the system on their own...
- Sequence1. An ordered set of quantities.
- Serial Peripheral Interface, see SPI
- Serial TestThe purpose of this test is to determine whether the number of occurrences of m-bit overlapping patterns is...
- Server1. A system entity that provides a service in response to requests from clients.
- service1. A software component participating in a service-oriented architecture that provides functionality or...
- service authority1. See service authority.
- Service CompositionAggregation of multiple small services into larger services.
- Service DescriptionA set of documents that describe the interface to and semantics of a service.
- Service InterfaceThe abstract boundary that a service exposes. It defines the types of messages and the message exchange...
- service level agreement (SLA)1. Defines the specific responsibilities of the service provider and sets the customer expectations.
- service of common concernA service deemed to be more efficiently or effectively accomplished in a consolidated manner that is...
- Service Processor, see SP
- Service Provider1. A provider of basic services or value-added services for operation of a network; generally refers to...
- Service-Oriented Architecture (SOA)1. A collection of services. These services communicate with each other. The communication can involve either...
- Session1. A persistent interaction between a subscriber and an endpoint, either an RP or a CSP. A session begins...
- set pointAn input variable that sets the desired value of the controlled variable. This variable may be manually set...
- set theory relationship mapping1. A concept relationship style derived from the branch of mathematics known as set theory.
- Setting the barSetting the bar means that a decision must be made as to the complexity of the material that will be...
- SFA characteristic of an authentication system or an authenticator that requires only one authentication factor...
- SFA, see security fault analysis (SFA)
- SFUG, see Security Features Users Guide
- SHA1. A hash algorithm with the property that it is computationally infeasible 1) to find a message that...
- SHA-11. A hash algorithm with the property that it is computationally infeasible 1) to find a message that...
- SHA-2A hash algorithm with the property that it is computationally infeasible 1) to find a message that...
- SHA-2561. A hash algorithm that can be used to generate digests of messages. The digests are used to detect whether...
- SHA-256/192(M)T192(SHA-256(M)), the most significant (i.e., leftmost) 192 bits of the SHA-256 hash of M.
- SHA-256(M)SHA-256 hash function as specified in [3].
- SHA-3Secure Hash Algorithm-3.
- shadow modelA model that imitates the behavior of the target model. The training datasets and the truth about membership...
- Shadow StackA parallel hardware stack that applications can utilize to store a copy of return addresses that are checked...
- SHAKE256/192(M)SHAKE256(M, 192), where SHAKE256 is specified in Section 6.2 of [5]. The output length is 192 bits.
- SHAKE256/256(M)SHAKE256(M, 256), where SHAKE256 is specified in Section 6.2 of [5]. The output length is 256 bits.
- Shall1. The term used to indicate a requirement of a Federal Information Processing Standard (FIPS) or a...
- ShardingA blockchain configuration and architecture that enables the processing of transactions in parallel. The...
- shared controlA security or privacy control that is implemented for an information system in part as a common control and...
- shared secret key1. A shared secret that can be used directly as a cryptographic key in symmetric-key cryptography. It does...
- Shared Service Provider, see SSP
- Shared Service Providers, see SSP
- shielded enclosureRoom or container designed to attenuate electromagnetic radiation, acoustic signals, or emanations.
- Short Integer Solution, see SIS
- Short Message Service Chata facility for exchanging messages between mobile phone users in real-time via SMS text messaging, which...
- Short Message Service (SMS)1. A cellular network facility that allows users to send and receive text messages of up to 160 alphanumeric...
- short titleIdentifying combination of letters and numbers assigned to certain COMSEC materials to facilitate handling...
- short title assignment requester (STAR)The key management entity (KME) privileged to request assignment of a new short title and generation of key...
- short-term stabilityThe stability of a time or frequency signal over a short measurement interval, usually an interval of 100...
- Should1. The term used to indicate an important recommendation. Ignoring the recommendation could result in...
- ShrinkageProduct loss or theft that results in declining revenue.
- SIA1. The analysis conducted by an organizational official to determine the extent to which a change to an...
- side channelAllows an attacker to infer information about a secret by observing the nonfunctional characteristics of a...
- SidechainA blockchain with its own consensus mechanism and set of nodes that is connected to another blockchain...
- Side-Channel Attack1. An attack enabled by the leakage of information from a physical cryptosystem. Characteristics that could...
- SIEM, see Security Information and Event Management
- sigA digital signature of a randomized message.
