📚 Cybersecurity Glossary
Your comprehensive guide to cybersecurity, compliance, and CMMC terminology. Search or browse through hundreds of definitions.
A
Access
Attribute Based Access ControlABAC
Access ControlAC
- Obtain and use information and related information processing services; and
- Enter specific physical facilities (e.g., federal buildings, military establishments, border crossing entrances, etc.).
Access Control ListACL
Access Control Policy
Access Profile
Activity/Activities
Administrative Safeguards
Advanced Encryption StandardAES
Advanced Persistent ThreatAPT
- Pursues its objectives repeatedly over an extended period of time
- Adapts to defenders’ efforts to resist it; and
- Is determined to maintain the level of interaction needed to execute its objectives
Adversarial Assessment
Adversary
Aerospace Industries AssociationAIA
Air Gap
Alert
Anti-Malware Tools
Anti-Spyware Software
Anti-Tamper
Anti-Virus Software
Application Programming InterfaceAPI
Assessment
Assessment Scope
Asset
Asset Category
- Contractor Risk Managed Asset
- CUI Asset
- Out-of-Scope Asset
- Security Protection Asset
- Specialized Asset
Asset Custodian
Asset ManagementAM
Asset Owner
Asset Types
- People – employees, contractors, vendors, and external service provider personnel
- Technology – servers, client computers, mobile devices, network appliances, VoIP devices, applications, virtual machines, and database systems
- Facilities – physical office locations, satellite offices, server rooms, datacenters, manufacturing plants, and secured rooms
- External Service Provider (ESP) – external people, technology, or facilities that the organization utilizes including Cloud Service Providers, Managed Service Providers, Managed Security Service Providers
Attack Surface
Audit
Audit and AccountabilityAU
Audit Log
Audit Record
Australian Cyber Security CentreACSC
Authentication
Authenticator
Authoritative Source
Authorization
Authorized User
Availability
Awareness
Awareness and TrainingAT
B
Backup
Baseline
Baseline Configuration
Baseline Security
Baselining
Blacklist
Blacklisting Software
Blue Team
Breach
Bring Your Own DeviceBYOD
C
Cybersecurity Capability Maturity ModelC2M2
CMMC Third-Party Assessment OrganizationC3PAO
Security AssessmentCA
Corrective Action RequestCAR
Certified CMMC AssessorCCA
Certified CMMC InstructorCCI
Certified CMMC ProfessionalCCP
Covered Defense InformationCDI
Council of Economic AdvisorsCEA
Certified Ethical HackerCEH
Computer Emergency Response TeamCERT
Code of Federal RegulationsCFR
Configuration ItemCI
Chief Information OfficerCIO
Center for Internet SecurityCIS
Cybersecurity and Infrastructure Security AgencyCISA
Configuration ManagementCM
CMMC
CMMC Accreditation BodyCMMC-AB
Computer Numeric ControlCNC
Committee on National Security Systems DirectiveCNSSD
Communications SecurityCOMSEC
Consequence
Consumer
Container
Context Aware
Continuity of Operations
Continuous
Continuous Monitoring
Contractor Risk Managed AssetsCRMA
Children's Online Privacy Protection ActCOPPA
Control
Controlled Unclassified InformationCUI
Controlled Technical InformationCTI
CUI AssetCUIA
Critical Program InformationCPI
Cryptographic Hashing Function
Cryptographic Module Validation ProgramCVMP
Cybersecurity FrameworkCSF
Center for Strategic and International StudiesCSIS
Cloud Service ProviderCSP
Common Vulnerabilities and ExposuresCVE
Common Weakness EnumerationCWE
Customer Information
Cybersecurity
Cybersecurity Event
D
Data Loss PreventionDLP
DIB Collaborative Information Sharing EnvironmentDCISE
Defense Contract Management AgencyDCMA
Distributed Control SystemDCS
Defense Federal Acquisition Regulation SupplementDFARS
Defense Industrial BaseDIB
Defense Industrial Base Cybersecurity Assessment CenterDIBCAC
Defense Industrial Base NetworkDIBNET
Defined Process
Deidentified
Demilitarized ZoneDMZ
Dependency
Device
Device Health CheckDHC
Domain
Domain Key Identified MailDKIM
Domain-based Message Authentication, Reporting, and ConformanceDMARC
Domain Name SystemDNS
Domain Name System SecurityDNSSEC
Department of DefenseDoD
Department of WarDoW
Department of Defense InstructionDoDI
Derived PIV Credential IssuersDPCI
Digital Versatile DiscDVD
E
Enclave
Encryption
Encryption Policies
Endorse
Enterprise
Enterprise Architecture
Enterprise Mission Assurance Support ServiceeMASS
Environment of Operations
Establish and Maintain
Event
Event Correlation
Exercise
Executive OrderE.O.
