home/glossary/malicious code

malicious code

nounid 3203·updated Aug 28, 2026
verified

Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems21 citations · 21 defined by this document · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.07.b ¶ 103.01.18.c ¶ 103.07.04.b03.07.04.c ¶ 103.07.04.c ¶ 203.08.07.b ¶ 203.13.01.c ¶ 103.14.0203.14.02.a03.14.02.b03.14.02.c03.14.02.c.203.14.02.c.2 ¶ 103.14.02.c.2 ¶ 103.14.02.c.2 ¶ 203.14.02.c.2 ¶ 203.14.02.c.2 ¶ 303.14.06.c ¶ 203.14.06.c ¶ 43.2.2 ¶ 913.2.2 ¶ 92

Classifications

Entity Type

Threat0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

Regulated85%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

synonym
software threat
plural
malicious codes
possessive
malicious code's
pluralpossessive
malicious codes'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
Software (e.g., Trojan horse) that appears to perform a useful or desirable function, but actually gains unauthorized access to system resources or tricks a user into executing other malicious logic.
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1 · extended_definition_available
Program code intended to perform an unauthorized function or process that will have adverse impact on the confidentiality, integrity, or availability of an information system.
NIST Cybersecurity Framework1 senseview framework →
§1
Software or firmware designed to infiltrate or damage a computer system without the owner's knowledge or consent, with the intent of compromising the confidentiality, integrity, or availability of the owner’s data, applications, or operating system. Such software typically enters a network during many business-approved activities, which results in the exploitation of system vulnerabilities. Examples include viruses, worms, Trojans (or Trojan horses), spyware, adware, and rootkits.
NERC CIP-010-2 (Config Change Management & Vulnerability) v21 senseview framework →
§1
Software or firmware designed to infiltrate or damage a computer system without the owner's knowledge or consent, with the intent of compromising the confidentiality, integrity, or availability of the owner’s data, applications, or operating system. Such software typically enters a network during many business-approved activities, which results in the exploitation of system vulnerabilities. Examples include viruses, worms, Trojans (or Trojan horses), spyware, adware, and rootkits.
NERC CIP-007-6 (System Security Management) v61 senseview framework →
§1
Software or firmware designed to infiltrate or damage a computer system without the owner's knowledge or consent, with the intent of compromising the confidentiality, integrity, or availability of the owner’s data, applications, or operating system. Such software typically enters a network during many business-approved activities, which results in the exploitation of system vulnerabilities. Examples include viruses, worms, Trojans (or Trojan horses), spyware, adware, and rootkits.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
NIST SP 800-531 senseview framework →
§1
Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
NIST SP 800-172r31 senseview framework →
§1 · glossary
Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
Attribution from the CKI glossary mapping stage (glossary)
NIST SP 800-171r31 senseview framework →
§1 · glossary
Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. Examples of malicious code include viruses, worms, Trojan horses, spyware, some forms of adware, or other code-based entities that infect a host.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

related