- SIGE(…)A digital signature generated by the entity E using an approved hash function and an approved digital...
- signaling rateThe signaling rate of a digital signal is defined as the reciprocal of the bit width (1/bit width). The...
- SignatoryThe entity that generates a digital signature on data using a private key.
- signature1. A recognizable, distinguishing pattern.
- signature certificateA public key certificate that contains a public key intended for verifying digital signatures rather than...
- Signature generation1. The process of using a digital signature algorithm and a private key to generate a digital signature on...
- Signature validation1. The (mathematical) verification of the digital signature and obtaining the appropriate assurances (e.g...
- Signature verification1. The process of using a digital signature algorithm and a public key to verify a digital signature on data.
- Signature-in-questionThe digital signature to be verified and validated.
- Signed data1. The data or message upon which a digital signature has been computed.
- significant consequencesLoss of life or serious injury; serious damage to significant property; serious adverse foreign policy...
- significant cybersecurity or privacy responsibilitiesThe preferred terminology herein for identifying those whose roles in the organization necessitate ongoing...
- signing keyThe cryptographic key used to create a signature. In asymmetric cryptography, the signing key refers to the...
- SIMA smart card chip specialized for use in GSM equipment.
- SimilarityThe similarity of two artifacts, as measured by a particular approximate matching algorithm, is defined as an...
- Similarity digestA similarity digest is a (compressed) representation of the original data object’s feature set that is...
- Similarity functioncompares two similarity digests and outputs a score. The recommended approach is to assign a score s in the 0...
- Simple Certificate Enrollment Protocol (SCEP)A protocol defined in an IETF internet draft specification that is used by numerous manufacturers of network...
- Simple Mail Transfer Protocol (SMTP)1. An MTA protocol defined by IETF RFC 2821. SMTP is the most commonly used MTA protocol.
- Simple Object Access ProtocolAn XML-based protocol for exchanging structured information in a decentralized, distributed environment.
- Simple t-way combination coverageFor a given test set for n variables, simple t-way combination coverage is the proportion of t-way...
- SimulatorsA functional exercise staff member who simulates or represents non-participating individuals or organizations...
- single loop controllerA controller that controls a very small process or a critical process.
- single point keying (SPK)Means of distributing key to multiple, local crypto equipment or devices from a single fill point.
- Single Sign-OnAn authentication process by which one account and its authenticators are used to access multiple...
- SingulationA function performed by a reader to individually identify any tags in the reader’s operating range.
- SISA system that is composed of sensors, logic solvers, and final control elements whose purpose is to take the...
- SISOSee Senior Agency Information Security Officer.
- situational awareness1. Within a volume of time and space, the perception of an enterprise's security posture and its threat...
- SKEYA session key in TPM.
- Skill1. The capacity to perform an observable action.
- SkimmingThe unauthorized use of a reader to read tags without the authorization or knowledge of tag’s owner or the...
- SK_PRFAn n-byte key used to pseudorandomly generate the randomizer r.
- SLARepresents a commitment between a service provider and one or more customers and addresses specific aspects...
- Slack SpaceThe unused space in a file allocation block or memory page that may hold residual data.
- Small businessSmall businesses are defined differently depending on the industry sector. For this publication, the...
- Small Computer System InterfaceA magnetic media interface specification. Small Computer System Interface.
- smart card1. A credit card-sized card with embedded integrated circuits that can store, process, and communicate...
- Smart contractA collection of code and data (sometimes referred to as functions and state) that is deployed using...
- smart dataAssociation of authority, access requirements, retention provenance and any additional information with a...
- Smart MeterA device that includes Metrology, Communications Module, and, optionally, HAN interface. These components are...
- S/MIME, see Secure Multipurpose Internet Mail Extensions (S/MIME)
- SMM, see System Management Mode (SMM)
- SMSa mobile phone network facility that allows users to send and receive alphanumeric text messages of up to 160...
- SMS ChatA facility for exchanging messages in real-time using SMS text messaging that allows previously exchanged...
- SMTPthe primary protocol used to transfer electronic mail messages on the Internet.
- SnThe nth partial sum for values Xi = {-1, +1}; i.e., the sum of the first n values of Xi.
- SnapshotA record of the state of a running image, generally captured as the differences between an image and the...
- snifferSee packet sniffer and passive wiretapping.
- SO1. Person or organization having responsibility for the development, procurement, integration, modification...
