home/dictionary/system behavior

system behavior

nounverified·updated Sep 1, 2026

The observable and operational characteristics of a computing system — encompassing its processes, configurations, resource usage, and responses to inputs — that collectively define how it functions at runtime. In security and compliance contexts, it is used as a reference baseline: controls are designed to preserve expected system behavior (e.g., by restricting commands that could alter it) or to detect when behavior deviates from that baseline, which may indicate compromise, misconfiguration, or unauthorized privileged action. Authority documents treat nominal or "typical" system behavior as a well-defined pool from which execution profiles are drawn, against which anomalous activity is measured. Frameworks such as CIS Benchmarks use the phrase directly, noting that hardening configurations "can significantly alter system behavior," and post-compromise threat models describe attackers modifying kernel parameters or device interfaces to alter system behavior in ways that are difficult to distinguish from legitimate administration.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
The observable and operational characteristics of a computing system — encompassing its processes, configurations, resource usage, and responses to inputs — that collectively define how it functions at runtime. In security and compliance contexts, it is used as a reference baseline: controls are designed to preserve expected system behavior (e.g., by restricting commands that could alter it) or to detect when behavior deviates from that baseline, which may indicate compromise, misconfiguration, or unauthorized privileged action. Authority documents treat nominal or "typical" system behavior as a well-defined pool from which execution profiles are drawn, against which anomalous activity is measured. Frameworks such as CIS Benchmarks use the phrase directly, noting that hardening configurations "can significantly alter system behavior," and post-compromise threat models describe attackers modifying kernel parameters or device interfaces to alter system behavior in ways that are difficult to distinguish from legitimate administration.
DR-088 backfill from the noun definition column