home/glossary/vulnerability scanning parameter

vulnerability scanning parameter

nounid 163572·updated Sep 1, 2026
verified

A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0198
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
vulnerability scanningthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

This phrase is compositional, not a term of art. "Vulnerability scanning" is the established term — a technique used to identify hosts, host attributes, and associated vulnerabilities — and "parameter" retains its ordinary technical sense of a configurable setting or boundary condition. NIST SP 800-171r3 uses the phrase in the context of "establishing vulnerability scanning parameters" alongside analogous constructions such as "establishing intrusion detection parameters," showing that "parameter" modifies "vulnerability scanning" the same way it would modify any other security process. Such parameters include practical configuration choices like network interfaces to scan, credentials for authorized scans, scheduling options, port ranges, scanning strategies, and time constraints — the ordinary inputs that scope and govern a scan, not a specialized concept requiring its own definition.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.d ¶ 1

Classifications

Entity Type

Control85%manual reviewllm:claude-haiku-4-5

Sensitivity

Regulated88%manual reviewllm:claude-haiku-4-5

Information Class

Cui82%manual reviewllm:claude-haiku-4-5

Variants

plural
vulnerability scanning parameters
possessive
vulnerability scanning parameter's
pluralpossessive
vulnerability scanning parameters'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.