- SOAA set of principles and methodologies for designing and developing software in the form of interoperable...
- SOAPAn XML-based protocol for exchanging structured information in a decentralized, distributed environment.
- SOAP HeaderA collection of zero or more blocks of information prepended to a SOAP message, each of which might be...
- SOAP MessageThe basic unit of communication between SOAP nodes.
- sobsThe observed value which is used as a statistic in the Frequency test.
- social engineering1. An attempt to trick someone into revealing information (e.g., a password) that can be used to attack...
- SOCKS ProtocolAn Internet protocol to allow client applications to form a circuit-level gateway to a network firewall via a...
- SoDrefers to the principle that no user should be given enough privileges to misuse the system on their own. For...
- Soft forkA change to a blockchain implementation that is backwards compatible. Non-updated nodes can continue to...
- software1. Computer programs and data stored in hardware - typically in read-only memory (ROM) or programmable...
- Software and Systems DivisionA Solid State Drive (SSD) is a storage device that uses solid state memory to store persistent data.
- Software as a Service (SaaS)The capability provided to the consumer is to use the provider’s applications running on a cloud...
- Software Asset Management1. An ISCM capability that identifies unauthorized software on devices that is likely to be used by attackers...
- software assurance (SwA)1. The planned and systematic set of activities that ensure that software life cycle processes and products...
- Software Bill of Materials1. A formal record containing the details and supply chain relationships of various components used in...
- software composition analysis, see SCA
- Software Development Life CycleA formal or informal methodology for designing, creating, and maintaining software (including code built into...
- Software IdentificationA SWID tag is an ISO 19770-2 compliant XML file describing a software product. It is typically digitally...
- software identification (SWID) tagInformation structure containing identification information about a software configuration item, which may be...
- software product and executable file versionA patch level versioning of the software product or digital fingerprint version of a software file.
- software system test and evaluation processProcess that plans, develops, and documents the qualitative/quantitative demonstration of the fulfillment of...
- Solid-State Drive1. A storage device that uses solid-state memory to store persistent data.
- SoM, see strength of mechanism
- SOP, see Standard operating procedures
- SoR1. A collection of records that contain information about individuals and are under the control of an agency...
- SORN1. A notice that federal agencies publish in the Federal Register to describe their system of record.
- SoS, see system of systems
- Source Address, see SA
- Source authentication1. A process that provides assurance of the source of information.
- source code controlA capability with which an attacker controls the source code of a machine learning algorithm.
- Source contentPart or all of SCAP source data streams.
- Source NameA single WFN that a matching engine compares to a target WFN to determine whether or not there is a...
- Source of Randomness1. A component of a DRBG (which consists of a DRBG mechanism and a randomness source) that outputs bitstrings...
- Source RestrictionA restriction configured for an authorized key that limits the IP addresses or host names from which login...
- Source ValueA single value that a matching engine compares to a corresponding target value to determine whether or not...
- Sources Sought NoticeA synopsis posted by a government agency that states they are seeking possible sources for a project. It is...
- SOWThe SOW details what the developer must do in the performance of the contract. Documentation developed under...
- SP1. Include proceedings of conferences sponsored by NIST, NIST annual reports, and other special publications...
- space structuresAny human-made assets in space, including “space debris” or “space junk” that is no longer in use for any...
- spam1. Electronic junk mail.
- SPARQLSPARQL Protocol and RDF Query Language
- SPD, see Security Policy Database (SPD)
- special access programA program established for a specific class of classified information that imposes safeguarding and access...
- special access program facilityA specific physical space that has been formally accredited in writing by the cognizant program security...
- special categorySensitive compartmented information (SCI), special access program (SAP) information, or other compartment...
- special character1. Any non-alphanumeric character that can be rendered on a standard, American-English keyboard. Use of a...
- Special Interest Group, see sig
- Specialized Security-Limited Functionality (SSLF) Environment1. A Custom environment that is highly restrictive and secure; it is usually reserved for systems that have...
- Specific1. The desired security strength for a digital signature.
- specification1. An assessment object that includes document-based artifacts (e.g., policies, procedures, plans, system...
- Specification Limit1. A condition indicating that risk has exceeded acceptable levels and that immediate action is needed to...
- specification requirementA type of requirement that provides a specification for a specific capability that implements all or part of...
- Specification versioningThe process of denoting a revision to a specification by changing its version number.
