Glossary · MWE Terms · C
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
cyber infrastructurenounMWEIncludes electronic information and communications systems and services and the information contained in these systems and services. Information and communications systems and services are composed of all hardware and software that process, store, and communicate information, or any combination of all of these elements. Processing includes the creation, access, modification, and destruction of information. Storage includes paper, magnetic, electronic, and all other media types. Communications include sharing and distribution of information. For example: computer systems; control systems (e.g., supervisory control and data acquisition–SCADA); networks, such as the Internet; and cyber services (e.g., managed security services) are part of cyber infrastructure.verified
cyber maturity modelnounMWEA mechanism to have cyber resilience controls, methods and processes assessed according to management best practice, against a clear set of external benchmarks.verified
Cyber OperationsnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Performs activities to gather evidence on criminal or foreign intelligence entities in order to mitigate possible or real-time threats, protect against espionage or insider threats, foreign sabotage, international terrorist activities, or to support other intelligence activities.verified
Cyber Operations PlanningnounMWEin the NICE Workforce Framework, cybersecurity work where a person: Performs in-depth joint targeting and cyber planning process. Gathers information and develops detailed Operational Plans and Orders supporting requirements. Conducts strategic and operational-level planning across the full range of operations for integrated information and cyberspace operationsverified
cyber resiliencenounMWEThe ability of a system or domain to withstand cyber attacks or failures and, in such events, to reestablish itself quickly.verified
cyber resilience frameworknounMWEConsists of the policies, procedures and controls an FMI has established to identify, protect, detect, respond to and recover from the plausible sources of cyber risks it faces.verified
cyber resilience strategynounMWEAn FMI’s high level principles and medium term plans to achieve its objective of managing cyber risks.verified
Cyber ResiliencynounMWEThe ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources. [13]verified
cyber risknounMWEThe combination of the probability of an event occurring within the realm of an organisation’s information assets, computer and communication resources and the consequences of that event for an organisation.verified
cyber risk managementnounMWEThe process used by an FMI to establish an enterprise-wide framework to manage the likelihood of a cyber attack and develop strategies to mitigate, respond to, learn from and coordinate its response to the impact of a cyber attack. The management of an FMI’s cyber risk should support the business processes and be integrated in the FMI’s overall risk management framework.verified
cyber risk profilenounMWEThe cyber risk actually assumed, measured at a given point in time.verified
cyber risk tolerancenounMWEThe propensity to incur cyber risk, being the level of cyber risk that an FMI intends to assume in pursuing its strategic objectives.verified
cyber supply chain risk assessment processnounMWEThe foundational task in the cyber supply chain risk assessment process, cyber supply chain risk assessments are aimed at identifying and assessing applicable risk of Information and operational technology (IT/OT) outsourcing, diverse distribution routes, assorted technologies, laws, policies, procedures, and practices.verified
Cyber Supply Chain Risk Management PlannounMWEA plan that includes confidentiality, integrity, and availability controls for mitigating the risks associated with the distributed and interconnected nature of IT/OT product and service supply chains. It covers the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction) as supply chain threats and vulnerabilities may intentionally or unintentionally compromise an IT/OT product or service at any stage.verified
cyber supply chain risk management processnounMWEA detailed description of the steps necessary to mitigating the risks associated with the distributed and interconnected nature of IT/OT product and service supply chains. It covers the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction) as supply chain threats and vulnerabilities may intentionally or unintentionally compromise an IT/OT product or service at any stage.verified
cyber system recovery plannounMWEA step-by-step outline of the processes and procedures to be performed to bring a cyber system back to working order after an incident has occurred.verified
cyber threatnounMWEAn internal or external circumstance, event, action, occurrence, or person with the potential to exploit technology-based vulnerabilities and to adversely impact (create adverse consequences for) organizational operations, organizational assets (including information and information systems), individuals, other organizations, or society.verified
