non-security information
The phrase is the straightforward logical complement of the defined term "security information" — defined by NIST SP 800-37 Rev. 2 as information within a system that can potentially impact the operation of security functions or the provision of security services. "Non-security information" therefore denotes any information residing in or processed by a system that does **not** meet that threshold — content whose compromise, modification, or disclosure would not affect security enforcement mechanisms, security policy, or the isolation of security-relevant code and data. In context it serves as a residual or exclusionary category, used to draw a boundary around the scope of a security control or analysis by naming what falls outside it, rather than labeling a substantive class of data in its own right.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- non-security informations
- possessive
- non-security information's
- pluralpossessive
- non-security informations'