Glossary · MWE Terms · A
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
audit policynounMWEA description of the standards and guidelines an organization uses for going through external audits or conducting internal audits.verified
audit procedurenounMWEA detailed description of the steps necessary to implement an audit in conformance with applicable standards.verified
Audit programnounMWEThe audit policies, procedures, and strategies that govern the audit function, including Information Technology (IT) audit.verified
Audit Reduction ToolsnounMWEPreprocessors designed to reduce the volume of audit records to facilitate manual review. Before a security review, these tools can remove many audit records known to have little security significance. These tools generally remove records generated by specified classes of events, such as records generated by nightly backups.verified
audit reportnounMWEA report issued by an independent Auditor that expresses an opinion about whether the financial statements present fairly a company's financial position, operating results, and cash flows in accordance with generally accepted accounting principles.verified
Audit ReviewnounMWEThe assessment of an information system to evaluate the adequacy of implemented security controls, assure that they are functioning properly, identify vulnerabilities, and assist in implementation of new security controls where required. This assessment is conducted annually or whenever significant change has occurred and may lead to recertification of the information system.verified
audit schedulenounMWEThe dates on which a planned, official examination of a system or equipment will be performed.verified
audit scopenounMWEDetermination of the range of the activities and the period (months or years) of records that are to be subjected to an audit examination.verified
audit staffnounMWEAll people who are employed by an organization to perform audit activities.verified
audit standardnounMWERules prescribed for auditors by various national and international organizations such as the Auditing Practices Board (in the UK) and the Auditing Standards Board (in the US).verified
Audit trailnounMWEA chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security relevant transaction from inception to final result.verified
audit universenounMWEAn inventory of audit areas that is compiled and maintained to identify areas for audit during the audit planning process.verified
Audit Work PapernounMWEThis record category contains records of working papers that are vital to the successful accomplishment of all audit assignments performed.verified
Audited AccountnounMWEan inspection of the accounting procedures and records by a trained accountant or CPAverified
Auditory AphasianounMWEan impairment in understanding spoken language that is not attributable to hearing lossverified
Auditory ApparatusnounMWEall of the components of the organ of hearing including the outer and middle and inner earsverified
Auditory AreanounMWEthe cortical area that receives auditory information from the medial geniculate bodyverified
Auditory CanalnounMWEeither of the passages in the outer ear from the auricle to the tympanic membraneverified
Auditory CenternounMWEthe part of the brain (in a fold of the cerebral cortex of the temporal lobe on both sides of the brain) that receives impulses from the ear by way of the auditory nerveverified
Auditory CortexnounMWEthe cortical area that receives auditory information from the medial geniculate bodyverified
Auditory HyperesthesianounMWEabnormal acuteness of hearing due to increased irritability of the sensory neural mechanismverified
Auditory MeatusnounMWEeither of the passages in the outer ear from the auricle to the tympanic membraneverified
Auditory NervenounMWEa composite sensory nerve supplying the hair cells of the vestibular organ and the hair cells of the cochleaverified
Auditory OssiclenounMWEossicles of the middle ear that transmit acoustic vibrations from the eardrum to the inner earverified
Auditory TubenounMWEeither of the paired tubes connecting the middle ears to the nasopharynxverified
Auricula AtriinounMWEa small conical pouch projecting from the upper anterior part of each atrium of the heartverified
Auricular PointnounMWEthe craniometric point at the center of the opening of the external acoustic meatusverified
Austenitic Manganese SteelnounMWEa steel with a relatively large component (10-14%) of manganeseverified
Austenitic SteelnounMWEsteel that has enough nickel and chromium or manganese to retain austenite at atmospheric temperaturesverified
Authentication CodenounMWEA cryptographic checksum based on an Approved security function (also known as a Message Authentication Code [MAC]).verified
authentication controlnounMWEOne of several systems which restrict user access to a network.verified
authentication mechanismnounMWEHardware or software-based mechanisms that forces users, devices, or processes to prove their identity before accessing data on an information system.verified
authentication methodnounMWEA method of Verifying the identity of a user, such as a challenge password or a digital certificate.verified
Authentication ModenounMWEA block cipher mode of operation that can provide assurance of the authenticity and, therefore, the integrity of data.verified
Authentication PeriodnounMWEThe maximum acceptable period between any initial authentication process and subsequent reauthentication processes during a single terminal session or during the period data is being accessed.verified
authentication procedurenounMWEThe documented steps necessary to authenticate the identity of an entity through the use of credentials in order to gain access to the system.verified
Authentication ProtocolnounMWEA defined sequence of messages between a Claimant and a Verifier that demonstrates that the Claimant has possession and control of a valid token to establish his/her identity, and optionally, demonstrates to the Claimant that he or she is communicating with the intended Verifier.verified
