Comprehensive definitions of cybersecurity, compliance, and technology terms
When users abuse their privilege level to carry out tasks that are not their responsibility, there are problems.
The process of granting or denying specific requests for obtaining and using information and related information processing services; and to enter specific physical facilities (e.g., Federal buildings, military establishments, and border crossing entrances).
Security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.
Administrative software tools used by network administrators to manage networks, systems, or applications, often with elevated privileges.
An adversary that possesses sophisticated levels of expertise and significant resources which allow it to create opportunities to achieve its objectives by using multiple attack vectors including, for example, cyber, physical, and deception. These objectives typically include establishing and extending footholds within the IT infrastructure of the targeted organizations for purposes of exfiltrating information, undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period; adapts to defenders’ efforts to resist it; and is determined to maintain the level of interaction needed to execute its objectives.
Software that automatically displays or downloads advertising material when a user is online, which can be intrusive and sometimes serve as a channel for malware.
The process an organization employs to assign security or privacy requirements to an information system or its environment of operation; or to assign controls to specific system elements responsible for providing a security or privacy capability (e.g., router, server, remote sensor).
Changes in the normal operations or responses of a system, application, or user behavior due to external influences, often indicative of a cyber threat.
A software program hosted by an information system.
The simulation of human intelligence in machines, enabling them to perform tasks typically requiring human cognition, such as problem-solving, decision-making, learning, and natural language understanding. AI is widely used in cybersecurity for threat detection, anomaly analysis, and automated incident response.
An act that threatens physical harm to a person; in cybersecurity, it metaphorically refers to aggressive attempts to damage or disrupt systems or networks.
See "Control assessment" or "Risk assessment".
The objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments.
The individual, group, or organization responsible for conducting a security or privacy control assessment.
A control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement (e.g., assigning a list of roles to be notified or a value for the frequency of testing). See "Organization-defined control parameters" and "Selection operation".
A control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement (e.g., assigning a list of roles to be notified or a value for the frequency of testing). See "Organization-defined control parameters" and "Selection operation".
Grounds for justified confidence that a [security or privacy] claim has been or will be achieved.
The set of points on the boundary of a system, a system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from, that system, component, or environment.
Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures.
A chronological record of system activities, including records of system accesses and operations performed in a given period.
An individual entry in an audit log related to an audited event.
A process that manipulates collected audit information and organizes it into a summary format that is more meaningful to analysts.
A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result.
Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.
Something that the claimant possesses and controls (typically a cryptographic module or password) that is used to authenticate the claimant’s identity. This was previously referred to as a token.
The property of being genuine and being able to be verified and trusted; confidence in the validity of a transmission, message, or message originator. See "Authentication".
Access privileges granted to a user, program, or process or the act of granting those privileges.
All components of an information system to be authorized for operation by an authorizing official. This excludes separately authorized systems to which the information system is connected.
The essential information that an authorizing official uses to determine whether to authorize the operation of an information system or the provision of a designated set of common controls.
The official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations, agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls.
The official management decision given by an authorizing official to authorize the use of an information system, service, or application based on the information in an existing authorization package generated by another organization, and to explicitly accept the risk to agency operations, agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of controls in the system, service, or application.
A senior Federal official or executive with the authority to authorize (i.e., assume responsibility for) the operation of an information system or the use of a designated set of common controls at an acceptable level of risk to agency operations (including mission, functions, image, or eputation), agency assets, individuals, other organizations, and the Nation.
An organizational official acting on behalf of an authorizing official in carrying out and coordinating the required activities associated with the authorization process.
Ensuring timely and reliable access to and use of information.
A method of bypassing normal authentication procedures to secretly allow remote access to a system, potentially for malicious purposes.
A form of social engineering that involves offering something enticing to an end user, which is used to deliver malware or perform harmful actions.
See "Control baseline".
A documented set of specifications for a system, or a configuration item within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures.
Monitoring and control of communications at the external interface to a system to prevent and detect malicious and other unauthorized communications using boundary protection devices.
A device (e.g., gateway, router, firewall, guard, or encrypted tunnel) that facilitates the adjudication of different system security policies for connected systems or provides boundary protection. The boundary may be the authorization boundary for a system, the organizational network boundary, or a logical boundary defined by the organization.
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: a person other than an authorized user accesses or potentially accesses personally identifiable information; or an authorized user accesses personally identifiable information for another than authorized purpose.
An attribute associated with an assessment method that addresses the scope or coverage of the assessment objects included with the assessment.
Offering something of value to influence or induce someone to act dishonestly or to gain unauthorized access to systems or data in a cybersecurity context.
A trial-and-error method used to obtain sensitive information such as a password or PIN by generating a large number of consecutive guesses.
Occurs when more data is sent to a buffer than it can handle, leading to data overflow that can overwrite adjacent memory locations and cause system crashes or unauthorized code execution.
A characteristic or quality that defines or describes a business operation, goal, or objective, helping to clarify the focus or scope of a business activity.
Individuals or groups that use hacking to gain a competitive advantage or to steal intellectual property
Factors or motivations that influence a company's decisions and policies regarding cybersecurity. These drivers often include the need to protect assets, comply with regulations, maintain reputation, and ensure operational continuity.
Specific, measurable aims that a company seeks to achieve as part of its strategic planning. Goals and objectives guide a business’s operations, including its security initiatives, to align with its broader mission and values.
Bypassed physical barriers or controls
A cyber attack where malicious data is inserted into a cache, causing users to be directed to fraudulent sites or servers.
A combination of mutually reinforcing controls implemented by technical means, physical means, and procedural means. Such controls are typically selected to achieve a common information security or privacy purpose.
A process level improvement training and appraisal program. Administered by the CMMI Institute, it helps organizations improve their performance by providing a set of guidelines for process improvement across a project, division, or an entire organization.
A type of requirement describing the capability that the organization or system must provide to satisfy a stakeholder need. Note: Capability requirements related to information security and privacy are derived from stakeholder protection needs and the corresponding security and privacy requirements.
The organization-wide management and implementation of selected security and privacy controls and related processes. Central management includes planning, implementing, assessing, authorizing, and monitoring the organization-defined, centrally managed security and privacy controls and processes.
A certain level of trust in supply chain interactions such that each participant in the consumer-provider relationship provides adequate protection for its component products, systems, and services.
A value that is computed by a function that is dependent on the contents of a data object and stored or transmitted together with the object, for detecting changes in the data.
The senior official that provides advice and other assistance to the head of the agency and other senior management personnel of the agency to ensure that IT is acquired and information resources are managed for the agency in a manner that achieves the agency’s strategic goals and information resources management goals; and is responsible for ensuring agency compliance with, and prompt, efficient, and effective implementation of, the information policies and information resources management responsibilities, including the reduction of information collection burdens on the public.
See "Senior Agency Information Security Officer".
See "Classified national security information".
Information that has been determined pursuant to Executive Order (E.O.) 13526 or any predecessor order to require protection against unauthorized disclosure and is marked to indicate its classified status when in documentary form.
Click fraud or Bitcoin mining
Purchases or contracts services or products from the company, driving its revenue.
Client-side or browser attack (e.g., redirection, XSS, MitB)
Computing services provided over the Internet, allowing for scalable resources and pay-as-you-go pricing, enhancing flexibility and reducing operating costs.
A method used by cybercriminals to maintain communication with compromised devices within a target network, allowing for the remote manipulation of those devices.
An interface over which users can execute system commands directly on a computer's operating system.
A system service provided by a commercial service provider to a large and diverse set of consumers. The organization acquiring or receiving the commodity service possesses limited visibility into the management structure and operations of the provider, and while the organization may be able to negotiate service-level agreements, the organization is typically not able to require that the provider implement specific security or privacy controls.
