home/glossary/Nouns · I

Glossary · Nouns · I

L1 — paginated flat list. Pick a POS, pick a letter.

TermTypeDefinitionClassificationsUpdated
information and communication(s) technologynounMWEAny information technology, equipment, or interconnected system or subsystem of equipment that processes, transmits, receives, or interchanges data or information.SystemRegulatedAug 30, 2026
information and systemsnounMWERefers to information in electronic form (electronic information) during its use, processing, transmission, and storage and systems that use, process, transmit or transfer, and store information or that produce, manufacture, or distribute products.AssetAug 30, 2026
information assetnounMWEData and the associated software and infrastructure used to process, transmit, and store information or to produce, manufacture, or distribute products.AssetMay 9, 2026
information assurancenounMWEMeasures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. These measures include providing for restoration of information systems by incorporating protection, detection, and reaction capabilities.CapabilityMay 9, 2026
Information Assurance CompliancnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Oversees, evaluates, and supports the documentation, validation, and accreditation processes necessary to assure that new IT systems meet the organization's information assurance and security requirements; ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives.CapabilityRegulatedMay 9, 2026
Information Assurance ComponentnounMWEAn application (hardware and/or software) that provides one or more Information Assurance capabilities in support of the overall security and operational objectives of a system.CapabilityRegulatedCUIAug 30, 2026
Information Assurance ProfessionalnounMWEIndividual who works IA issues and has real-world experience plus appropriate IA training and education commensurate with their level of IA responsibility.RoleMay 9, 2026
Information Assurance Vulnerability AlertnounMWENotification that is generated when an Information Assurance vulnerability may result in an immediate and potentially severe threat to DoD systems and information; this alert requires corrective action because of the severity of the vulnerability risk.VulnerabilityRegulatedCDIAug 30, 2026
Information BulletinnounMWEa bulletin containing the latest informationverifiedMay 18, 2026
Information DomainnounMWEA three-part concept for information sharing, independent of, and across information systems and security domains that 1) identifies information sharing participants as individual members, 2) contains shared information objects, and 3) provides a security policy that identifies the roles and privileges of the members and the protections required for the information objects.FrameworkMay 9, 2026
Information EnvironmentnounMWEAggregate of individuals, organizations, and/or systems that collect, process, or disseminate information, also included is the information itself.SystemMay 9, 2026
information flownounMWEThe path data takes from its original source to the end user.ProcessMay 9, 2026
Information Flow ControlnounMWEProcedure to ensure that information transfers within a system are not made in violation of the security policy.ControlRegulatedCUIMay 9, 2026
information flow control policynounMWEA security or privacy policy construct that specifies the authorized paths and directions along which data may move—within a system, between systems, or across security/privacy domains—based on the characteristics of the information itself or its path rather than on who holds access rights to it. It is distinct from access control policy in that it governs *where* information may travel rather than *who* may read it, and it is typically enforced at boundary devices (firewalls, guards, proxies, data-loss-prevention tools) through rule sets keyed to data classification labels, content, or network attributes. In practice, organizations define organization-specific information flow control policies and then implement enforcement mechanisms—such as one-way data diodes, content filters, or export restrictions—to ensure transfers never violate those policies.RequirementAug 30, 2026
information flow enforcementnounMWEA security control category that governs whether and how data may move between subjects, objects, systems, or trust domains — distinct from access control, which concerns *who* may read or write information. Information flow enforcement regulates *where* information is allowed to travel within a system and between systems, as opposed to who is allowed to access the information, and without explicit regard to subsequent accesses to that information. Organizations employ information flow control policies and enforcement mechanisms to control flows between designated sources and destinations; flow control is based on the characteristics of the information and/or the information path, and enforcement occurs in boundary protection devices that use rule sets, packet-filtering on header information, or message-filtering based on content. Enforcement techniques include prohibiting transfers between connected systems, verifying write permissions before accepting information from another security or privacy domain, employing hardware mechanisms to enforce one-way flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels.ControlAug 30, 2026
