Demilitarized zone
nounid
2280·updated Aug 28, 2026verified
Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network’s Information Assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.
MWE
Attested in
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
03.13.01.c ¶ 13.2.1 ¶ 133.2.1 ¶ 14
Classifications
Entity Type
Network0%rule-basedmulti_axis_classifier_low_confidence.v1
Sensitivity
—85%llm-generatedllm:claude-haiku-4-5
Information Class
—90%llm-generatedllm:claude-haiku-4-5
Variants
- acronym
- DMZ
- alternatephrasing
- Demilitarized Zone
- plural
- Demilitarized zones
- possessive
- Demilitarized zone's
- pluralpossessive
- Demilitarized zones'
Framework definitions
- §1
- In computer security, in general a demilitarized zone (DMZ) or perimeter network is a network area (a subnetwork) that sits between an organization's internal network and an external network, usually the Internet. DMZ's help to enable the layered security model in that they provide subnetwork segmentation based on security requirements or policy. DMZ's provide either a transit mechanism from a secure source to an insecure destination or from an insecure source to a more secure destination. In some cases, a screened subnet which is used for servers accessible from the outside is referred to as a DMZ.
- §1
- A screened (firewalled) network segment that acts as a buffer zone between a trusted and untrusted network Scope Note: A DMZ is typically used to house systems such as web servers that must be accessible from both internal networks and the Internet.
- §1
- An interface on a routing firewall that is similar to the interfaces found on the firewall’s protected side. Traffic moving between the DMZ and other interfaces on the protected side of the firewall still goes through the firewall and can have firewall protection policies applied.
- §2 · sense_2_pending_review
- A host or network segment inserted as a “neutral zone” between an organization’s private network and the Internet.
- §3 · sense_3_pending_review
- Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network’s Information Assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.
- §1
- Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network’s Information Assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.
- §1
- An interface on a routing firewall that is similar to the interfaces found on the firewall’s protected side. Traffic moving between the DMZ and other interfaces on the protected side of the firewall still goes through the firewall and can have firewall protection policies applied.
- §1
- A host or network segment inserted as a “neutral zone” between an organization’s private network and the Internet.
- §1
- a zone from which military forces or operations or installations are prohibited
- §1 · acronym list
- DMZ: Demilitarized ZoneAttribution from the CKI glossary mapping stage (acronym list)
- §1 · legacy_primary
- Perimeter network segment that is logically between internal and external networks. Its purpose is to enforce the internal network’s Information Assurance policy for external information exchange and to provide external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks.DR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
No incoming triples
No other term currently asserts a relationship to this one.