Glossary · MWE Terms · S
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
System Of RecordsnounMWEA group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.verified
System of SystemsnounMWEset of systems and system elements that interact to provide a unique capability that none of the constituent systems can accomplish on its own (note: can be necessary to facilitate interaction of the constituent systems in the system of systems)verified
System of Weights and MeasuresnounMWEsystem of measurement for length and weight and durationverified
system operationnounMWEThe day to day processes of using a system according to its design and development criteria.verified
System OwnernounMWEPerson or organization having responsibility for the development, procurement, integration, modification, operation and maintenance, and/or final disposition of an information system.verified
system processnounMWEAn active security principal—specifically, an executing software process on a computing system—that has been granted an identity and access rights so it can perform actions on behalf of a human user without that user being directly present. NIST (SP 800-37 Rev. 2) treats it as one of the two forms a "system user" may take: "an individual or (system) process acting on behalf of an individual that is authorized to access information and information systems to perform assigned duties." In access-control frameworks such as NIST SP 800-53 and SP 800-171, system processes are classified alongside human users as **active entities or subjects** that access control policies must govern, standing in contrast to passive objects such as devices, files, records, and domains. Practically, if a user launches an application or background tool, that application runs as the user and "is acting on behalf of the user," meaning any process running under a user's authority must be confined to the same access permissions as that user and no more.verified
System ProfilenounMWEDetailed security description of the physical structure, equipment component, location, relationships, and general operating environment of an information system.verified
System ProgramnounMWEa program (as an operating system or compiler or utility program) that controls some aspect of the operation of a computerverified
system requirementsnounMWESpecifications regarding how the system should function to ( a ) meet the entity's commitments to customers and others (such as customers' customers); ( b ) meet the entity's commitments to suppliers and business partners; ( c ) comply with relevant laws and regulations and guidelines of industry groups, such as business or trade associations; and ( d ) achieve other entity objectives that are relevant to the trust services category or categories addressed by the description. Requirements are often specified in the entity's system policies and procedures, system design documentation, contracts with customers, and government regulations.
System requirements may result from the entity's commitments relating to security, availability, processing integrity, confidentiality, or privacy. For example, a commitment to programmatically enforce segregation of duties between data entry and data approval creates system requirements regarding user access administration.verified
System resourcesnounMWECapabilities that can be accessed by a user or program either on the user's machine or across the network. Capabilities can be services, such as file or print services, or devices, such as routers.verified
system securitynounMWEThe protection of Bulk Electronic System (BES) Cyber Systems against compromise that could lead to misoperation or instability in the Bulk Electronic System (BES).verified
System Security OfficernounMWEA person responsible for enforcement or administration of the security policy that applies to the system.verified
System Security PlannounMWEA document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary, the environment in which the system operates, how security requirements are implemented, and the relationships with or connections to other systems.verified
system servicenounMWEA capability provided by a system that facilitates information processing, storage, or transmission.verified
System SoftwarenounMWEThe special software within the cryptographic boundary (e.g., operating system, compilers or utility programs) designed for a specific computer system or family of computer systems to facilitate the operation and maintenance of the computer system, associated programs, and data.verified
system support functionnounMWEA category of privileged IT activities — such as configuration management, quality assurance and testing, system management, programming, and network security — that must be distributed across multiple individuals or roles rather than concentrated in any one person. It is distinguished from mission or business functions by its technical/administrative character: these are the internal operational tasks that keep a system running and secure, as opposed to the outputs the system produces for the organization. In the field, the concept is invoked as one of the three main mechanisms for implementing separation of duties (NIST SP 800-53 AC-5; NIST SP 800-171 control 3.1.4), alongside dividing mission functions and preventing administrators from holding cross-cutting privileges such as both access-control administration and audit administration.verified
system upgradenounMWEA planned, authorized lifecycle event in which one or more components of an operational information system — software, firmware, or hardware — are replaced or advanced to a newer version, typically involving a service interruption or maintenance window. It is distinguished from a routine patch or hotfix by its broader scope: a system upgrade commonly replaces a major version, introduces new functionality, or transitions the platform itself, rather than simply remediating a discrete vulnerability. In security and compliance frameworks it appears alongside scheduled maintenance as a category of anticipated downtime that must be governed by change-management controls — including authorization, scheduling, testing, and documented rollback plans — so that the upgrade event does not itself introduce new risk or violate availability commitments. The phrase is compositional (upgrade of a system) rather than a specialized term of art with a fixed regulatory definition, and its meaning is understood directly from its component words across NIST, CMMC, and related authority documents.verified
system usagenounMWEA characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.verified
system usernounMWEAn individual or (system) process acting on behalf of an individual that is authorized to access a system.verified
System-Specific PolicynounMWEA System-specific policy is a policy written for a specific system or device.verified
System-Specific Security ControlnounMWEA security control for an information system that has not been designated as a common security control or the portion of a hybrid control that is to be implemented within an information system.verified
Systema LymphaticumnounMWEthe interconnected system of spaces and vessels between body tissues and organs by which lymph circulates throughout the bodyverified
Systema NervosumnounMWEthe sensory and control apparatus consisting of a network of nerve cellsverified
Systema Nervosum CentralenounMWEthe portion of the vertebrate nervous system consisting of the brain and spinal cordverified
Systema Nervosum PeriphericumnounMWEthe section of the nervous system lying outside the brain and spinal cordverified
Systema SkeletalenounMWEthe hard structure (bones and cartilages) that provides a frame for the body of an animalverified
Systema UrogenitalenounMWEthe system that includes all organs involved in reproduction and in the formation and voidance of urineverified
Systematic DesensitisationnounMWEa technique used in behavior therapy to treat phobias and other behavior problems involving anxietyverified
Systematic DesensitizationnounMWEa technique used in behavior therapy to treat phobias and other behavior problems involving anxietyverified
Systemic BiasnounMWESystemic biases result from procedures and practices of particular institutions that operate in ways which result in certain social groups being advantaged or favored and others being disadvantaged or devalued. This need not be the result of any conscious prejudice or discrimination but rather of the majority following existing rules or norms.verified
Systemic CirculationnounMWEcirculation that supplies blood to all the body except to the lungsverified
Systemic Lupus ErythematosusnounMWEan inflammatory disease of connective tissue with variable features including fever and weakness and fatigability and joint pains and skin lesions on the face or neck or armsverified
Systems AnalysisnounMWEanalysis of all aspects of a project along with ways to collect information about the operation of its partsverified
Systems DevelopmennounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Works on the development phases of the systems development lifecycle.verified
Systems Development Life Cycle (SDLC)nounMWEAn approach used to plan, design, develop, test, and implement an application system or a major modification to an application system.verified
Systems ProgramnounMWEa program (as an operating system or compiler or utility program) that controls some aspect of the operation of a computerverified
Systems Requirements PlanningnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Consults with customers to gather and evaluate functional requirements and translates these requirements into technical solutions; provides guidance to customers about applicability of information systems to meet business needs.verified
Systems Security AnalysisnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Conducts the integration/testing, operations, and maintenance of systems security.verified
Systems Security ArchitecturenounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Develops system concepts and works on the capabilities phases of the systems development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into system and security designs and processes.verified
Systems SoftwarenounMWEa program such as an operating system, compiler, or utility program that controls some aspect of the operation of a computerverified
Systolic PressurenounMWEthe blood pressure (as measured by a sphygmomanometer) during the contraction of the left ventricle of the heartverified