Information GatheringnounMWEthe act of collecting informationverifiedMay 18, 2026
Information Input ComponentnounMWEOne of the three components of a model. This component delivers assumptions and data to the model.verifiedSep 1, 2026
Information ManagementnounMWEThe planning, budgeting, manipulating, and controlling of information throughout its life cycle.ProcessMay 9, 2026
Information MeasurenounMWEa system of measurement of information based on the probabilities of the events that convey informationverifiedMay 18, 2026
information neednounMWEInsight necessary to manage objectives, goals, risks and problems.RequirementRegulatedMay 9, 2026
Information OperationsnounMWEThe integrated employment of the core capabilities of electronic warfare, computer network operations, psychological operations, military deception, and operations security, in concert with specified supporting and related capabilities, to influence, disrupt, corrupt, or usurp adversarial human and automated decision-making process, information, and information systems while protecting our own.CapabilityRegulatedCUIMay 9, 2026
Information OwnernounMWEOfficial with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal. See Information Steward.RoleMay 9, 2026
information pathnounMWE** A property of a data flow used as a basis for access-control decisions about where information is permitted to travel within or between systems. It is distinguished from the *content* of the information itself: information flow control regulates where information is allowed to travel within an information system and between information systems, as opposed to who is allowed to access the information. Specifically, organizations use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations — such as networks, individuals, and devices — within systems and between interconnected systems, with flow control based on characteristics of the information or the information path. In practice, the information path serves as one of two alternative criteria (the other being content characteristics) against which boundary protection devices such as encrypted tunnels, routers, gateways, and firewalls apply rule sets or configuration settings to restrict system services, provide packet-filtering based on header information, or provide message-filtering based on message content. **VERDICT:** TERM_OF_ART --- **SouControlAug 30, 2026
Information ProcessingnounMWEthe sciences concerned with gathering, manipulating, storing, retrieving, and classifying recorded informationProcessRegulatedPIISep 1, 2026
Information Processing SystemnounMWEAny operation or set of operations performed on personal data, whether or not by automated meansSystemRegulatedPIISep 1, 2026
Information ResourcesnounMWEInformation and related resources, such as personnel, equipment, funds, and information technology. [24]AssetRegulatedMay 9, 2026
Information Resources ManagementnounMWEThe planning, budgeting, organizing, directing, training, controlling, and management activities associated with the burden, collection, creation, use, and dissemination of information by agencies.ProcessAug 30, 2026
Information ReturnnounMWEa return that provides information to the tax collector but does not compute the tax liabilityverifiedMay 18, 2026
Information SciencenounMWEthe sciences concerned with gathering, manipulating, storing, retrieving, and classifying recorded informationverifiedMay 18, 2026
Information SecuritynounMWEThe protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. [20]CapabilityAug 28, 2026
Information Security ArchitectnounMWEIndividual, group, or organization responsible for ensuring that the information security requirements necessary to protect the organization’s core missions and business processes are adequately addressed in all aspects of enterprise architecture including reference models, segment and solution architectures, and the resulting information systems supporting those missions and business processes.RoleMay 9, 2026
Information Security ArchitecturenounMWEAn embedded, integral part of the enterprise architecture that describes the structure and behavior for an enterprise’s security processes, information security systems, personnel and organizational sub-units, showing their alignment with the enterprise’s mission and strategic plans.FrameworkAug 30, 2026
Information Security AwarenessnounMWEActivities which seek to focus an individual’s attention on an (information security) issue or set of issues.ProcessMay 9, 2026
Information Security Continuous MonitoringnounMWEMaintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. [Note: The terms “continuous” and “ongoing” in this context mean that security controls and organizational risks are assessed and analyzed at a frequency sufficient to support risk-based security decisions to adequately protect organization information.]CapabilityMay 9, 2026
Information Security Continuous Monitoring ProcessnounMWEA process to: • Define an ISCM strategy; • Establish an ISCM program; • Implement an ISCM program; • Analyze data and Report findings; • Respond to findings; and • Review and Update the ISCM strategy and program.ProcessRegulatedAug 30, 2026