cyber threat intelligencenounMWEOrganized, analyzed and refined information about potential or current attacks that threaten an organization. The primary purpose of threat intelligence is helping organizations understand the risks of the most common and severe external threats, such as zero-day threats, advanced persistent threats (APTs) and exploits. Although threat actors also include internal (or insider) and partner threats, the emphasis is on the types that are most likely to affect a particular organization's environment. Threat intelligence includes in-depth information about specific threats to help an organization protect itself from the types of attacks that could do them the most damage. In a military, business or security context, intelligence is information that provides an organization with decision support and possibly a strategic advantage. Threat intelligence is a component of security intelligence and, like SI, includes both the information relevant to protecting an organization from external and inside threats as well as the processes, policies and tools designed to gather and analyze that information. Threat intelligence services provide organizations with current information related to potential attack sources relevant to their businesses; some also offer consultation service.verified
cyber threat response strategynounMWEA plan of action designed to achieve a long-term or overall aim regarding how to resolve cyber incidents.verified
cyber-physical systemnounMWEInteracting digital, analog, physical, and human components engineered for function through integrated physics and logic.verified
cybersecurity activitynounMWESecurity controls that are specific to the realm of Cybersecurity.verified
Cybersecurity and Infrastructure Security AgencynounMWECISA: Cybersecurity and Infrastructure Security Agencyverified
Cybersecurity architecturenounMWEDescribes the structure, components and topology (connections and layout) of security controls within an enterprise's IT infrastructure Scope Note: The security architecture shows how defense-in-depth is implemented and how layers of control are linked and is essential to designing and implementing security controls in any complex environment.verified
cybersecurity awarenessnounMWEThe extent to which individuals of an organization or those who have access to an organizations information understand their individual responsibilities regarding cybersecurity risks and the need to identify, assess, and mitigate these risks in light of the increasing volume and sophistication of cyber threats.verified
Cybersecurity CategorynounMWEThe subdivision of a Function into groups of cybersecurity outcomes, closely tied to programmatic needs and particular activities. Examples of Cybersecurity Categories include “Asset Management,” “Identity Management and Access Control,” and “Detection Processes.”.verified
cybersecurity controlnounMWEPractices and procedures established to protect organizational assets, user assets, and the cyber environment from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide integrity, confidentiality, and availability.verified
cybersecurity eventnounMWEAny act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System.verified
Cybersecurity Framework CorenounMWEA set of cybersecurity activities and references that are common across critical infrastructure sectors and are organized around particular outcomes. The Framework Core comprises four types of elements: Functions, Categories, Subcategories, and Informative References.verified
Cybersecurity Framework Implementation TiernounMWEA lens through which to view the characteristics of an organization’s approach to risk—how an organization views cybersecurity risk and the processes in place to manage that risk.verified
cybersecurity functionnounMWEOne of the main components of the Cybersecurity Framework. Cybersecurity functions provide the highest level of structure for organizing basic cybersecurity activities into Cybersecurity Categories and Cybersecurity Subcategories. The five Cybersecurity functions are the Identify function, Protect function, Detect function, Respond function, and Recover function.verified
cybersecurity incident responsenounMWEThe process of managing and resolving cybersecurity events that disrupt the organization's operations and restoring services.verified
cybersecurity incident response groupnounMWEA group of people that prepares for and resolves events that disrupt an organization's cybersecurity operations.verified
cybersecurity law, rule, or regulationnounMWEAny federal, state, or local statute or ordinance or any rule or regulation adopted according to any federal, state, or local statute or ordinance that deals specifically with the topic of protecting or defending computerized environments, organizational computerized assets, and user’s computerized assets.verified
cybersecurity objectivesnounMWEObjectives that address the cybersecurity risks that could affect the achievement of the entity's overall business objectives (including compliance, reporting, and operational objectives).verified
Cybersecurity outcomenounMWEA Cybersecurity outcome is the business need defined and tiered implementation of the outcomes listed in either the Categories or Subcategories section of Table 2 in the NIST Cybersecurity Framework.verified
cybersecurity personnelnounMWEAll people who are employed by an organization to perform cybersecurity activities.verified
