Dictionary · NIST SP 800-61
L2 — definitions grouped by regulatory framework.
Nouns
15 senses- Baselining
Monitoring resources to determine typical utilization patterns so that significant deviations can be detected.
- Computer Security Incident Response Team
A capability set up for the purpose of assisting in responding to computer security-related incidents; also called a Computer Incident Response Team (CIRT) or a CIRC (Computer Incident Response Center, Computer Incident Response Capability).
- precursor
A sign that an attacker may be preparing to cause an incident.
- event
Any observable occurrence in a network or system.
- False Positive
An alert that incorrectly indicates that malicious activity is occurring.
- Incident Handling
The mitigation of violations of security policies and recommended practices.
- incident
A violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.
- indicator
A sign that an incident may have occurred or may be currently occurring.
- Intrusion Detection and Prevention System
Software that automates the process of monitoring the events occurring in a computer system or network and analyzing them for signs of possible incidents and attempting to stop detected possible incidents.
- Malware
A virus, worm, Trojan horse, or other code-based malicious entity that successfully infects a host.
- Profiling
Measuring the characteristics of expected activity so that changes to it can be more easily identified.
- signature
A recognizable, distinguishing pattern associated with an attack, such as a binary string in a virus or a particular set of keystrokes used to gain unauthorized access to a system.
- Social engineering
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.
- threat
The potential source of an adverse event.
- vulnerability
A weakness in a system, application, or network that is subject to exploitation or misuse.