- SPIArbitrarily chosen value that acts as a unique identifier for an IPsec connection.
- spillageSecurity incident that results in the transfer of classified information or Controlled Unclassified...
- split tunneling1. A method that routes organization-specific traffic through the SSL VPN tunnel, but routes other traffic...
- Sponge ConstructionThe method originally specified in [Cryptographic sponge functions, version 0.1] for defining a function from...
- Sponge FunctionA function that is defined according to the sponge construction, possibly specialized to a fixed output...
- sponsorSubmits a Derived PIV Credential request on behalf of the applicant.
- Sponsor (of a certificate)1. A human entity that is responsible for managing a certificate for the non-human entity identified as the...
- Sponsor (of a key)1. A human entity that is responsible for managing a key for the non-human entity (e.g., device, application...
- spoofing1. An attempt to gain access to a system by posing as an authorized user. Note: Impersonating, masquerading...
- SprawlThe proliferation of images.
- spread spectrumTelecommunications techniques in which a signal is transmitted in a bandwidth considerably greater than the...
- spyware1. Software that is secretly or surreptitiously installed into an information system to gather information on...
- SQL injectionAttacks that look for web sites that pass insufficiently-processed user input to database back-ends
- squareThe property that some element x of a finite field GF(q) can be written as x=z^2 for some element z in the...
- SRG, see security requirements guide (SRG)
- SRTM, see security requirements traceability matrix (SRTM)
- SRxCryptoAPI, see SCA
- SSD1. A storage device that uses solid-state memory to store persistent data.
- SSE, see systems security engineering
- SSH ClientThe software implementation that enables a user or an automated process to remotely access an SSH server. An...
- SSH KeyA term that is generally used to refer to an identity and authorized keys. The term may also be occasionally...
- SSH ServerA software implementation that enables SSH access to a system from SSH clients. SSH server may be included...
- SSIDA name assigned to a wireless access point that allows stations to distinguish one wireless access point from...
- ss_KThe security strength that can be supported by the key K
- SSL, see Secure Sockets Layer (SSL)
- ss_MiThe security strength that can be supported by the combination of the methods used to generate a key Ki, and...
- SSOAn authentication process by which one account and its authenticators are used to access multiple...
- SSP1. Formal document that provides an overview of the security requirements for an information system and...
- STA, see Station
- stabilityAn inherent characteristic of an oscillator that determines how well it can produce the same frequency over a...
- stablecoinA cryptocurrency token that is a fungible unit of financial value pegged to a currency, some other asset, or...
- stagePeriod within the life cycle of an entity that relates to the state of its description or realization.
- stakeholder1. Individual or organization having a right, share, claim, or interest in a system or in its possession of...
- StakingProtocol-defined token collateralization earning yields and/or providing privileges, either at the base layer...
- Standalone Environment1. Environment containing individually managed devices (e.g., desktops, laptops, smartphones, tablets).
- standard1. A rule, condition, or requirement: (1) Describing the following information for products, systems...
- Standard Normal Cumulative Distribution FunctionSee the definition in Section 5.5.3. This is the normal function for mean = 0 and variance = 1.
- Standard operating proceduresA set of instructions used to describe a process or procedure that performs an explicit operation or explicit...
- Standards Developing Organizationany organization that develops and approves standards using various methods to establish consensus among its...
- Standards Developing Organizations, see SDO
- Standards-Setting Organization, see SSO
- STAR, see short title assignment requester (STAR)
- Start-up testingA suite of health tests that are performed every time the entropy source is initialized or powered up. These...
- StateIntermediate result of the AES block cipher that is represented as a two-dimensional array of bytes with four...
- State ChannelA scheme that enables the off-chain processing of transactions by a group of participants with instant second...
- State UpdateAn on-chain transaction used to anchor the current state of an external ledger onto the underlying blockchain.
- StatefulRefers to a data representation or a process that is dependent on an external data store.
- Stateful InspectionPacket filtering that also tracks the state of connections and blocks packets that deviate from the expected...
- Stateful Protocol AnalysisA firewalling capability that improves upon standard stateful inspection by adding basic intrusion detection...
- StatelessRefers to a data representation or a process that is self-contained and does not depend on any external data...
- Stateless InspectionSee “Packet Filtering”.
- Statement coverageThis is the simplest of coverage criteria - the percentage of statements exercised by the test set.
