Glossary · MWE Terms · S
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
Secretarial AssistantnounMWEan assistant who handles correspondence and clerical work for a boss or an organizationverified
Secretarial SchoolnounMWEa school where secretarial skills (typing and shorthand and filing etc) are taughtverified
Secretory OrgannounMWEany of various organs that synthesize substances needed by the body and release it through ducts or directly into the bloodstreamverified
Secular GamesnounMWEthe centennial rites and games of ancient Rome that marked the commencement of a new generation (100 years representing the longest life in a generation)verified
Secular HumanismnounMWEthe doctrine emphasizing a person's capacity for self-realization through reasonverified
secure coding practicenounMWEA method used as part of the software development life cycle risk management so that software applications are designed and implemented with appropriate security requirements.verified
Secure Communication ProtocolnounMWEA communication protocol that provides the appropriate confidentiality, authentication, and content-integrity protection.verified
Secure CommunicationsnounMWETelecommunications deriving security through use of NSA-approved products and/or Protected Distribution Systems.verified
secure development practicenounMWEA software development practice where the confidentiality, integrity, and availability of the software code is protected against threats and vulnerabilities.verified
secure disposalnounMWEThe process of erasing or overwriting data stored on media before relinquishing control of said media when no longer required, in a manner that ensures that no data can be recovered from the media.verified
Secure DNSnounMWEConfiguring and operating DNS servers so that the security goals of data integrity and source authentication are achieved and maintained.verified
Secure Electronic TransactionnounMWEA standard that will ensure that credit card and associated payment order information travels safely and securely between the various involved parties on the Internet.verified
Secure ErasenounMWEAn overwrite technology using firmware-based process to overwrite a hard drive. Is a drive command defined in the ANSI ATA and SCSI disk drive interface specifications, which runs inside drive hardware. It completes in about 1/8 the time of 5220 block erasure.verified
Secure Hash AlgorithmnounMWEA hash algorithm with the property that is computationally infeasible 1) to find a message that corresponds to a given message digest, or 2) to find two different messages that produce the same message digest.verified
Secure Hash StandardnounMWEThis Standard specifies secure hash algorithms -SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224 and SHA-512/256 -for computing a condensed representation of electronic data (message). When a message of any length less than 264 bits (for SHA-1, SHA-224 and SHA-256) or less than 2128 bits (for SHA-384, SHA-512, SHA-512/224 and SHA-512/256) is input to a hash algorithm, the result is an output called a message digest. The message digests range in length from 160 to 512 bits, depending on the algorithm. Secure hash algorithms are typically used with other cryptographic algorithms, such as digital signature algorithms and keyed-hash message authentication codes, or in the generation of random numbers (bits). The hash algorithms specified in this Standard are called secure because, for a given algorithm, it is computationally infeasible 1) to find a message that corresponds to a given message digest, or 2) to find two different messages that produce the same message digest. Any change to a message will, with a very high probability, result in a different message digest. This will result in a verification failure when the secure hash algorithm is used with a digital signature algorithm or a keyed-hash message authentication algorithm.verified
Secure Multipurpose Internet Mail ExtensionsnounMWEProvides cryptographic security services for electronic messaging applications: authentication, message integrity and non-repudiation of origin (using digital signatures) and privacy and data security (using encryption) to provide a consistent way to send and receive MIME data. (RFC 2311)verified
Secure ShellnounMWENetwork protocol that uses cryptography to secure communication, remote command line log-in, and remote command execution between two networked computers.verified
Secure Socket LayernounMWEA protocol used for protecting private information during transmission via the Internet. Note: SSL works by using a public key to encrypt data that's transferred over the SSL connection. Most Web browsers support SSL, and many Web sites use the protocol to obtain confidential user information, such as credit card numbers. By convention, URLs that require an SSL connection start with “https:” instead of “http:.”verified
Secure Socket Layer (SSL)nounMWEA protocol that is used to transmit private documents through the Internet.verified
Secure Sockets LayernounMWEA protocol that is used to transmit private documents through the Internet Scope Note: The SSL protocol uses a private key to encrypt the data that are to be transferred through the SSL connection.verified
Secure StatenounMWECondition in which no subject can access any object in an unauthorized manner.verified
Secure SubsystemnounMWESubsystem containing its own implementation of the reference monitor concept for those resources it controls. Secure subsystem must depend on other controls and the base operating system for the control of subjects and the more primitive system objects.verified