Authentication TagnounMWEA pair of bit strings associated to data to provide assurance of its authenticity.verified
Authentication TokennounMWEAuthentication information conveyed during an authentication exchange.verified
Authoring LanguagenounMWEsoftware that can be used to develop interactive computer programs without the technically demanding task of computer programmingverified
Authoritarian RegimenounMWEa government that concentrates political power in an authority not responsible to the peopleverified
Authoritarian StatenounMWEa government that concentrates political power in an authority not responsible to the peopleverified
Authorization (ACH)nounMWEA written or oral agreement between the originator and a receiver that allows payments processed through the ACH network to be deposited in, or withdrawn from, the receiver's account at a financial institution.verified
Authorization BoundarynounMWEAll components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.verified
authorization recordnounMWEA document or identifier which provides evidence of authorization.verified
Authorization to operatenounMWEThe official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.verified
authorizations to executenounMWEA compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.verified
authorized accessnounMWEAccess to system components that (a) has been approved by a person designated to do so by management and (b) does not compromise segregation of duties, confidentiality commitments, or otherwise increase risk to the system beyond the levels approved by management (that is, access is appropriate).verified
authorized devicenounMWEA computer device that the organization has authorized to be used and connected to the system.verified
authorized personnounMWEThis role is focused on a person who has been given permission to do something by an authority. Any individual who has been granted permission to do something on behalf of their organization should be assigned to this role.verified
authorized personnelnounMWEThis role is focused on employees who are granted access to the organizations assets, information, and/or certain areas, or permitted to conduct certain work. Any individual who is sanctioned by management should be assigned to this role.verified
authorized privilegenounMWE** A set of elevated access rights, permissions, or capabilities that have been formally granted to a user, role, or process by an authorizing entity within a defined access-control policy. The expression functions as the collective object of access-governance controls — particularly least privilege and separation of duties — which exist precisely because such rights, though legitimately held, remain a vector for insider abuse or insider threat if concentrated without checks. The principle of least privilege is applied with the goal of authorized privileges no higher than necessary to accomplish required organizational missions or business functions. In practice, separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion — making "authorized privileges" the specific threat surface that controls such as role separation, audit logging of privileged-function execution, and periodic access reviews are designed to govern.
**VERDICT:** COMPOSITIONAL
The expression is not a defined term of art with its own glossary entry in NIST SP 800-53, NIST SP 800-171, or related authority documents. It is a tverified
Authorized SharesnounMWEthe maximum number of shares authorized under the terms of a corporation's articles of incorporationverified
Authorized StocknounMWEthe maximum number of shares authorized under the terms of a corporation's articles of incorporationverified
authorized usernounMWEA person who has the authority or permission to manage access or make changes to an account.verified
Authorized VendornounMWEManufacturer of information assurance equipment authorized to produce quantities in excess of contractual requirements for direct sale to eligible buyers. Eligible buyers are typically U.S. government organizations or U.S. government contractors.verified
Authorized Vendor ProgramnounMWEProgram in which a vendor, producing an information systems security (INFOSEC) product under contract to NSA, is authorized to produce that product in numbers exceeding the contracted requirements for direct marketing and sale to eligible buyers. Eligible buyers are typically U.S. government organizations or U.S. government contractors. Products approved for marketing and sale through the AVP are placed on the Endorsed Cryptographic Products List (ECPL).verified
Authorizing OfficialnounMWEA senior (federal) official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.verified
Authorizing Official Designated RepresentativenounMWEAn organizational official acting on behalf of an authorizing official in carrying out and coordinating the required activities associated with security authorization.verified
Auto LimitationnounMWEsocial control achieved as a manifestation of self-will or general consentverified
Autoimmune DiseasenounMWEany of a large group of diseases characterized by abnormal functioning of the immune system that causes your immune system to produce antibodies against your own tissuesverified
Autoimmune DisordernounMWEany of a large group of diseases characterized by abnormal functioning of the immune system that causes your immune system to produce antibodies against your own tissuesverified
Automated Clearing House (ACH)nounMWEAn electronic clearing system in which a data processing center handles payment orders that are exchanged among financial institutions, primarily via telecommunications networks. ACH systems process large volumes of individual payments electronically. Typical ACH payments include salaries, consumer and corporate bill payments, interest and dividend payments, and Social Security payments.verified