Information Security Continuous Monitoring ProgramnounMWEA program established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls.ProcessRegulatedAug 30, 2026
information security controlnounMWEPractices and procedures established to protect information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide integrity, confidentiality, and availability.ControlMay 9, 2026
information security eventnounMWEIdentified occurrence of a system, service or network state indicating a possible breach of information security policy or failure of controls, or a previously unknown situation that may be security relevant.EventRegulatedAug 30, 2026
information security incidentnounMWEA single or a series of unwanted or unexpected information security events that have a significant probability of compromising business operations and threatening information security.EventRegulatedMay 9, 2026
Information Security Oversight OfficenounMWEISOO: Information Security Oversight OfficeOrganizationAug 30, 2026
information security policynounMWEThe rules and guidelines of an organization on how to ensure the confidentiality, integrity, and availability of the organization's information.RequirementMay 9, 2026
information security procedurenounMWEThe documented series of steps on how to establish and maintain the confidentiality, integrity, and availability of information.RequirementMay 18, 2026
information security processnounMWEThe activities associated with establishing and maintaining the confidentiality, integrity, and availability of data and information.ProcessMay 18, 2026
information security programnounMWEA documented approach for organizing and directing all activities undertaken to ensure the confidentiality, integrity, and availability of the information held by the organization.ProcessInternalMay 18, 2026
Information Security Program PlannounMWEFormal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management controls and common controls in place or planned for meeting those requirements.ArtifactRestrictedCUIMay 9, 2026
Information Security risknounMWEThe risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation due to the potential for unauthorized access, use, disclosure, disruption, modification, or destruction of information and/or information systems. See Risk.MetricRegulatedCUIAug 30, 2026
information security roles and responsibilitiesnounMWEThe position and collection of tasks, duties, obligations that participants undertake to perform the daily and all special tasks in the role of information security.RoleMay 9, 2026
information security strategynounMWEA plan to mitigate risks while complying with legal, statutory, contractual, and internally developed requirements.RequirementInternalAug 30, 2026
information security threatnounMWEAny circumstance or event with the potential to adversely impact the measures taken so that information and information systems are protected from unauthorized access, use, disclosure, disruption, modification, or destruction.ThreatRegulatedAug 30, 2026
information security trainingnounMWETraining strives to produce relevant and needed (information) security skills and competencies.ProcessAug 30, 2026
information sharingnounMWEThe requirements for information sharing by an IT system with one or more other IT systems or applications, for information sharing to support multiple internal or external organizations, missions, or public programs.ProcessMay 9, 2026
Information Sharing and Analysis CentersnounMWEISAC: Information Sharing and Analysis CentersOrganizationRegulatedCUIAug 30, 2026
Information Sharing and Analysis OrganizationsnounMWEISAO: Information Sharing and Analysis OrganizationsOrganizationRegulatedCUIAug 30, 2026
Information Sharing EnvironmentnounMWE1. An approach that facilitates the sharing of terrorism and homeland security information; or 2. ISE in its broader application enables those in a trusted partnership to share, discover, and access controlled information.SystemRegulatedCUIMay 9, 2026
information sharing forumnounMWEAn assembly in which participants share problems, solutions, updates, and data on topics relevant to its discourse.CapabilityMay 9, 2026
Information StewardnounMWEIndividual or group that helps to ensure the careful and responsible management of federal information belonging to the Nation as a whole, regardless of the entity or source that may have originated, created, or compiled the information. Information stewards provide maximum access to federal information to elements of the federal government and its customers, balanced by the obligation to protect the information in accordance with the provisions of FISMA and any associated security-related federal policies, directives, regulations, standards, and guidance.RoleRegulatedMay 9, 2026
Information SuperhighwaynounMWEan extensive electronic network (such as the internet) used for the rapid transfer of sound and video and graphics in digital formverifiedMay 18, 2026
Information SystemnounMWEA discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. [24]SystemAug 28, 2026