A telecommunications company that holds itself out to the public for hire to provide communications transmission services.
A security or privacy control that is inherited by multiple information systems or programs.
An organizational official responsible for the development, implementation, assessment, and monitoring of common controls (i.e., security or privacy controls inheritable by systems).
Governing document that provides a comprehensive, rigorous method for specifying security function and assurance requirements for products and systems.
Recognized, standardized, and established benchmarks that stipulate secure configuration settings for specific information technology platforms/products and instructions for configuring those system components to meet operational requirements. These benchmarks are also referred to as security configuration checklists, lockdown and hardening guides, security reference guides, and security technical implementation guides.
The security and privacy controls employed in lieu of the controls in the baselines described in NIST Special Publication 800-53B that provide equivalent or comparable protection for a system or organization.
Compliance risks stem from potential legal penalties, financial forfeitures, or material losses a company might face for not adhering to relevant laws, regulations, standards, and prescribed practices that apply to its business activities. Non-compliance can lead to damage to the company's reputation, legal penalties, and financial loss.
See "System component".
A compromise of the service engine will give an attacker access to the data of all customers, resulting in a potential complete loss of data or denial of service.
Refers to the processing power, memory, and computational resources required to run applications, process data, and execute workloads, typically delivered via on-premises hardware or cloud-based virtual environments.
Highly sensitive information that if disclosed could cause significant harm or risk to the organization, requiring stringent access controls and protection.
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.
Process for controlling modifications to hardware, firmware, software, and documentation to protect the system against improper modifications before, during, and after system implementation.
An aggregation of system components that is designated for configuration management and treated as a single entity in the configuration management process.
A collection of activities focused on establishing and maintaining the integrity of information technology products and systems, through control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.
The set of parameters that can be changed in hardware, software, or firmware that affect the security posture and/or functionality of the system.
Maintaining ongoing awareness to support organizational risk decisions.
A program established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls. Note: Privacy and security continuous monitoring strategies and programs can be the same or different strategies and programs.
See "Security control" or "Privacy control".
The testing or evaluation of the controls in an information system or an organization to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security or privacy requirements for the system or the organization.
The individual, group, or organization responsible for conducting a control assessment. See "Assessor".
Predefined sets of controls specifically assembled to address the protection needs of groups, organizations, or communities of interest. See "Privacy control baseline" or Security control baseline".
The process of assigning a control to one of three control types: common, hybrid, or system-specific.
A measure of whether a security or privacy control contributes to the reduction of information security or privacy risk.
Augmentation of a security or privacy control to build in additional but related functionality to the control, increase the strength of the control, or add assurance to the control.
A situation in which a system or application receives protection from security or privacy controls (or portions of controls) that are developed, implemented, assessed, authorized, and monitored by entities other than those responsible for the system or application; entities either internal or external to the organization where the system or application resides. See "Common control".
See "Organization-defined control parameter".
Any area or space for which an organization has confidence that the physical and procedural protections provided are sufficient to meet the requirements established for protecting the information and/or information system.
An interface to a system with a set of mechanisms that enforces the security policies and controls the flow of information between connected systems.
Information that the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency.
The exclusive legal right, given to an originator or an assignee to print, publish, perform, film, or record literary, artistic, or musical material.
Reducing an impact.
An unauthorized copy or substitute that has been identified, marked, and/or altered by a source other than the item's legally authorized source and has been misrepresented to be an authorized item of the legally authorized source.
Actions, devices, procedures, techniques, or other measures that reduce the vulnerability of a system. Synonymous with security controls and safeguards.
An unintended or unauthorized intra-system channel that enables two cooperating entities to transfer information in a way that violates the system's security policy but does not exceed the entities' access authorizations.
Determination of the extent to which the security policy model and subsequent lower-level program descriptions may allow unauthorized access to information.
A system feature that enables one system entity to signal information to another entity by directly or indirectly writing to a storage location that is later directly or indirectly read by the second entity.
A system feature that enables one system entity to signal information to another by modulating its own use of a system resource in such a way as to affect system response time observed by the second entity.
An object or data structure that authoritatively binds an identity, via an identifier or identifiers, and (optionally) additional attributes, to at least one authenticator possessed and controlled by a subscriber.
Information that is used to confirm a user's identity before allowing access to a computer system, typically consisting of a username and a password.
Systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.
Systems, assets, and networks considered essential for the functioning of a society and economy, including energy grids, financial systems, transportation networks, and healthcare facilities. Disruption or compromise can have severe consequences for national security and public safety.
A form of controlled interface that provides the ability to manually and/or automatically access and/or transfer information between different security domains.
The study and practice of breaking cryptographic codes, analyzing encryption systems to discover vulnerabilities.
The set of hardware, software, and/or firmware that implements Approved security functions (including cryptographic algorithms and key generation) and is contained within the cryptographic boundary.
Cross-Site Request Forgery, a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts.
Interacting digital, analog, physical, and human components engineered for function through integrated physics and logic.
Prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.
A risk-based approach to reducing cybersecurity risk composed of three parts: the Framework Core, the Framework Profile, and the Framework Implementation Tiers.
The subdivision of a Function into groups of cybersecurity outcomes, closely tied to programmatic needs and particular activities.
A set of cybersecurity activities and references that are common across critical infrastructure sectors and are organized around particular outcomes. The Framework Core comprises four types of elements: Functions, Categories, Subcategories, and Informative References.
One of the main components of the Framework. Functions provide the highest level of structure for organizing basic cybersecurity activities into Categories and Subcategories. The five functions are Identify, Protect, Detect, Respond, and Recover.
A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories.
The subdivision of a Category into specific outcomes of technical and/or management activities.
The interdependent network of information technology infrastructures that includes the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries.
Data refers to any digital information that is created, collected, stored, processed, or transmitted by the organization. This encompasses a wide range of content, including personal information of employees and customers, financial records, intellectual property, operational data, and communications.
A system operation that processes personally identifiable information.
An analytical process that attempts to find correlations or patterns in large data sets for the purpose of data or knowledge discovery.
The incorrect handling or processing of data that can lead to data breaches or unintentional data disclosure.
The practice of ensuring that personal, confidential, and sensitive data is securely stored, processed, and transmitted to prevent unauthorized access, loss, or breaches, while also complying with legal and regulatory requirements.
Data protection law is based on the premise that it is always clear where personal data is located, who process it and who is responsible for data processing. Distributed environments appear to conflict with this evidence.
General term for any process of removing the association between a set of identifying data and the data subject.
A set of strategies, technologies, and practices designed to protect systems, networks, and data from cyber threats, unauthorized access, and malicious activities, ensuring resilience against disruptions or breaches.
A planned, systematic set of multidisciplinary activities that seek to identify, manage, and reduce risk of exploitable vulnerabilities at every stage of the system, network, or subcomponent life cycle, including system, network, or product design and development; manufacturing; packaging; assembly; system integration; distribution; operations; maintenance; and retirement.
An information security strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.
Intentional alteration of the information to obtain a benefit or cause damage.
The lack of sufficient resources causes the system failure when the workload is too high
An attribute associated with an assessment method that addresses the rigor and level of detail associated with the application of the method.
A requirement that is implied or transformed from a higher-level requirement. Note 1: Implied requirements cannot be assessed since they are not contained in any requirements baseline. The decomposition of requirements throughout the engineering process makes implicit requirements explicit, allowing them to be stated and captured in appropriate baselines and allowing associated assessment criteria to be stated. Note 2: A derived requirement must trace back to at least one higher-level requirement.