cybersecurity plannounMWEFormal document that provides an overview of the cybersecurity requirements for an Information Technology and industrial control system and describes the cybersecurity controls in place or planned for meeting those requirements.verified
cybersecurity procedurenounMWEA detailed description of the steps necessary to implement cybersecurity in conformance with applicable standards.verified
Cybersecurity ProfilenounMWEA representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories.verified
cybersecurity programnounMWEAn integrated group of activities designed and managed to meet cybersecurity objectives for the organization and/or the function. A cybersecurity program may be implemented at either the organization or the function level, but a higher-level implementation and enterprise viewpoint may benefit the organization by integrating activities and leveraging resource investments across the entire enterprise.verified
cybersecurity requirementnounMWERequirements levied on an Information Technology and Operations Technology that are derived from organizational mission and business case needs (in the context of applicable legislation, Executive Orders, directives, policies, standards, instructions, regulations, procedures) to ensure the confidentiality, integrity, and availability of the services being provided by the organization and the information being processed, stored, or transmitted.verified
cybersecurity risknounMWEA risk to organizational operations, (including mission, functions, image, and reputation), resources, and other organizations due to the potential for unauthorized access, use, disclosure, disruption, modification, or destruction of information, Information Technology, and/or Operations Technology.verified
cybersecurity risk managementnounMWEThe process of identifying risks and vulnerabilities and applying administrative actions and comprehensive solutions to ensure that the organization is adequately protected.verified
cybersecurity roles and responsibilitiesnounMWEThe functions and duties of personnel who are responsible for preventing cybersecurity events that disrupt operations or affected parties, assigned and performed in conformance with pertinent laws and standards.verified
Cybersecurity SubcategorynounMWEThe subdivision of a Cybersecurity Category into specific outcomes of technical and/or management activities. Examples of Subcategories include “External information systems are catalogued,” “Data-at-rest is protected,” and “Notifications from detection systems are investigated.”.verified
cybersecurity trainingnounMWEActivities that are used to teach people about tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance and technologies that can be used to protect the cyber environment and organization and user’s assets.verified
cybersecurity vulnerabilitynounMWEA flaw in a organization's system which leaves it exposed to and defenseless against a cyberthreat.verified
Cycad FamilynounMWEancient palmlike plants closely related to ferns in that fertilization is by means of spermatozoidsverified
Cyclic Redundancy ChecknounMWESometimes called "cyclic redundancy code." A type of checksum algorithm that is not a cryptographic hash but is used to implement data integrity service where accidental changes to data are expected.verified
Cyclical Redundancy ChecknounMWEError checking mechanism that verifies data integrity by computing a polynomial algorithm based checksum.verified
Cyclodestructive SurgerynounMWEan eye operation that treats glaucoma by destroying the ciliary body with a laserverified
Cyclopean MasonrynounMWEa primitive style of masonry characterized by use of massive stones of irregular shape and sizeverified
Cylinder BlocknounMWEa metal casting containing the cylinders and cooling ducts of an engineverified
Cylinder HeadnounMWEa detachable plate that covers the closed end of a cylinder chamber in a reciprocating engine or pumpverified
Cylinder PressnounMWEa printing press where the type is carried on a flat bed under a cylinder that holds paper and rolls over the typeverified
Cyma RectanounMWEa cyma in which the upper section is concave and the lower section is convexverified
Cyma ReversanounMWEa molding that (in section) has the shape of an S with the convex part above and the concave part belowverified
Cypress PinenounMWEany of several evergreen trees or shrubs of Australia and northern New Caledoniaverified
Cypress TreenounMWEany of numerous evergreen conifers of the genus Cupressus of north temperate regions having dark scalelike leaves and rounded conesverified
Cypress VinenounMWEtropical American annual climber having red or white flowers and finely dissected leavesverified
Cyprinid FishnounMWEsoft-finned mainly freshwater fishes typically having toothless jaws and cycloid scalesverified
Cyrilla FamilynounMWEshrubs and trees with leathery leaves and small white flowers in racemes: genera Cyrilla and Cliftoniaverified
Cystic FibrosisnounMWEan inherited disease which causes secreted fluids in the body to become abnormally sticky and thick, commonly affecting the respiratory and digestive systemsverified
Cytologic SmearnounMWEa thin tissue or blood sample spread on a glass slide and stained for cytologic examination and diagnosis under a microscopeverified
Cytotoxic T CellnounMWET cell with CD8 receptor that recognizes antigens on the surface of a virus-infected cell and binds to the infected cell and kill itverified