information system componentnounMWEA discrete, identifiable information technology asset (e.g., hardware, software, firmware) that represents a building block of an information system. Information system components include commercial information technology products.SystemRegulatedAug 30, 2026
Information System Contingency PlannounMWEManagement policy and procedures designed to maintain or restore business operations, including computer operations, possibly at an alternate location, in the event of emergencies, system failures, or disasters.ProcessRegulatedCUIMay 9, 2026
Information System Life CyclenounMWEThe phases through which an information system passes, typically characterized as initiation, development, operation, and termination (i.e., sanitization, disposal and/or destruction).ProcessAug 30, 2026
Information System OwnernounMWEOfficial responsible for the overall procurement, development, integration, modification, or operation and maintenance of an information system.RoleMay 9, 2026
Information System Owner or Program ManagernounMWEOfficial responsible for the overall procurement, development, integration, modification, or operation and maintenance of an information system.RoleMay 9, 2026
information system resiliencenounMWEThe ability of an information system to continue to: (i) operate under adverse conditions or stress, even if in a degraded or debilitated state, while maintaining essential operational capabilities; and (ii) recover to an effective operational posture in a time frame consistent with mission needs.CapabilityAug 30, 2026
Information System Security OfficernounMWEIndividual assigned responsibility by the senior agency information security officer, authorizing official, management official, or information system owner for ensuring that the appropriate operational security posture is maintained for an information system or program.RoleMay 9, 2026
Information System-Related Security RisksnounMWEInformation system-related security risks are those risks that arise through the loss of confidentiality, integrity, or availability of information or information systems and consider impacts to the organization (including assets, mission, functions, image, or reputation), individuals, other organizations, and the Nation.ThreatRegulatedAug 30, 2026
Information Systems SecuritynounMWEProtection of information systems against unauthorized access to or modification of information, whether in storage, processing, or transit, and against the denial of service to authorized users, including those measures necessary to detect, document, and counter such threats.CapabilityRegulatedAug 30, 2026
Information Systems Security EngineernounMWEIndividual assigned responsibility for conducting information system security engineering activities.RoleMay 9, 2026
Information Systems Security EngineeringnounMWEProcess of capturing and refining information protection requirements to ensure their integration into information systems acquisition and information systems development through purposeful security design or configuration.ProcessMay 9, 2026
Information Systems Security Equipment ModificationnounMWEModification of any fielded hardware, firmware, software, or portion thereof, under NSA configuration control. There are three classes of modifications: mandatory (to include human safety); optional/special mission modifications; and repair actions. These classes apply to elements, subassemblies, equipment, systems, and software packages performing functions such as key generation, key distribution, message encryption, decryption, authentication, or those mechanisms necessary to satisfy security policy, labeling, identification, or accountability.ProcessRegulatedCUIMay 9, 2026
Information Systems Security ManagernounMWEIndividual responsible for the information assurance of a program, organization, system, or enclave.RoleMay 9, 2026
Information Systems Security OfficernounMWEIndividual assigned responsibility by the senior agency information security officer, authorizing official, management official, or information system owner for maintaining the appropriate operational security posture for an information system or program.RoleMay 9, 2026
Information Systems Security OperationsnounMWEIn the NICE Workforce Framework, cybersecurity work where a person: Oversees the information assurance program of an information system in or outside the network environment; may include procurement duties (e.g., Information Systems Security Officer).CapabilityMay 9, 2026
Information Systems Security ProductnounMWEItem (chip, module, assembly, or equipment), technique, or service that performs or relates to information systems security.CapabilityMay 9, 2026
information technologynounMWEAny services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use. [18]SystemAug 28, 2026
Information Technology auditnounMWEAn examination of the controls within an Information technology (IT) infrastructure.ProcessRegulatedAug 30, 2026
Information Technology controlnounMWERefers to the internal controls over security management, system development and change management, information processing, communications networks and management of technology service providers.ControlRegulatedAug 30, 2026
Information Technology LaboratorynounMWEITL: Information Technology LaboratoryOrganizationAug 30, 2026