Software or a feature within a software application that allows users to share access to their desktop or applications with others over a network.
The intentional deletion of information, to obtain a benefit or cause damage.
Vandalism, terrorism, military action, etc.
Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event.
Detecting a problem and triggers other controls.
A general term that includes developers or manufacturers of systems, system components, or system services; systems integrators; vendors; and product resellers. The development of systems, components, or services can occur internally within organizations or through external entities.
A form of electronic media where data is stored in digital (as opposed to analog) form.
Enabling the processing of personally identifiable information or events without association to individuals or devices beyond the operational requirements of the system.
Intentional disclosure of information
An access control policy that is enforced over all subjects and objects in a system where the policy specifies that a subject that has been granted access to information can do one or more of the following: pass the information to other subjects or objects; grant its privileges to other subjects; change the security attributes of subjects, objects, systems, or system components; choose the security attributes to be associated with newly-created or revised objects; or change the rules governing access control.
Distributes the company's products to broader markets or consumer bases, extending the company's reach beyond direct sales channels.
An environment or context that includes a set of system resources and a set of system entities that have the right to access the resources as defined by a common security policy, security model, or security architecture. See "Security domain".
Denial of Service, a cyber attack intended to shut down a machine or network, making it inaccessible to its intended users by overwhelming it with a flood of internet traffic.
Attackers have access to information that is not theirs, without the information itself being altered.
Authorization
The art of subtly extracting confidential information from individuals by asking seemingly innocuous questions that do not arouse suspicion.
A function within some email systems that allows attachments or links to be opened or executed automatically without user intervention.
The theft of assets (usually money) from a company or individual to which one had access, typically occurring in a corporate or employment environment.
When the premises have been invaded and control is lost over the means of work
An organization with a defined mission/goal and a defined boundary, using systems to execute that mission, and with responsibility for managing its own risks and performance. An enterprise may consist of all or some of the following business aspects: acquisition, program management, human resources, financial management, security, and systems, information and mission management. See "Organization".
A strategic information asset base, which defines the mission; the information necessary to perform the mission; the technologies necessary to perform the mission; and the transitional processes for implementing new technologies in response to changing mission needs; and includes a baseline architecture; a target architecture; and a sequencing plan.
The physical surroundings in which an information system processes, stores, and transmits information.
Any observable occurrence in a system.
The unauthorized transfer of information from a system.
An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
A network not controlled by the organization.
This domain refers to the security considerations associated with an organization's interactions and collaborations with external entities, such as vendors, suppliers, business partners, and service providers.
See "External system service provider".
A system or component of a system that is used by but is not a part of an organizational system and for which the organization has no direct control over the implementation of required security and privacy controls or the assessment of control effectiveness.
A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by, but not a part of, the organizational system) and for which the organization typically has no direct control over the application of required controls or the assessment of control effectiveness.
A provider of external system services to an organization through a variety of consumer-producer relationships, including joint ventures, business partnerships, outsourcing arrangements (i.e., through contracts, interagency agreements, lines of business arrangements), licensing agreements, and/or supply chain exchanges.
External threats originate from sources outside of the organization and its network of partners. Examples include criminal groups, lone hackers, former employees, and government entities. Also includes God (as in “acts of”), “Mother Nature,” and random chance. Typically, no trust or privilege is implied for external entities.
The domain of "External - Untrusted" refers to the security considerations associated with an organization's interactions and collaborations that originate from sources outside an organization's trusted network or control. These external sources can include unknown or unverified individuals, organizations, networks, and services that are not directly associated with or trusted by the organization.
Pressure with threats, on people, to oblige them to act in a certain way.
This domain refers to a physical or virtual space equipped with the necessary resources to support various business activities. These facilities can range from office buildings and factories to virtual platforms that host online operations.
One or more physical locations containing systems or system components that process, store, or transmit information.
The capability to switch over automatically (typically without human intervention or warning) to a redundant or standby system upon the failure or abnormal termination of the previously active system.
An emotional response to perceived threats and danger, often used in social engineering attacks to manipulate individuals.
A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet requirements specified in FIPS Publication 140-3 (as amended). As a prerequisite to CMVP validation, the cryptographic module is required to employ a cryptographic algorithm implementation that has successfully passed validation testing by the Cryptographic Algorithm Validation Program (CAVP). See "NSA-approved cryptography".
Computer programs and data stored in hardware - typically in read-only memory (ROM) or programmable read-only memory (PROM) - such that the programs and data cannot be dynamically written or modified during execution of the programs. See "Hardware and software".
The technique of gathering information about computer systems and the entities they belong to; used to find vulnerabilities and aid in attacks.
A security exploit in which the attacker forces a web browser to access unauthorized content on a website.
The act of falsely making or materially altering a document with the intent to deceive.
A vulnerability in software where an attacker can execute arbitrary code or cause a crash by manipulating input strings passed to a formatter function.
A transaction that is made without the authorization of the account holder, typically involving theft or deception.
A software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program to detect errors or vulnerabilities.
Disruptive action done in the name of geopolitics (mostly carried out by state sponsored groups).
Gaining information on IP (Intellectual Property), sensitive data, classified data (mostly executed by state sponsored groups).
Establish and monitor risk management strategy, expectations, and policy.
The framework of policies, roles, responsibilities, and processes used to ensure that an organization’s cybersecurity strategy aligns with its objectives, manages risks effectively, and complies with legal, regulatory, and industry standards.
Official government agencies and bodies that the company interacts with for regulatory compliance, contracts, or guidance.
A strong feeling of resentment or anger towards someone or something, potentially leading to malicious actions or behaviors.
Hacking is defined within VERIS as all attempts to intentionally access or harm information assets without (or exceeding) authorization by circumventing or thwarting logical security mechanisms. Includes brute force, SQL injection, cryptanalysis, denial of service attacks, etc.
The material physical components of a system. See "Software and firmware".
The act of physically altering or interfering with hardware components to undermine system integrity, functionality, or security.
In a cybersecurity context, it refers to the overall operational status and resilience of systems, networks, and applications, ensuring they are functioning effectively and securely without vulnerabilities or performance issues.
A system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS Publication 199 potential impact value of high.
A technique where maliciously crafted HTTP requests are used to exploit web application parsing discrepancies, potentially bypassing security mechanisms.
An attack technique where HTTP requests are split into multiple parts, potentially confusing the target server and causing it to behave unexpectedly.
Policies and procedures designed to ensure that employees, contractors, and other personnel are screened, trained, and monitored to prevent insider threats, ensure proper access management, and align their activities with security policies.
A security or privacy control that is implemented for an information system in part as a common control and in part as a system-specific control. See "Common control" and "System-specific control".
A software layer or firmware that enables the creation and management of virtual machines by abstracting and isolating hardware resources. Hypervisors allow multiple operating systems to run simultaneously on a single physical machine securely.
Infrastructure-as-a-Service; a cloud computing model where virtualized computing resources, such as servers, storage, and networking, are delivered over the Internet, allowing organizations to scale resources without managing physical hardware.
Unique data used to represent a person’s identity and associated attributes. A name or a card number are examples of identifiers. A unique label used by a system to indicate a specific entity, object, or group.
Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event.
A framework of policies and technologies to ensure that the right individuals have the appropriate access to systems, applications, and data, minimizing the risk of unauthorized access and protecting sensitive information.
Hacktivists and terrorists, due to their similar ideological motivations, despite differing methods and outcomes. Hacktivists violate computer security laws to promote their causes, while terrorists engage in acts designed to instill fear for similar ideological reasons.
Content that is illegal or not authorized for distribution or possession, which often includes copyright infringement or materials deemed harmful.
The effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system.
See "Impact value".
