Glossary · Nouns · A
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
Authentication ModenounMWEA block cipher mode of operation that can provide assurance of the authenticity and, therefore, the integrity of data.Control
Authentication PeriodnounMWEThe maximum acceptable period between any initial authentication process and subsequent reauthentication processes during a single terminal session or during the period data is being accessed.RequirementRegulatedCUI
authentication procedurenounMWEThe documented steps necessary to authenticate the identity of an entity through the use of credentials in order to gain access to the system.Requirement
Authentication ProtocolnounMWEA defined sequence of messages between a Claimant and a Verifier that demonstrates that the Claimant has possession and control of a valid token to establish his/her identity, and optionally, demonstrates to the Claimant that he or she is communicating with the intended Verifier.ProcessRegulated
Authentication TagnounMWEA pair of bit strings associated to data to provide assurance of its authenticity.Artifact
Authentication TokennounMWEAuthentication information conveyed during an authentication exchange.Credential
AuthenticatornounSomething the claimant possesses and controls (typically a cryptographic module or password) that is used to authenticate the claimant's identity. This was previously referred to as a token.Credential
AuthenticitynounThe property of being genuine and being able to be verified and trusted; confidence in the validity of a transmission, a message, or message originator. See Authentication.Capability
Authoring LanguagenounMWEsoftware that can be used to develop interactive computer programs without the technically demanding task of computer programmingverified
Authoritarian RegimenounMWEa government that concentrates political power in an authority not responsible to the peopleverified
Authoritarian StatenounMWEa government that concentrates political power in an authority not responsible to the peopleverified
Authoritarianismnouna form of government in which the ruler is an absolute dictator (not restricted by a constitution or laws or opposition etc.)verified
AuthoritynounPerson(s) or established bodies with rights and responsibilities to exert control in an administrative sphere.Organization
authorizationnounThe process of granting access privileges to a user, program, or process by a person that has the authority to grant such access.Process
Authorization (ACH)nounMWEA written or oral agreement between the originator and a receiver that allows payments processed through the ACH network to be deposited in, or withdrawn from, the receiver's account at a financial institution.RequirementRegulatedPCI
Authorization BoundarynounMWEAll components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.RequirementRegulated
authorization recordnounMWEA document or identifier which provides evidence of authorization.ArtifactRegulatedCUI
Authorization to operatenounMWEThe official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.ArtifactRegulatedCUI
authorizations to executenounMWEA compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.ControlRegulated
authorized accessnounMWEAccess to system components that (a) has been approved by a person designated to do so by management and (b) does not compromise segregation of duties, confidentiality commitments, or otherwise increase risk to the system beyond the levels approved by management (that is, access is appropriate).ControlRegulated
authorized devicenounMWEA computer device that the organization has authorized to be used and connected to the system.Physical
authorized personnounMWEThis role is focused on a person who has been given permission to do something by an authority. Any individual who has been granted permission to do something on behalf of their organization should be assigned to this role.Role
authorized personnelnounMWEThis role is focused on employees who are granted access to the organizations assets, information, and/or certain areas, or permitted to conduct certain work. Any individual who is sanctioned by management should be assigned to this role.Role
authorized privilegenounMWE** A set of elevated access rights, permissions, or capabilities that have been formally granted to a user, role, or process by an authorizing entity within a defined access-control policy. The expression functions as the collective object of access-governance controls — particularly least privilege and separation of duties — which exist precisely because such rights, though legitimately held, remain a vector for insider abuse or insider threat if concentrated without checks. The principle of least privilege is applied with the goal of authorized privileges no higher than necessary to accomplish required organizational missions or business functions. In practice, separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion — making "authorized privileges" the specific threat surface that controls such as role separation, audit logging of privileged-function execution, and periodic access reviews are designed to govern.