External Serial Advanced Technology AttachmenteSATA
External Service ProviderESP
F
Facility
Frequently Asked QuestionFAQ
Federal Acquisition RegulationFAR
Federal Bureau of InvestigationFBI
Federal Contract InformationFCI
Fiber Distributed Data InterfaceFDDI
Full Disk EncryptionFDE
Federal Risk and Authorization Management ProgramFedRAMP
Federally Funded Research and Development CenterFFRDC
Federated Trust
Federation
Federal Information Processing StandardFIPS
FIPS 140-2 and 140-3
Firewall
Flash Drive
Full-Time EquivalentFTE
File Transfer ProtocolFTP
G
General Data Protection RegulationGDPR
Government Property
H
Health Insurance Portability and Accountability ActHIPAA
Homeland Security Presidential DirectiveHSPD
Hashing
High-Value AssetHVA
High-Value Service
Honey Pot
I
Identification
Identity
Identity Management System
Identity, Credential, and Access ManagementICAM
Identity-Based Access ControlIBAC
Incident
Incident Handling
Incident Stakeholder
Industrial Control SystemICS
Industrial Internet of ThingsIIoT
Information Flow
Information SystemIS
Information System Component
Insider
Insider Threat
Integrity
Internet of ThingsIoT
Inventory
L
Law, Regulation, or Government-Wide PolicyLRGWP
Least Privilege
Life Cycle
M
Maintenance
Malicious Code
Malware
Managed Services ProviderMSP
Managed Security Services ProviderMSSP
Media
Media Sanitization
Mobile Code
Mobile Device
Monitor
Multifactor AuthenticationMFA
N
National Institute of Standards and TechnologyNIST
Natural Person
Nonpublic Information
O
Ongoing Basis
Out-of-Scope AssetsOoSA
Operational TechnologyOT
Organization
Organization Seeking CertificationOSC
Organizational System(s)
Organizationally Defined
P
Patch
Patching
Penetration Testing
Periodically
Person
Personally Identifiable InformationPII
Phishing
PII Subject
Plan
Plan of Action and MilestonesPOA&M
Policy
Portable Storage Device
Practice
Privilege
Privileged Access
Privileged Account
Privileged User
Procedure
Process
Proxy
Publicly Available Information
R
Responsible, Accountable, Consulted, and InformedRACI
Real Time
Recovery
Red Team
Red Teaming
Regularly
Remote Access
Removable Media
Reporting (Forensics)
Residual Risk
Resilience
Restricted Information Systems
Risk
Risk Analysis
Risk Assessment
Risk Based Authentication
Risk Categories
Risk ManagementRM
Risk Management Criteria
Risk Mitigation
Risk Mitigation Plan
Risk Sources
Risk Tolerance
Root Cause Analysis
Root Directory
S
Specialized AssetSA
Safeguards
Sandboxing
Scanning
Scope
Security Control Assessment
Security Control Inheritance
Security Domain
Security Incident and Event ManagementSIEM
Security Operations CenterSOC
Security Policy
Security Protection AssetsSPA
Senior Executive Team
Sensitive Information
Separation of Duties
Service Continuity Plan
Service Responsibility MatrixSRM
Session
Session Key
SHA-256
Single Sign OnSSO
Situational AwarenessSA
Small and Medium BusinessesSMB
Software
SPAM
Specialized Assets
Split Tunneling
Spyware
Supplier Performance Risk SystemSPRS
Standard
Standard Process
Store
Subnetwork
Supply Chain
Supply Chain Attack
Supply Chain Risk ManagementSCRM
Sustain
System Assets
System Boundary
System Integrity
System Interconnection
System Security PlanSSP
T
Two-Factor Authentication2FA
Tampering
Test Equipment
Third Party
Third Party Service Provider
Threat
Threat Actor
Threat Intelligence
Threat Monitoring
Transmit
Trigger
Trojan Horse
Tunneling
U
Unauthorized Access
Universal Serial BusUSB
User
V
Virus
Vulnerability
Vulnerability Assessment
Vulnerability Management
Vulnerability Scan
W
Whitelist
No results found
Try adjusting your search terms or browse by letter above