The assessed worst-case potential impact that could result from a compromise of the confidentiality, integrity, or availability of information expressed as a value of low, moderate or high.
An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
A comprehensive review, analysis, and testing, (software and/or hardware) performed by an objective third party to confirm (i.e., verify) that the requirements are correctly defined, and to confirm (i.e., validate) that the system correctly implements the required functionality and security requirements.
General term that encompasses several types of control systems, including supervisory control and data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations such as programmable logic controllers (PLC) often found in the industrial sectors and critical infrastructures. An ICS consists of combinations of control components (e.g., electrical, mechanical, hydraulic, pneumatic) that act together to achieve an industrial objective (e.g., manufacturing, transportation of matter or energy).
Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms.
Unauthorized exposure or sharing of sensitive data.
Controls to ensure that information transfers within a system or organization are not made in violation of the security policy.
The intentional or unintentional release of information to an untrusted environment.
The stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition, to include destruction and deletion.
Official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal.
The implementation of safeguards and technologies to prevent unauthorized access, alteration, or destruction of sensitive information, ensuring confidentiality, integrity, and availability of data throughout its lifecycle.
Information and related resources, such as personnel, equipment, funds, and information technology.
The protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.
An embedded, integral part of the enterprise architecture that describes the structure and behavior of the enterprise security processes, security systems, personnel and organizational subunits, showing their alignment with the enterprise’s mission and strategic plans. See "Security architecture".
The process of evaluating and validating the effectiveness of an organization’s information security controls, policies, and practices to ensure they meet security objectives and regulatory requirements while mitigating potential risks.
The proactive monitoring, detection, and management of security-related events, including identifying threats, analyzing incidents, and implementing response measures to reduce potential harm and maintain system integrity.
Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information.
Formal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management controls and common controls in place or planned for meeting those requirements.
The risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation due to the potential for unauthorized access, use, disclosure, disruption, modification, or destruction of information and/or systems.
An agency official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal.
A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
See "Authorization boundary".
Individual with assigned responsibility for maintaining the appropriate operational security posture for an information system or program.
A formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements.
Any services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use.
See "System component".
A specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor-sensitive, security management) defined by an organization or in some instances, by a specific law, Executive Order, directive, policy, or regulation.
This domain refers to the fundamental systems and networks that support and enable the functioning of an organization. This includes physical components like network hardware, servers, and data communication devices, as well as virtual components such as cloud resources, virtual networks, and software-defined networks.
Provisioning, management, orchestration and monitoring are all performed through APIs. The security and availability of general services is dependent on the security of these interfaces.
Deleting data from storage does not in fact mean that the data is permanently removed from the storage. The data could be accessed at later time byanother customer of an outsourcing partner / provider.
Any person with authorized access to any organizational resource, to include personnel, facilities, information, equipment, networks, or systems.
The threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of organizational operations and assets, individuals, other organizations, and the Nation. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of organizational resources or capabilities.
A coordinated collection of capabilities authorized by the organization and used to deter, detect, and mitigate the unauthorized disclosure of information.
A condition where the value of a computed integer exceeds the storage capacity allocated for it, leading to unexpected behaviors or system crashes.
Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
Common boundary between independent systems or modules where interactions take place.
Data intended for use within the organization and not for public dissemination, requiring some level of control.
A network where the establishment, maintenance, and provisioning of security controls are under the direct control of organizational employees or contractors. Cryptographic encapsulation or similar security technology implemented between organization-controlled endpoints provides the same effect (at least regarding confidentiality and integrity). An internal network is typically organization-owned yet may be organization-controlled while not being organization-owned.
Internal threats are those originating from within the organization. This encompasses company full-time employees, independent contractors, interns, and other staff. Insiders are trusted and privileged (some more than others). see "Insider".
The Internet of Things (IoT) refers to a network of physical devices, vehicles, appliances, and other objects embedded with sensors, software, and network connectivity, enabling them to collect, exchange, and act upon data.
Individuals or entities that provide capital to the company, either through direct investment or via financial instruments like stocks or bonds.
See "Internet of Things (IOT)".
Failure of mechanisms separating storage, memory, routing, and even reputation between different tenants of the shared infrastructure
See "Information technology (IT)".
Authorization involving multiple authorizing officials.
Misuse of knowledge gained from one’s position or access to confidential information to harm or deceive.
See "Security label".
An attack method used to exploit web-based applications by manipulating LDAP statements through custom crafted input.
The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
The processes and measures organizations follow to ensure adherence to applicable laws, regulations, and industry standards related to cybersecurity, data privacy, and risk management, often requiring documentation, audits, and periodic reviews.
Access to an organizational system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.
Relying strongly on the services of one provider can lead to severe difficulties in changing the provider.
The unauthorized alteration of logs to hide malicious activity or create false entries in system records.
An automated system that controls an individual’s ability to access one or more computer system resources, such as a workstation, network, application, or database. A logical access control system requires the validation of an individual’s identity through some mechanism, such as a PIN, card, biometric, or other token. It has the capability to assign different access privileges to different individuals depending on their roles and responsibilities in an organization.
The loss of governance and control could have a potentially severe impact on the organization’s strategy and therefore on the capacity to meet its mission and goals.
A system in which all three security objectives (i.e., confidentiality, integrity, and availability) are assigned a FIPS Publication 199 potential impact value of low.
A type of attack where an attacker sends email containing commands that are executed by the receiving server, potentially compromising it.
Software or firmware intended to perform an unauthorized process that will have adverse impacts on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
Malware is any malicious software, script, or code run on a device that alters its state or function without the owner’s informed consent. Examples include viruses, worms, spyware, keyloggers, backdoors, etc.
Intentional propagation of viruses, spy ware, worms, Trojans, logic bombs, etc.
An interface within a system that provides boundary protection capabilities using automated mechanisms or devices.
A management interface is compromised
An access control policy that is uniformly enforced across all subjects and objects within a system. A subject that has been granted access to information is constrained from: passing the information to unauthorized subjects or objects; granting its privileges to other subjects; changing one or more security attributes on subjects, objects, the system, or system components; choosing the security attributes to be associated with newly created or modified objects; or changing the rules for governing access control.
See "Security marking".
When attackers manage to appear as authorised users, they enjoy the users’ privileges for their own purposes
A written agreement between a recipient agency and a source agency (or a non-Federal agency) that is required by the Privacy Act for parties engaging in a matching program.
A structured framework for assessing the maturity of an organization's processes, practices, and controls in areas such as cybersecurity, risk management, and compliance, often used to identify areas for improvement and measure progress over time.
Physical devices or writing surfaces including magnetic tapes, optical disks, magnetic disks, Large-Scale Integration memory chips, and printouts (but excluding display media) onto which information is recorded, stored, or printed within a system.
Information that describes the characteristics of data, including structural metadata that describes data structures (i.e., data format, syntax, semantics) and descriptive metadata that describes data contents (i.e., security labels).
Misuse is defined as the use of entrusted organizational resources or privileges for any purpose or manner contrary to that which was intended. Includes administrative abuse, use policy violations, use of non-approved assets, etc. These actions can be malicious or non-malicious in nature. Misuse is exclusive to parties that enjoy a degree of trust from the organization, such as insiders and partners.
An attack where the attacker secretly intercepts and possibly alters the communication between two parties who believe they are directly communicating with each other.
Software programs or parts of programs obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient.
Software technologies that provide the mechanisms for the production and use of mobile code.
A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable data storage; and is powered on for extended periods of time with a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the device to capture (e.g., photograph, video, record, or determine location) information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones, tablets, and e-readers.
A system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS Publication 199 potential impact value of moderate and no security objective is assigned a potential impact value of high.