- Statement of Requirements, see SoR
- statement of work requirementA type of requirement that represents an action that is performed operationally or during system development.
- static code analyzerA tool that analyzes source code without executing the code. Static code analyzers are designed to review...
- Static key1. A key that is intended for use for a relatively long period of time and is typically intended for use in...
- Static key pair1. A key pair, consisting of a private key (i.e., a static private key) and a public key (i.e., a static...
- StationA client device in a wireless network.
- statistical biasA form of bias that occurs when the expected value of a released statistic does not match the true statistic.
- statistical disclosure controlThe set of methods to reduce the risk of disclosing information on individuals, businesses or other...
- statistical disclosure limitationThe set of methods to reduce the risk of disclosing information on individuals, businesses or other...
- Statistical Test (of a Hypothesis)A function of the data (binary stream) which is computed and used to decide whether or not to reject the null...
- Statistically Independent EventsTwo events are independent if the occurrence of one event does not affect the chances of the occurrence of...
- status word1. Two bytes returned by an integrated circuit card after processing any command that signify the success of...
- ST&E, see security test and evaluation (ST&E)
- steganography1. The art, science, and practice of communicating in a way that hides the existence of the communication.
- stewardA privileged person entity responsible for curating ICAM data.
- STIG, see security technical implementation guide (STIG)
- Stochastic modelA stochastic model is a mathematical description (of the relevant properties) of an entropy source using...
- Storage Area Network, see SAN
- Store a key or metadataPlacing a key and/or metadata in storage outside of a cryptographic module without retaining the original...
- stratified samplingThe process of segmenting a population across levels of some factors to minimize variability within those...
- stream cipherSequence of symbols (or their electrical or mechanical equivalents) produced in a machine or auto-manual...
- Stream componentA major element of a data stream, such as an XCCDF benchmark or a set of OVAL definitions.
- strength of function1. Criterion expressing the minimum efforts assumed necessary to defeat the specified security behavior of an...
- strength of mechanismA scale for measuring the relative strength of a security mechanism hierarchically ordered from SML 1 through...
- String1. An ordered sequence (string) of 0s and 1s. The leftmost bit is the most significant bit.
- structural relationship mappingA concept relationship style that captures an inherent hierarchical structure of concepts, usually defined...
- SU, see system user
- subaccountA COMSEC account that only received key from, and only reports to, its parent account, never a Central Office...
- subassemblyTwo or more parts that form a portion of an assembly or a unit replaceable as a whole, but having a part or...
- Sub-CapabilityA capability that supports the achievement of a larger capability. In this NISTIR, each defined capability is...
- Subcategory1. The subdivision of a Category into specific outcomes of technical and/or management activities. Examples...
- Subcommittee, see SC
- SubdirectoryA directory contained within another directory.
- Sub-functionsSub-functions are the basic operations employed to provide the system services within each area of operations...
- sub-hand receiptThe hand receipt of COMSEC material to authorized individuals by persons to whom the material has already...
- subject1. The entity requesting to perform an operation upon the object.
- Subject Alternative NameA field in an X.509 certificate that identifies one or more fully qualified domain names, IP addresses, email...
- Subject (in a certificate)The entity authorized to use the private key associated with the public key in the certificate.
- subjectAltName, see SAN
- SubkeyA secret string that is derived from the key.
- Subkey GenerationAn algorithm that derives subkeys from a key.
- SubmitterThe party that submits the entire entropy source and output from its components for validation. The submitter...
- subordinate certificate authorityIn a hierarchical public key infrastructure (PKI), a certificate authority (CA) whose certificate signing key...
- subsamplingAn algorithmic strategy where the query output is computed using only a fraction of the original data...
- subscriber1. An entity that has applied for and received a certificate from a Certificate Authority.
- subscriber accountAn account established by the CSP for each subscriber enrolled in its identity service that contains...
- Subscriber Identity Module (SIM)A smart card chip specialized for use in GSM equipment.
- subscriber-controlled walletA type of IdP that is issued attribute bundles by the CSP. The subscriber-controlled wallet that is either...
- subsystem1. A major subdivision or component of an information system consisting of information, information...
- SuccessorIn the RBG-based construction of IVs, the result of one or more applications of the appropriate incrementing...
- Suitability and Credentialing Executive AgentIndividual responsible for prescribing suitability standards and minimum standards of fitness for employment...
- summation queryA query that sums a derived quantity from each row in a dataset with a particular property.
553 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.