Glossary · MWE Terms · S
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
security patching processnounMWEThe series of steps taken to acquire, test, and distribute security patches to the appropriate administrators and users throughout the organization.verified
Security perimeternounMWEA physical or logical boundary that is defined for a system, domain, or enclave, within which a particular security policy or security architecture is applied.verified
security personnelnounMWEIndividuals who protect people, facilities, and information for an organization.verified
Security PlannounMWEFormal document that provides an overview of the security requirements for an information system or an information security program and describes the security controls in place or planned for meeting those requirements. See ‘System Security Plan’ or ‘Information Security Program Plan.’verified
security policynounMWEA set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.verified
Security PosturenounMWEThe security status of an enterprise’s networks, information, and systems based on IA resources (e.g., people, hardware, software, policies) and capabilities in place to manage the defense of the enterprise and to react as the situation changes.verified
security practicenounMWEThe actions an organization takes to initiate, implement, and maintain organizational security.verified
Security procedure agreementnounMWEAn agreement between a financial institution and a Federal Reserve Bank whereby the financial institution agrees to certain security procedures if it uses an encrypted communications line with access controls for the transmission or receipt of a payment order to or from a Federal Reserve Bank.verified
Security Program ManagementnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Manages information security (e.g., information security) implications within the organization, specific program, or other area of responsibility, to include strategic, personnel, infrastructure, policy enforcement, emergency planning, security awareness, and other resources (e.g., the role of a Chief Information Security Officer).verified
Security Program PlannounMWEFormal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management security controls and common security controls in place or planned for meeting those requirements.verified
Security RangenounMWEHighest and lowest security levels that are permitted in or on an information system, system component, subsystem, or network.verified
security requirementnounMWEA requirement levied on a system or an organization that is derived from applicable laws, Executive Orders, directives, regulations, policies, standards, procedures, or mission/business needs to ensure the confidentiality, integrity, and availability of information that is being processed, stored, or transmitted. [7, adapted] [8, adapted]verified
Security Requirements BaselinenounMWEDescription of the minimum requirements necessary for an information system to maintain an acceptable level of risk.verified
Security Requirements RequirementsnounMWERequirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, or procedures, or organizational mission/business case needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or transmitted.verified
Security Requirements Traceability MatrixnounMWEMatrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system’s security features and compliance methods for each security requirement.verified
Security ReviewnounMWEcounterintelligence achieved by banning or deleting any information of value to the enemyverified
security risknounMWEA measure of potential harm to an organization's information assets, operations, individuals, or mission — jointly determined by the likelihood that a threat will exploit a vulnerability and the severity of the resulting adverse impact. Per the NIST CSRC Glossary, drawing from NIST SP 800-160v1r1 and ISO Guide 73, it is formally defined as "the effect of uncertainty on objectives pertaining to asset loss and the associated consequences." In information-system contexts, NIST elaborates this as risk arising through loss of confidentiality, integrity, or availability of information or systems, considering impacts to organizational operations and assets, individuals, other organizations, and the Nation. The field uses the expression operationally as an assessable and manageable quantity: risk is the potential for harm when a threat exploits a vulnerability, expressed as a function of threat source, threat event, vulnerability, predisposing conditions, and impact, and practitioners apply it at every tier — from individual systems to enterprise missions — to prioritize controls, justify countermeasures, and drive risk-treatment decisions.verified
Security SafeguardsnounMWEProtective measures and controls prescribed to meet the security requirements specified for an information system. Safeguards may include security features, management constraints, personnel security, and security of physical structures, areas, and devices.verified
Security ServicenounMWEA capability that supports one, or more, of the security requirements (Confidentiality, Integrity, Availability). Examples of security services are key management, access control, and authentication.verified
security solutionnounMWEThe key design, architectural, and implementation choices made by organizations in satisfying specified security requirements for systems or system components.verified
Security SpecificationnounMWEDetailed description of the safeguards required to protect an information system.verified
Security StrengthnounMWEA measure of the computational complexity associated with recovering certain secret and/or security-critical information concerning a given cryptographic algorithm from known data (e.g. plaintext/ciphertext pairs for a given encryption algorithm).verified
Security SystemnounMWEan electrical device that sets off an alarm when someone tries to break inverified
Security TagnounMWEInformation unit containing a representation of certain security-related information (e.g., a restrictive attribute bit map).verified
Security TargetnounMWECommon Criteria specification that represents a set of security requirements to be used as the basis of an evaluation of an identified Target of Evaluation (TOE).verified
security testnounMWEThe purpose of this task is to determine if the security features of a system are implemented and functioning as designed. This process includes hands on functional testing, penetration testing and vulnerability scanning.verified
Security Test & EvaluationnounMWEExamination and analysis of the safeguards required to protect an information system, as they have been applied in an operational environment, to determine the security posture of that system.verified
Security TestingnounMWEProcess to determine that an information system protects data and maintains functionality as intended.verified
Security violationnounMWEAn instance in which a user or other person circumvents or defeats the controls of a system to obtain unauthorized access to information or system resources.verified
Security-Relevant ChangenounMWEAny change to a system’s configuration, environment, information content, functionality, or users which has the potential to change the risk imposed upon its continued operations.verified
Security-Relevant EventnounMWEAn occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).verified
Security-Relevant InformationnounMWEAny information within the information system that can potentially impact the operation of security functions in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data.verified
Sed RatenounMWEthe rate at which red blood cells settle out in a tube of blood under standardized conditionsverified
Sedative-Hypnotic DrugnounMWEa sedative that depresses activity of the central nervous system and reduces anxiety and induces sleepverified
Sedge BirdnounMWEsmall European warbler that breeds among reeds and wedges and winters in Africaverified
Sedge WarblernounMWEsmall European warbler that breeds among reeds and wedges and winters in Africaverified
Sedge WrennounMWEsmall European warbler that breeds among reeds and wedges and winters in Africaverified
Sedimentation RatenounMWEthe rate at which red blood cells settle out in a tube of blood under standardized conditionsverified
Seed FernnounMWEan extinct seed-producing fernlike plant of the order Cycadofilicales (or group Pteridospermae)verified
Seed ShrimpnounMWEtiny marine and freshwater crustaceans with a shrimp-like body enclosed in a bivalve shellverified
Seek TimenounMWE(computer science) the time it takes for a read/write head to move to a specific data trackverified
Sego LilynounMWEperennial plant having clusters of one to four showy white bell-shaped flowers atop erect unbranched stemsverified
Segregation/separation of dutiesnounMWEA basic internal control that prevents or detects errors and irregularities by assigning to separate individuals the responsibility for initiating and recording transactions and for the custody of assets Scope Note: Segregation/separation of duties is commonly used in large IT organizations so that no single person is in a position to introduce fraudulent or malicious code without detection.verified
Selective InformationnounMWE(communication theory) a numerical measure of the uncertainty of an outcomeverified
Selective LipectomynounMWEplastic surgery involving the breakdown and removal of fatty tissueverified
Selective-Serotonin Reuptake InhibitornounMWEan antidepressant drug that acts by blocking the reuptake of serotonin so that more serotonin is available to act on receptors in the brainverified
Self-Adapting ProgramnounMWEa program that can change its performance in response to its environmentverified
Self-Aware SystemnounMWEA computing platform imbued with sufficient knowledge and analytic capability to make useful conclusions about its inputs, its own processing, and the use of its output so that it is capable of self- judgment and improvement consistent with its purpose.verified
Self-Employed PersonnounMWEa writer or artist who sells services to different employers without a long-term contract with any of themverified