Any financially related action (carried out by cybercrime groups).
An authentication system or an authenticator that requires more than one authentication factor for successful authentication. Multi-factor authentication can be performed using a single authenticator that provides more than one factor or by a combination of authenticators that provide different factors. The three authentication factors are something you know, something you have, and something you are. See "Authenticator".
Concept of processing information with different classifications and categories that simultaneously permits access by users with different security clearances and denies access to users who lack authorization.
Capability of a system that is trusted to contain, and maintain separation between, resources (particularly stored data) of different security domains.
Governments or their agencies that conduct cyber espionage or cyberwarfare for political, economic, or military advantage.
The improper or unethical use of a computer network for personal gain, or to perform illegal activities.
A system implemented with a collection of connected components, which may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices.
Access to a system by a user (or a process acting on behalf of a user) communicating through a network, including a local area network, a wide area network, and the Internet.
The method by which malware spreads across a network by replicating itself from one device to another.
Non-profit organizations that partner with or are supported by the company in social, environmental, or developmental programs.
A user who is not an organizational user (including public users).
Protection against an individual who falsely denies having performed a certain action and provides the capability to determine whether an individual took a certain action, such as creating information, sending a message, approving information, or receiving a message.
A value used in security protocols that is never repeated with the same key. For example, nonces used as challenges in challenge-response authentication protocols are not repeated until the authentication keys are changed, to prevent a replay attack.
See "Mandatory access control".
An entity that owns, operates, or maintains a nonfederal system.
A system that does not meet the criteria for a federal system.
Maintenance activities conducted by individuals who communicate through either an internal or external network.
Cryptography that consists of an approved algorithm, an implementation that has been approved for the protection of classified information and/or controlled unclassified information in a specific environment, and a supporting key management infrastructure.
A type of injection attack where an attacker inserts a null character (0x00) into a data stream to manipulate the logical flow of an application.
Passive system-related entity, including devices, files, records, tables, processes, programs, and domains that contain or receive information. Access to an object (by a subject) implies access to the information it contains. See "Subject".
The act of making something unclear or difficult to understand, often to conceal the truth or to mislead.
The practice of retrieving cryptographic keys from a secure system through direct access to its data outside of the network.
Operational Plans describe what will happen during a given period of time. These plans are often referred to as operational plans because they define the day-to-day operations of an organization.
Operational risks refer to the potential failures in the day-to-day activities of an organization. They encompass risks that arise from internal processes, systems, people, and external events. This includes everything from breakdowns in internal procedures, systems, and controls to unforeseen external events like natural disasters.
Technical, administrative, and physical measures implemented to ensure the ongoing protection of systems, applications, and data during regular operations, reducing vulnerabilities and preventing unauthorized access.
Programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building management systems, fire control systems, and physical access control mechanisms.
Systematic and proven process by which potential adversaries can be denied information about capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence of the planning and execution of sensitive activities. The process involves five steps: identification of critical information, analysis of threats, analysis of vulnerabilities, assessment of risks, and application of appropriate countermeasures.
See "Operational technology".
The coordination and oversight of an organization's resources, including people, processes, and technology, to ensure alignment with strategic goals, operational efficiency, and effective risk management.
An entity of any size, complexity, or positioning within an organizational structure, including federal agencies, private enterprises, academic institutions, state, local, or tribal governments, or as appropriate, any of their operational elements.
The variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement. See Assignment operation" and "Selection operation".
The variable part of a security requirement that is instantiated by an organization during the tailoring process by assigning an organization-defined value as part of the requirement. [8, adapted]
Relating to the structure, culture, policies, and processes within an organization that define roles, responsibilities, and workflows for managing operations, security, and risk.
An organizational employee or an individual whom the organization deems to have equivalent status of an employee, including a contractor, guest researcher, or individual detailed from another organization. Policies and procedures for granting the equivalent status of employees to individuals may include need-to-know, relationship to the organization, and citizenship.
A control baseline tailored for a defined notional (type of) information system using overlays and/or system-specific control tailoring, and intended for use in selecting controls for multiple systems within one or more organizations.
Groups that use hacking as a means to commit financial crimes, such as theft, fraud, or extortion.
An attack where commands are executed on a host operating system through a vulnerability in another application.
See "Operational Technology (OT)".
A specification of security or privacy controls, control enhancements, supplemental guidance, and other supporting information employed during the tailoring process, that is intended to complement (and further refine) security control baselines. The overlay specification may be more stringent or less stringent than the original security control baseline specification and can be applied to multiple information systems. See "Tailoring".
Platform-as-a-Service; a cloud computing model that provides hardware and software tools over the Internet, enabling developers to build, deploy, and manage applications without managing the underlying infrastructure.
A device or program that monitors data traveling over a network and can be used maliciously to capture and analyze traffic.
See "Organization-defined control parameter".
A business entity involved with another in a joint venture or partnership, where trust and security are pivotal.
A tool or script that extracts passwords stored or processed on a computer system.
A security vulnerability that allows an attacker to access files on a server that are not intended to be accessible.
A test methodology in which assessors, typically working under specific constraints, attempt to circumvent or defeat the security features of a system.
This domain refers to all individuals working for the organization in any role, including employees, contractors, and temporary staff.
A mode of system operation in which information of different sensitivities is processed at distinctly different times by the same system with the system being properly purged or sanitized between periods.
Information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual.
The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities that require trustworthiness.
A type of social engineering attack often disguised as legitimate communication, aimed at stealing user data, including login credentials and credit card numbers.
An electronic system that controls the ability of people or vehicles to enter a protected area by means of authentication and authorization at access control points.
Physical actions encompass deliberate threats that involve proximity, possession, or force. Includes theft, tampering, snooping, sabotage, local device access, assault, etc. intentionallly perpetrated by a human actor.
Measures and protocols designed to prevent unauthorized physical access to facilities, equipment, and assets, including surveillance, access controls, barriers, and environmental safeguards.
An operation or set of operations performed upon personally identifiable information that can include, but is not limited to, the collection, retention, logging, generation, transformation, use, disclosure, transfer, and disposal of personally identifiable information.
The requirements for how personally identifiable information can be processed or the conditions under which personally identifiable information can be processed.
A document that identifies tasks that need to be accomplished. It details resources required to accomplish the elements of the plan, milestones for meeting the tasks, and the scheduled completion dates for the milestones.
This domain refers to the underlying hardware and software environments on which applications and services are hosted and operated. This can include operating systems, databases, cloud services, and virtual machine environments.
A system component that can communicate with and be added to or removed from a system or network and that is limited to data storage—including text, video, audio or image data—as its primary function (e.g., optical discs, external or removable hard drives, external or removable solid-state disk drives, magnetic or optical tapes, flash memory devices, flash memory cards, and other external or removable disks).
The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect (FIPS Publication 199 low); a serious adverse effect (FIPS Publication 199 moderate); or a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals.
Reducing a vulnerability.
Primary assets include all the core business processes and functions as well as Services provided to external parties, as well as the Information and Data serving business processes and/or activities of the organisation
The principle of ensuring that individuals’ personal and sensitive data is collected, stored, and processed securely and transparently, in compliance with privacy laws and with respect for user consent and rights.
Individual, group, or organization responsible for ensuring that the system privacy requirements necessary to protect individuals’ privacy are adequately addressed in all aspects of enterprise architecture including reference models, segment and solution architectures, and information systems processing PII.
An embedded, integral part of the enterprise architecture that describes the structure and behavior for an enterprise’s privacy protection processes, technical measures, personnel and organizational sub-units, showing their alignment with the enterprise’s mission and strategic plans.