Securely ProvisionnounMWEA NICE Workforce Framework category consisting of specialty areas concerned with conceptualizing, designing, and building secure IT systems, with responsibility for some aspect of the systems' development.verified
Securities MarketnounMWEan exchange where security trading is conducted by professional stockbrokersverified
security alertnounMWEAny form of notification or alert structure that something is amiss with the system's configuration, settings, etc.verified
Security architecturenounMWEA detailed description of all aspects of the system that relate to security, along with a set of principles to guide the design. A security architecture describes how the system is put together to satisfy the security requirements.verified
Security as a ServicenounMWEThe next generation of managed security services dedicated to the delivery, over the Internet, of specialized information-security services.verified
Security Assertion Markup LanguagenounMWEA framework for exchanging authentication and authorization information. Security typically involves checking the credentials presented by a party for authentication and authorization. SAML standardizes the representation of these credentials in an XML format called “assertions,” enhancing the interoperability between disparate applications.verified
security assessment reportnounMWEAny published finding of security component audits such as a vulnerability assessment.verified
Security AssociationnounMWEA relationship established between two or more entities to enable them to protect data they exchange.verified
Security AttributenounMWEAn abstraction representing the basic properties or characteristics of an entity with respect to safeguarding information; typically associated with internal data structures (e.g., records, buffers, files) within the information system which are used to enable the implementation of access control and flow control policies; reflect special dissemination, handling, or distribution instructions; or support other aspects of the information security policy.verified
Security auditnounMWEAn independent review and examination of system records and activities to test for adequacy of system controls, ensure compliance with established policy and operational procedures, and recommend any indicated changes in control, policy, and procedures.verified
security automationnounMWEThe use of information technology in place of manual processes for cyber incident response and management.verified
Security Automation DomainnounMWEAn information security area that includes a grouping of tools, technologies, and data.verified
Security Awareness programnounMWEThe documented plan and documented activities to create well-informed interest in being free from danger or threat.verified
security awareness trainingnounMWEThe process of educating personnel on critical business processes.verified
Security BannernounMWEA banner at the top or bottom of a computer screen that states the overall classification of the system in large, bold type. Also can refer to the opening screen that informs users of the security implications of accessing a computer resource.verified
Security BlanketnounMWEa blanket (or toy) that a child carries around in order to reduce anxietyverified
Security breachnounMWEA security event that results in unauthorized access of data, applications, services, networks, or devices by bypassing underlying security mechanisms.verified
Security CategorizationnounMWEThe process of determining the security category for information or an information system. Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS 199 for other than national security systems.verified
Security CategorynounMWEThe characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, individuals, other organizations, and the Nation.verified
Security Concept of OperationsnounMWEA security-focused description of an information system, its operational policies, classes of users, interactions between the system and its users, and the system’s contribution to the operational mission.verified
Security Content Automation ProtocolnounMWEA method for using specific standardized testing methods to enable automated vulnerability management, measurement, and policy compliance evaluation against a standardized set of security requirements.verified
security controlnounMWEThe safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. [18]verified
Security Control AssessmentnounMWEThe testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization. [18]verified
Security Control AssessornounMWEThe individual, group, or organization responsible for conducting a security control assessment.verified
Security Control BaselinenounMWEOne of the sets of minimum security controls defined for federal information systems in NIST Special Publication 800-53 and CNSS Instruction 1253.verified
Security Control EffectivenessnounMWEThe measure of correctness of implementation (i.e., how consistently the control implementation complies with the security plan) and how well the security plan meets organizational needs in accordance with current risk tolerance.verified
Security Control EnhancementsnounMWEStatements of security capability to: (i) build in additional, but related, functionality to a security control; and/or (ii) increase the strength of the control.verified
Security Control InheritancenounMWEA situation in which an information system or application receives protection from security controls (or portions of security controls) that are developed, implemented, assessed, authorized, and monitored by entities other than those responsible for the system or application; entities either internal or external to the organization where the system or application resides. See Common Control.verified
