home/glossary/Spyware

Spyware

nounid 4216·updated May 9, 2026
candidate

Software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge; a type of malicious code.

Classifications

Entity Type

Threat90%rule-basedr:entity.threat.attack.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
Spywares
possessive
Spyware's
pluralpossessive
Spywares'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
Software that is secretly or surreptitiously installed into an information system without the knowledge of the system user or owner.
ISACA Cybersecurity Glossary1 senseview framework →
§1
Software whose purpose is to monitor a computer user’s actions (e.g., web sites visited) and report these actions to a third party, without the informed consent of that machine’s owner or legitimate user Scope Note: A particularly malicious form of spyware is software that monitors keystrokes to obtain passwords or otherwise gathers sensitive information such as credit card numbers, which it then transmits to a malicious third party. The term has also come to refer more broadly to software that subverts the computer’s operation for the benefit of a third party.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
Software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge; a type of malicious code.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge; a type of malicious code.
NIST SP 800-531 senseview framework →
§1
Software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge; a type of malicious code.

Outgoing relationships

related
  • Noun #3097

Incoming relationships

related