The administrative, technical, and physical safeguards employed within an agency to ensure compliance with applicable privacy requirements and manage privacy risks.
The assessment of privacy controls to determine whether the controls are implemented correctly, operating as intended, and sufficient to ensure compliance with applicable privacy requirements and manage privacy risks. A privacy control assessment is both an assessment and a formal document detailing the process and the outcome of the assessment.
The set of privacy controls selected based on the privacy selection criteria that provide a starting point for the tailoring process.
A domain that implements a privacy policy.
An analysis of how information is handled to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy; to determine the risks and effects of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of information in identifiable form in an electronic information system; and to examine and evaluate protections and alternate processes for handling information to mitigate potential privacy concerns. A privacy impact assessment is both an analysis and a formal document detailing the process and the outcome of the analysis.
Information that describes the privacy posture of an information system or organization.
A formal document that details the privacy controls selected for an information system or environment of operation that are in place or planned for meeting applicable privacy requirements and managing privacy risks, details how the controls have been implemented, and describes the methodologies and metrics that will be used to assess the controls.
The privacy posture represents the status of the information systems and information resources (e.g., personnel, equipment, funds, and information technology) within an organization based on information assurance resources (e.g., people, hardware, software, policies, procedures) and the capabilities in place to comply with applicable privacy requirements and manage privacy risks and to react as the situation changes.
A formal document that provides an overview of an agency’s privacy program, including a description of the structure of the privacy program, the resources dedicated to the privacy program, the role of the Senior Agency Official for Privacy and other privacy officials and staff, the strategic goals and objectives of the privacy program, and the program management controls and common controls in place or planned for meeting applicable privacy requirements and managing privacy risks.
A requirement that applies to an information system or an organization that is derived from applicable laws, executive orders, directives, policies, standards, regulations, procedures, and/or mission/business needs with respect to privacy. Note: The term privacy requirement can be used in a variety of contexts from high-level policy activities to low-level implementation activities in system development and engineering disciplines.
The misuse of elevated access rights or privileges to perform unauthorized actions within a computer system.
Access rights granted to users allowing them to perform administrative-level tasks and access sensitive system components.
A system account with the authorizations of a privileged user.
A human-initiated command executed on a system that involves the control, monitoring, or administration of the system, including security functions and associated security-relevant information.
A user that is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.
Process refers to the formal, structured methods and procedures that guide how the organization secures its technology and information assets. Processes ensure consistent implementation and enforcement of security practices.
Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services.
Wire line or fiber optic system that includes adequate safeguards and/or countermeasures (e.g., acoustic, electric, electromagnetic, and physical) to permit its use for the transmission of unencrypted information through an area of lesser classification or control.
Protected health information (PHI) is any information in the medical record or designated record set that can be used to identify an individual and that was created, used, or disclosed in the course of providing a health care service such as diagnosis or treatment.
The chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include the personnel and processes used to interact with or make modifications to the system, component, or associated data.
Information that can be openly shared with the public without any risk to security or privacy.
Everyone has access.
The architecture, organization, techniques, practices, and procedures that collectively support the implementation and operation of a certificate-based public key cryptographic system. Framework established to issue, maintain, and revoke public key certificates.
A method of sanitization that applies physical or logical techniques that render target data recovery infeasible using state of the art laboratory techniques.
A type of malware that specifically targets the volatile memory of a system to extract sensitive data such as credit card numbers.
Malicious software that locks access to user data or systems until a ransom is paid to the attacker, often accompanied by threats of data destruction.
The sending of information via a system or network using, deliberately, an incorrect route that sent the information to a wrong destination
Agreement among participating organizations to accept each other’s security assessments to reuse system resources and/or to accept each other’s assessed security posture to share information.
All recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.
Develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event.
An exercise, reflecting real-world conditions that is conducted as a simulated adversarial attempt to compromise organizational missions or business processes and to provide a comprehensive assessment of the security capabilities of an organization and its systems.
A set of design requirements on a reference validation mechanism that, as a key component of an operating system, enforces an access control policy over all subjects and objects. A reference validation mechanism is always invoked (i.e., complete mediation), tamperproof, and small enough to be subject to analysis and tests, the completeness of which can be assured (i.e., verifiable).
A trusted process explicitly authorized to re-classify and re-label data in accordance with a defined policy exception. Untrusted or unauthorized processes are such actions by the security policy.
Bodies overseeing compliance with industry-specific standards and regulations, ensuring adherence to legal and ethical practices.
A detailed action plan designed to address identified vulnerabilities, threats, or compliance gaps, specifying the steps, timelines, and responsibilities required to resolve security issues effectively.
Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network.
An attack technique that introduces harmful code into a system from a remote location to manipulate or control it.
Maintenance activities conducted by individuals communicating through an external network.
Any portable storage device that can be attached to a computer system to add or remove data, such as USB drives, CDs, and external hard drives.
An attack in which the attacker is able to replay previously captured messages (between a legitimate claimant and a verifier) to masquerade as that claimant to the verifier or vice versa.
Protection against the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized effect or gaining unauthorized access.
Non-repudiation
An entity denies being involved in an exchange with a third party or carrying out an operation. The later rejection of actions or undertakings acquired in the past.
The ability of an information system to operate under adverse conditions or stress, even if in a degraded or debilitated state, while maintaining essential operational capabilities, and to recover to an effective operational posture in a time frame consistent with mission needs.
Develop and implement the appropriate activities to take action regarding a detected cybersecurity event.
Most employees have access.
All data concerning (i) design, manufacture, or utilization of atomic weapons; (ii) the production of special nuclear material; or (iii) the use of special nuclear material in the production of energy, but shall not include data declassified or removed from the Restricted Data category pursuant to Section 142 [of the Atomic Energy Act of 1954].
The process of disassembling and analyzing a product's system, components, or software to understand how it operates or to reproduce it.
Radio Frequency Interference, unwanted noise or signals that interfere with the operation of electronic devices, affecting performance and functionality.
A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.
The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Risk management includes threat and vulnerability analyses as well as analyses of adverse effects on individuals arising from information processing and considers mitigations provided by security and privacy controls planned or in place. Synonymous with risk analysis.
An individual or group within an organization that helps to ensure that security risk-related considerations for individual systems, to include the authorization decisions for those systems, are viewed from an organization-wide perspective with regard to the overall strategic goals and objectives of the organization in carrying out its mission and business functions; and managing risk from individual systems is consistent across the organization, reflects organizational risk tolerance, and is considered along with other organizational risks affecting mission or business success.
When data is stored or processed in a data centre located in a country other than the customer country, there are numerous ways in which the change in jurisdiction could affect the security of the information.
The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes: establishing the context for risk-related activities; assessing risk; responding to risk once determined; and monitoring risk over time.
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
Accepting, avoiding, mitigating, sharing, or transferring risk to agency operations, agency assets, individuals, other organizations, or the Nation.
The level of risk or the degree of uncertainty that is acceptable to an organization.
Access control based on user roles (i.e., a collection of access authorizations that a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
A set of malicious software tools that enable unauthorized access and control over a computer system, often hidden from the user and system monitors.
An unauthorized rerouting of network traffic through a different, often malicious, route to intercept or manipulate it.
The period during which a computer program is executing.
Software-as-a-Service; a cloud computing model where software applications are hosted and delivered over the Internet, enabling users to access them from anywhere without installation or infrastructure management.
Deliberate actions aimed at damaging, destroying, or disrupting the normal functioning of a system or organization.
A process to render access to target data on the media infeasible for a given level of effort. Clear, purge, and destroy are actions that can be taken to sanitize media.
A fraudulent scheme or trick used to deceive someone into parting with money or information under false pretenses.