Information Technology Management programnounMWEA documented listing of procedures, schedules, roles and responsibilities, and plans to manage Information Technology resources of an organization in accordance with its needs and priorities. These resources may include tangible investments like computer hardware, software, data, networks and data center facilities, as well as the staff who are hired to maintain them.ProcessInternalAug 30, 2026
Information Technology operationnounMWEThe activities and work involving Information Technology equipment and personnel.ProcessAug 30, 2026
Information Technology risknounMWEAny possibility of harm or damage related to Information Technology systems and data.MetricMay 9, 2026
information technology risk managementnounMWEInformation Technology risk management is the application of the principles of risk management to an Information Technology organization in order to manage the risks associated with the field. Information Technology risk management aims to manage the risks that come with the ownership, involvement, operation, influence, adoption and use of Information Technology as part of a larger enterprise. Information Technology risk management is a component of a larger enterprise risk management system. This encompasses not only the risks and negative effects of service and operations that can degrade organizational value, but it also takes the potential benefits of risky ventures into account.ProcessMay 9, 2026
Information Technology servicenounMWEA service provided to one or more customers by an Information Technology (IT) service provider. An IT service is based on the use of information technology and supports the customer’s business processes. An IT service is made up from a combination of people, processes, and technology and should be defined in a service level agreement.CapabilityAug 30, 2026
information technology suppliernounMWEInformation systems, components and services providers used for an organization’s internal purposes (e.g., IT infrastructure) or integrated into the products of services provided to that organization’s buyers.OrganizationAug 30, 2026
Information Technology systemnounMWEInformation technology systems are collectively the equipment used to create, store and transmit digital data and any related software owned (or otherwise controlled) and used by the State and its agencies to fulfill its service and obligations to the citizens of Arizona.SystemRegulatedAug 30, 2026
Information TheorynounMWE(computer science) a statistical theory dealing with the limits and efficiency of information processingverifiedMay 18, 2026
Information TypenounMWEA specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor sensitive, security management), defined by an organization or in some instances, by a specific law, Executive Order, directive, policy, or regulation.RequirementRegulatedAug 30, 2026
Information ValuenounMWEA qualitative measure of the importance of the information based upon factors such as: level of robustness of the Information Assurance controls allocated to the protection of information based upon: mission criticality, the sensitivity (e.g., classification and compartmentalization) of the information, releasability to other countries, perishability/longevity of the information (e.g., short life data versus long life intelligence source data), and potential impact of loss of confidentiality and integrity and/or availability of the information.MetricMay 9, 2026
Information WarfarenounMWEInformation Warfare is the competition between offensive and defensive players over information resources.ThreatMay 9, 2026
Informational RnanounMWEthe template for protein synthesisverifiedMay 18, 2026
Informative ReferencenounMWEA specific section of standards, guidelines, and practices common among critical infrastructure sectors that illustrates a method to achieve the outcomes associated with each Cybersecurity Subcategory. An example of an Informative Reference is ISO/IEC 27001 Control A.10.8.3, which supports the “Data-in-transit is protected” Subcategory of the “Data Security” Category in the “Protect” function.ArtifactAug 30, 2026
Informed ConsentnounMWEconsent by a patient to undergo a medical or surgical treatment or to participate in an experiment after the patient understands the risks involvedRequirementRegulatedPHISep 1, 2026
Informernounone who reveals confidential information in return for moneyverifiedMay 18, 2026
Informer's PrivilegenounMWEthe right of the government to refuse to reveal the identity of an informerverifiedMay 18, 2026
Informercialnouna television commercial presented in the form of a short documentaryverifiedMay 18, 2026
Informingnounto furnish incriminating evidence to an officer of the law (usually in return for favors)verifiedMay 18, 2026
Infotainmentnouna film or TV program presenting the facts about a person or eventverifiedMay 18, 2026
Infractionnouna crime less serious than a felonyverifiedMay 18, 2026
Infraorbital ArterynounMWEan artery that originates from the maxillary artery and supplies structures below the orbit (from lower eyelid to upper lip)verifiedMay 18, 2026
Infrared EmissionnounMWEelectromagnetic radiation with wavelengths longer than visible light but shorter than radio wavesverifiedMay 18, 2026