**VERDICT:** COMPOSITIONAL
The expression is not a defined term of art with its own glossary entry in NIST SP 800-53, NIST SP 800-171, or related authority documents. It is a tCapabilityRegulated
Authorized SharesnounMWEthe maximum number of shares authorized under the terms of a corporation's articles of incorporationverified
Authorized StocknounMWEthe maximum number of shares authorized under the terms of a corporation's articles of incorporationverified
authorized usernounMWEA person who has the authority or permission to manage access or make changes to an account.Identity
Authorized VendornounMWEManufacturer of information assurance equipment authorized to produce quantities in excess of contractual requirements for direct sale to eligible buyers. Eligible buyers are typically U.S. government organizations or U.S. government contractors.OrganizationRegulated
Authorized Vendor ProgramnounMWEProgram in which a vendor, producing an information systems security (INFOSEC) product under contract to NSA, is authorized to produce that product in numbers exceeding the contracted requirements for direct marketing and sale to eligible buyers. Eligible buyers are typically U.S. government organizations or U.S. government contractors. Products approved for marketing and sale through the AVP are placed on the Endorsed Cryptographic Products List (ECPL).ProcessRegulated
Authorizing OfficialnounMWEA senior (federal) official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.Role
Authorizing Official Designated RepresentativenounMWEAn organizational official acting on behalf of an authorizing official in carrying out and coordinating the required activities associated with security authorization.RoleRegulated
Auto LimitationnounMWEsocial control achieved as a manifestation of self-will or general consentverified
Auto-Changernounan automatic mechanical device on a record player that causes new records to be played without manual interventionverified
Autochthonynounnativeness by virtue of originating or occurring naturally (as in a particular place)verified
Autocoidnounany physiologically active internal secretion especially one of uncertain classificationverified
Autogenesisnouna hypothetical organic phenomenon by which living organisms are created from nonliving matterverified
Autogenynouna hypothetical organic phenomenon by which living organisms are created from nonliving matterverified
Autogironounan aircraft that is supported in flight by unpowered rotating horizontal wings (or blades)verified
Autograftnountissue that is taken from one site and grafted to another site on the same personverified
Autogyronounan aircraft that is supported in flight by unpowered rotating horizontal wings (or blades)verified
Autoimmune DiseasenounMWEany of a large group of diseases characterized by abnormal functioning of the immune system that causes your immune system to produce antibodies against your own tissuesverified
Autoimmune DisordernounMWEany of a large group of diseases characterized by abnormal functioning of the immune system that causes your immune system to produce antibodies against your own tissuesverified
Automated Clearing House (ACH)nounMWEAn electronic clearing system in which a data processing center handles payment orders that are exchanged among financial institutions, primarily via telecommunications networks. ACH systems process large volumes of individual payments electronically. Typical ACH payments include salaries, consumer and corporate bill payments, interest and dividend payments, and Social Security payments.SystemRegulatedPCI
Automated Clearing House (ACH) OperatornounMWEA central clearing facility that depository financial institutions use to transmit and receive ACH entries. ACH operators are typically a Federal Reserve Bank or a private-sector organization that operates on behalf of a depository financial institution.Role
automated clearing house activitynounMWEAny transaction made through the Automated Clearing House network.EventRegulatedPCI
automated clearing house capturenounMWEA service that allows a user to transmit automated clearing house data to a bank for posting and clearing.CapabilityRegulatedPCI
Automated ControlsnounMWESoftware routines designed into programs to ensure the validity, accuracy, completeness, and availability of input, processed, and stored data.ControlRegulated
Automated Key TransportnounMWEThe transport of cryptographic keys, usually in encrypted form, using electronic means such as a computer network (e.g., key transport/agreement protocols).ProcessRegulated
Automated Password GeneratornounMWEAn algorithm which creates random passwords that have no association with a particular user.Credential
Automated Security MonitoringnounMWEUse of automated procedures to ensure security controls are not circumvented or the use of these tools to track actions taken by subjects suspected of misusing the information system.Capability
Automated TellernounMWEan unattended machine that dispenses money when a personal coded card is usedverified
Automated Teller MachinenounMWEan unattended machine that dispenses money when a personal coded card is usedverified
Automated Teller Machine (ATM)nounMWEAn electronic funds transfer (EFT) terminal that allows customers using a PIN-based debit (ATM) card to initiate transactions (e.g., deposits, withdrawals, account balance inquiries).PhysicalRegulatedPCI