The activity of checking a network for connected devices and services by sending packets to various ports and interpreting the responses.
A part of tailoring guidance that provides organizations with specific considerations on the applicability and implementation of security and privacy controls in the control baselines. Considerations include policy or regulatory, technology, physical infrastructure, system component allocation, public access, scalability, common control, operational or environmental, and security objective.
Disclosure of secret data would cause serious damage to national security. This data is considered less sensitive than data classified as top secret.
The implementation of secure settings and configurations on systems, networks, and applications to reduce vulnerabilities, prevent unauthorized access, and ensure compliance with security standards.
A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization’s risk management approach.
Individual, group, or organization responsible for ensuring that the information security requirements necessary to protect the organization’s core missions and business processes are adequately addressed in all aspects of enterprise architecture including reference models, segment and solution architectures, and the resulting information systems supporting those missions and business processes.
An embedded, integral part of the enterprise architecture that describes the structure and behavior for an enterprise’s security processes, information security systems, personnel and organizational sub-units, showing their alignment with the enterprise’s mission and strategic plans. See information security architecture.
See "Security control assessment".
An abstraction that represents the basic properties or characteristics of an entity with respect to safeguarding information. Typically associated with internal data structures— including records, buffers, and files within the system—and used to enable the implementation of access control and flow control policies; reflect special dissemination, handling or distribution instructions; or support other aspects of the information security policy.
The process of determining the security category for information or a system. Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS Publication 199 for other than national security systems. See "Security category".
The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on agency operations, agency assets, individuals, other organizations, and the Nation.
The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information.
The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.
The set of minimum security controls defined for a low-impact, moderate-impact, or high-impact information system.
A domain that implements a security policy and is administered by a single authority.
The security-related features, functions, mechanisms, services, procedures, and architectures implemented within organizational information systems or the environments in which those systems operate.
The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.
The analysis conducted by qualified staff within an organization to determine the extent to which changes to the system affect the security posture of the system.
Information within the system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data.
Hardware, firmware, and software elements of a trusted computing base that implement the reference monitor concept, mediating all accesses and being protected from modification and verifiable as correct.
The means used to associate a set of security attributes with a specific information object as part of the data structure for that object.
The means used to associate a set of security attributes with objects in a human-readable form to enable organizational, process-based enforcement of information security policies.
Confidentiality, integrity, or availability as the primary goals of a security program.
A formal document that provides an overview of the security requirements for an information system or program, and describes the security controls in place or planned for meeting those requirements.
A set of criteria for the provision of security services, encompassing all aspects of security-relevant system and system component behavior.
A hardware and/or software component that performs functions such as content verification, content inspection, and malicious content checking to ensure compliance with a defined security policy.
The security status of an enterprise’s networks, information, and systems based on information assurance resources (e.g., people, hardware, software, policies) and capabilities in place to manage the defense of the enterprise and to react as the situation changes. Synonymous with security status.
A requirement levied on an information system or an organization that is derived from applicable laws, executive orders, directives, policies, standards, instructions, regulations, procedures, and/or mission/business needs to ensure the confidentiality, integrity, and availability of information that is being processed, stored, or transmitted. Note: Security requirements can be used in a variety of contexts from high-level policy activities to low-level implementation activities in system development and engineering disciplines.
A capability or function provided by an entity to support one or more security objectives.
Information within a system that impacts the operation of security functions or the provision of security services, potentially leading to a failure to enforce the security policy.
A control parameter allowing an organization to select a value from predefined options provided as part of the control or control enhancement.
A control parameter that allows an organization to select a value from a list of pre-defined values provided as part of the control or control enhancement (e.g., selecting to either restrict an action or prohibit an action). See "Assignment statement" and "Organization-defined control parameter".
The senior official, designated by the head of each agency, who has vision into all areas of the organization and is responsible for alignment of information security management processes with strategic, operational, and budgetary planning processes.
The official responsible for managing an organization's information security program, serving as the liaison to the agency's authorizing officials and information security personnel.
A high-ranking official responsible for organization-wide privacy, ensuring compliance with applicable privacy laws and managing privacy risks.
Refer to senior agency information security officer.
Sensitive But Unclassified (SBU) data is data that is not considered vital to national security, but its disclosure would do some harm. Many agencies classify data they collect from citizens as SBU. In Canada, the SBU classification is referred to as protected (A, B, C).
Information that concerns or derives from intelligence sources, which requires handling within formal access control systems established by the Director of National Intelligence.
The alteration of the order of the messages sent. The idea is that the new order changes the meaning of the group of messages, prejudicing the integrity of the affected data.
Design and development principles for creating interoperable services that are well-defined business functions, reusable as software components.
This domain encompasses all internal and external product and service offerings provided by an organization, including both tangible products and intangible services, whether used within the organization or offered to customers.
A security vulnerability where a user's session is hijacked by fixing an established session identifier, typically on a web application.
The use of algorithms or tools to predict the validity of session identifiers based on patterns or previously observed sessions.
A form of network attack in which a valid data transmission is maliciously or fraudulently repeated or delayed.
A control applied to an information system in part as a common control and in part as a system-specific control.
The unauthorized observation or monitoring of someone's data or behavior, often without their knowledge.
The exploitation of a web application by injecting an array with too many elements or malformed elements via a SOAP interface, causing disruption or data leakage.
Social tactics employ deception, manipulation, intimidation, etc to exploit the human element, or users, of information assets. Includes pretexting, phishing, blackmail, threats, scams, etc.
Taking advantage of the good will of some persons to make them carry out activities of interest to a third party.
Online platforms and applications that enable users to create, share, and exchange content, ideas, and information through virtual communities and networks, often presenting security and privacy risks.
Programs and associated data that can be dynamically written or modified during execution by the user of the system.
Unsolicited bulk messages sent through electronic messaging systems.
A program with specific classification and protection requirements exceeding those normally required for information at the same classification level.
Injection of content that manipulates the logic of an application through the insertion of unexpected elements or components.
A document that specifies, in a complete, precise, verifiable manner, the requirements, design, behavior, or other characteristics of a system or component and often the procedures for determining whether these provisions have been satisfied. See "Specification requirement".
A type of requirement that provides a specification for a specific capability that implements all or part of a control and that may be assessed (i.e., as part of the verification, validation, testing, and evaluation processes).
Allowing a remote user to simultaneously maintain a non-remote connection with a system while communicating over an external network.
Authenticity
Software installed secretly to gather information on individuals or organizations without their knowledge, categorized as malicious code.
Malicious software designed to secretly record keystrokes (keylogger) or gather other private information (spyware) from a target's computer.
An attack technique that involves inserting malicious SQL statements into an input field to be executed by the backend database.
Short for SQL Injection, it refers to the same technique as SQL injection, exploiting vulnerabilities in data-driven applications.
Server-Side Includes injection, a web security vulnerability that allows an attacker to inject malicious code into a web page.
Deliberate absence from the work post: such as strikes, labour absenteeism, unjustified absences, the blocking of accesses, etc.
A type of requirement that represents an action that is performed operationally or during system development.
The Strategic Plan is a document that describes the goals of an organization. It also provides guidance for planning activities to achieve those goals. The plan can be used by management as well as employees.
These are risks that arise from decisions related to the long-term business strategies of an organization. They are associated with factors that might prevent the company from achieving its objectives, such as adverse business decisions, improper implementation of strategies, or unforeseen market developments.
Only top management have access or some other resources based on project need.
An individual or process that initiates information flow among objects or changes to system state, with potential impacts on security.
Law enforcement authorities may ask operators of IT infrastructures to provide information pertaining to criminal cases, or information may have to be provided during civil lawsuits.
