non-security information
163581·updated Sep 1, 2026The phrase is the straightforward logical complement of the defined term "security information" — defined by NIST SP 800-37 Rev. 2 as information within a system that can potentially impact the operation of security functions or the provision of security services. "Non-security information" therefore denotes any information residing in or processed by a system that does **not** meet that threshold — content whose compromise, modification, or disclosure would not affect security enforcement mechanisms, security policy, or the isolation of security-relevant code and data. In context it serves as a residual or exclusionary category, used to draw a boundary around the scope of a security control or analysis by naming what falls outside it, rather than labeling a substantive class of data in its own right.
Source
or non-security information.the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
** This is a compositional phrase, not a term of art. It functions as an ordinary modifier+noun construction meaning simply "information that is not security-related" — used in a given document to distinguish the scope of a provision, requirement, or control from information that does bear a security classification or security-relevant designation. Its meaning is fully derivable from its component words in context and it does not carry a standardized, field-wide sense beyond that ordinary reading. **VERDICT:** COMPOSITIONAL --- **Sources consulted:** - NIST CSRC / RMF FAQ (csrc.nist.gov) — searched for authoritative NIST usage; phrase not present as a defined term. - NIST FISMA Background (csrc.nist.gov/Projects/risk-management/fisma-background) — no definition of the phrase found. - HKCERT self-help guide (hkcert.org) — uses "non-information security incidents" compositionally, not "non-security information" as a term of art. - Multiple data classification policy documents (CMU, Michigan Tech, Maryland DoIT, SIU) — none define "non-security information" as a standalone term. - General searches across NIST, AICPA, ISO, CIS, and FISMA contexts returned no authority document defin
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- non-security informations
- possessive
- non-security information's
- pluralpossessive
- non-security informations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The phrase is the straightforward logical complement of the defined term "security information" — defined by NIST SP 800-37 Rev. 2 as information within a system that can potentially impact the operation of security functions or the provision of security services. "Non-security information" therefore denotes any information residing in or processed by a system that does **not** meet that threshold — content whose compromise, modification, or disclosure would not affect security enforcement mechanisms, security policy, or the isolation of security-relevant code and data. In context it serves as a residual or exclusionary category, used to draw a boundary around the scope of a security control or analysis by naming what falls outside it, rather than labeling a substantive class of data in its own right.DR-088 backfill from the noun definition column