home/dictionary/vulnerability scanning parameter

vulnerability scanning parameter

nounverified·updated Sep 1, 2026

A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.
DR-088 backfill from the noun definition column