A major component of an information system that performs specific functions and consists of information, IT, and personnel.
An organization or individual that provides a product or service to another entity within a supply chain, including developers, manufacturers, integrators, and vendors.
Policies and measures to ensure that suppliers and third-party partners adhere to security standards and practices, minimizing risks associated with external dependencies and supply chain vulnerabilities.
The network of organizations involved in the production, delivery, and sale of a product, from production to distribution.
Entities involved in designing, manufacturing, delivering, and supporting products and services in a supply chain.
Potential threats and vulnerabilities introduced by suppliers and their products, impacting an organization's security posture.
The process of identifying and evaluating supply chain threats and vulnerabilities to understand potential impacts.
The process of managing risks introduced by suppliers and their products throughout the lifecycle of the supply chain.
Supporting assets include Hardware, devices and equipment, software and applications, roles, locations and utilities as well as the organisational infrastructure (e.g. policies, procedures and supporting ICT Services)
An organized assembly of resources and procedures united to accomplish a set of specific functions, often including complex systems such as industrial controls and telecommunications.
See "Authorization boundary".
A discrete component of a system that includes hardware, software, or firmware, and is considered a building block of the system.
The scope of activities associated with a system, encompassing the system’s initiation, development and acquisition, implementation, operation and maintenance, and ultimately its disposal that instigates another system initiation.
Member of a set of elements that constitute a system. Note: A system element can be a discrete component, product, service, subsystem, system, infrastructure, or enterprise.
Records controlled by an agency from which information is retrieved by a unique identifier, subject to privacy protections.
A notice issued by an agency describing the existence and characteristics of a system of records, detailing how information is stored, used, and managed.
Official responsible for the overall procurement, development, integration, modification, operation, and maintenance of a system.
Individual with assigned responsibility for maintaining the appropriate operational privacy posture for a system or program.
Individual with assigned responsibility for maintaining the appropriate operational security posture for a system or program.
A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems. See "Security plan".
A capability provided by a system that facilitates information processing, storage, or transmission.
An individual or (system) process acting on behalf of an individual that is authorized to access a system.
Risk that arises through the loss of confidentiality, integrity, or availability of information or systems and that considers impacts to the organization (including assets, mission, functions, image, or reputation), individuals, other organizations, and the Nation. See "Risk".
A security or privacy control for an information system that is implemented at the system level and is not inherited by any other information system.
An engineering discipline whose responsibility is creating and executing an interdisciplinary process to ensure that the customer and all other stakeholder needs are satisfied in a high-quality, trustworthy, cost-efficient, and schedule-compliant manner throughout a system’s entire life cycle.
Individual assigned responsibility for conducting systems privacy engineering activities.
Process that captures and refines privacy requirements and ensures their integration into information technology component products and information systems through purposeful privacy design or configuration.
Individual assigned responsibility for conducting systems security engineering activities.
A specialty engineering field strongly related to systems engineering. It applies scientific, engineering, and information assurance principles to deliver trustworthy systems that satisfy stakeholder requirements within their established risk tolerance.
Tactical plans are usually short-term in nature. They provide direction on how to accomplish specific objectives within a specified time frame. A tactical plan may include detailed schedules or instructions on how to complete tasks.
Tactical risks are associated with decisions made to achieve short-term objectives. They are typically linked with the methods, tactics, and operational plans used to implement broader strategies. These risks can arise from operational challenges, competitive pressures, or short-term market fluctuations.
A set of controls that result from the application of tailoring guidance to a control baseline. See "Tailoring".
The process by which security control baselines are modified by: identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating security controls, assigning specific values to organization-defined security control parameters, supplementing baselines with additional security controls or control enhancements, and providing additional specification information for control implementation.
An intentional but unauthorized act resulting in the modification of a system, components of systems, its intended behavior, or data.
The intentional alteration of the operation of hardware to obtain an indirect benefit when an authorised person uses it
The intentional alteration of the operation of a program to obtain an indirect benefit when an authorised person uses it
Theft of equipment directly causes a lack of resources to provide the services, that is, non-availability
Theft of media directly causes a lack of resources to provide the services, that is, non-availability
Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
The systematic process of identifying, assessing, prioritizing, and mitigating threats and vulnerabilities to reduce cybersecurity risks and ensure ongoing protection of systems, data, and networks.
Formal description and evaluation of threat to an information system.
A form of risk assessment that models aspects of the attack and defense sides of a logical entity, such as a piece of data, an application, a host, a system, or an environment.
The intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability. See "Threat agent".
Person, who attacks computer systems merely to prove himself, in order to learn or experiment.
Disclosure of top secret data would cause severe damage to national security.
Without needing to analyse the contents of communications, the attacker can reach conclusions based on the analysis of the origin, destination, volume and frequency of the exchanges
The state that exists when information is being electronically sent from one location to one or more other locations.
A mechanism by which a user (through an input device) can communicate directly with the security functions of the system with the necessary confidence to support the system security policy. This mechanism can only be activated by the user or the security functions of the system and cannot be imitated by untrusted software.
The attribute of a person or enterprise that provides confidence to others of the qualifications, capabilities, and reliability of that entity to perform specific tasks and fulfill assigned responsibilities.
The degree to which an information system (including the information technology components that are used to build the system) can be expected to preserve the confidentiality, integrity, and availability of the information being processed, stored, or transmitted by the system across the full range of threats.
An information system that is believed to be capable of operating within defined levels of risk despite the environmental disruptions, human errors, structural failures, and purposeful attacks that are expected to occur in its environment of operation.
An attacker manages to access the system’s resources without authorisation for doing so, typically taking advantage of a failure in the identification and authorisation system.
Unclassified data is data that has no classification or is not sensitive.
The misuse of website URL redirection and rewriting functionality, typically to redirect users to phishing or malware sites without their knowledge.
Individual, or (system) process acting on behalf of an individual, authorized to access a system.
Customers need to ensure with the providers what data can or cannot be used by them for secondary purposes. It includes data that can be mined directly from user data by providers or indirectly based on user behaviour (clicks, etc.)
Provides goods or services essential to the company's operations, ranging from one-time purchases to long-term supply agreements.
A security breach that occurs when a virtual machine 'breaks out' of its encapsulation and interacts directly with the host machine's operating system.
Protected information system link utilizing tunneling, security controls, and endpoint address translation giving the impression of a dedicated line.
Limited rights or permissions granted to a visitor within a computer system or network, typically less than those available to regular users.
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Note: The term weakness is synonymous for deficiency. Weakness may result in security and/or privacy risks.
See "Vulnerability assessment".
Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
The process of transferring data from the internet to a user's device, often referring to software, documents, or other digital materials.
A type of attack where malware or unwanted software is automatically downloaded and executed from a website without the user's consent.
The interception and recording of phone calls or Internet communications by a third party without the consent of the individuals being monitored.
A self-replicating malware that spreads copies of itself from computer to computer, often without user intervention.
An XML-based attack where an excessively large number of attributes are added to an XML document, causing a system to consume excessive resources.
A type of XML attack that involves expanding entities within an XML document to consume resources or cause a denial of service.
Attacks where malicious entities are embedded in an XML document, which are processed by the application to access unauthorized external systems.
The malicious manipulation of XML input to an application in order to alter backend SQL statements or other commands that are dynamically generated from XML input.
The injection of malicious XPath queries into a web application that uses those queries to construct XML searches for data.
An injection flaw wherein an attacker can execute arbitrary XQuery commands against a data source that is manipulated through XML.
A vulnerability where attackers inject malicious scripts into web pages to steal data or hijack user sessions.
Bring the program, the work and the proof together in one workspace.