Security Controls BaselinenounMWEThe set of minimum security controls defined for a low-impact, moderate-impact, or high-impact information system.verified
Security DepartmentnounMWEa department responsible for the security of the institution's property and workersverified
Security DepositnounMWEthe amount of collateral a customer deposits with a broker when borrowing from the broker to buy securitiesverified
Security DomainnounMWEA domain that implements a security policy and is administered by a single authority. [16, adapted]verified
Security EngineeringnounMWEAn interdisciplinary approach and means to enable the realization of secure systems. It focuses on defining customer needs, security protection requirements, and required functionality early in the systems development life cycle, documenting requirements, and then proceeding with design, synthesis, and system validation while considering the complete problem.verified
security eventnounMWEAn occurrence, arising from actual or attempted unauthorized access or use by internal or external parties, that impairs or could impair the availability, integrity, or confidentiality of information or systems: result in unauthorized disclosure or theft of information or other assets; or cause damage to systems.verified
Security Event LognounMWEThis record contains records of any security-related and auditing-related events.verified
Security Fault AnalysisnounMWEAn assessment, usually performed on information system hardware, to determine the security properties of a device when hardware fault is encountered.verified
Security Features Users GuidenounMWEGuide or manual explaining how the security mechanisms in a specific system work.verified
Security FilternounMWEA secure subsystem of an information system that enforces security policy on the data passing through it.verified
Security ForcenounMWEa privately employed group hired to protect the security of a business or industryverified
Security FunctionsnounMWEThe hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.verified
Security GoalsnounMWEThe five security goals are confidentiality, availability, integrity, accountability, and assurance.verified
Security Impact AnalysisnounMWEThe analysis conducted by an organizational official to determine the extent to which changes to the information system have affected the security state of the system.verified
security incidentnounMWEA security event that requires action on the part of an entity to protect information assets and resources.verified
security incident response plannounMWEThe steps taken during an incident. An incident response plan brings together and organizes the resources for dealing with any event that harms or threatens the security of information assets. Such an event may be a malicious code attack, an unauthorized access to information or systems, the unauthorized use of services, a denial of service attack, or a hoax.verified
Security Information and Event ManagementnounMWEApplication that provides the ability to gather security data from information system components and present that data as actionable information via a single interface.verified
Security InspectionnounMWEExamination of an information system to determine compliance with security policy, procedures, and practices.verified
Security IntelligencenounMWEintelligence on the identity and capability and intentions of hostile individuals or organizations that may be engaged in espionage or sabotage or subversion or terrorismverified
Security InterestnounMWEany interest in a property that secures the payment of an obligationverified
Security KernelnounMWEHardware, firmware, and software elements of a trusted computing base implementing the reference monitor concept. Security kernel must mediate all accesses, be protected from modification, and be verifiable as correct.verified
Security LabelnounMWEInformation that represents or designates the value of one or more security relevant-attributes (e.g., classification) of a system resource.verified
Security LevelnounMWEA hierarchical indicator of the degree of sensitivity to a certain threat. It implies, according to the security policy being enforced, a specific level of protection.verified
Security lognounMWEA record that contains log-in and logout activity and other security-related events and that is used to track security-related information on a computer system.verified
Security Management DashboardnounMWEA tool that consolidates and communicates information relevant to the organizational security posture in near real-time to security management stakeholders.verified
Security MarkingnounMWEHuman-readable information affixed to information system components, removable media, or output indicating the distribution limitations, handling caveats, and applicable security markings.verified
Security MeasuresnounMWEmeasures taken as a precaution against theft or espionage or sabotage etc.verified
Security MechanismnounMWEA device designed to provide one or more security services usually rated in terms of strength of service and assurance of the design.verified
Security metricsnounMWEA standard of measurement used in management of security-related activitiesverified
Security Net Control StationnounMWEManagement system overseeing and controlling implementation of network security policy.verified
security operations centrenounMWEA function or service responsible for monitoring, detecting and isolating incidents.verified
security patchnounMWEComputer code intended to repair or lessen the impact of vulnerabilities within application software.verified
security patchingnounMWEThe purpose of this task is to distribute patches to apply security patches to organizational operating systems and applications.verified