vulnerability scanning parameter
163572·updated Sep 1, 2026A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.
Source
vulnerability scanningthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- NIST Special Publication 800 NIST SP 800-171r3
- Vulnerability scanner
- How to Perform a Vulnerability Scan in 10 Steps | eSecurity Planet
- Vulnerability Scanning - Glossary | CSRC
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
This phrase is compositional, not a term of art. "Vulnerability scanning" is the established term — a technique used to identify hosts, host attributes, and associated vulnerabilities — and "parameter" retains its ordinary technical sense of a configurable setting or boundary condition. NIST SP 800-171r3 uses the phrase in the context of "establishing vulnerability scanning parameters" alongside analogous constructions such as "establishing intrusion detection parameters," showing that "parameter" modifies "vulnerability scanning" the same way it would modify any other security process. Such parameters include practical configuration choices like network interfaces to scan, credentials for authorized scans, scheduling options, port ranges, scanning strategies, and time constraints — the ordinary inputs that scope and govern a scan, not a specialized concept requiring its own definition.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- vulnerability scanning parameters
- possessive
- vulnerability scanning parameter's
- pluralpossessive
- vulnerability scanning parameters'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A configurable attribute or setting that governs the behavior of a vulnerability scanning process — such as scan scope (IP ranges, ports, or asset types), scan frequency, authentication credentials, scanning depth, and included or excluded checks. Standards and compliance frameworks treat these settings as security-relevant information, because their unauthorized disclosure or modification could allow an adversary to evade detection or narrow the scan's coverage. In practice, documents such as NIST SP 800-171r3 group them alongside intrusion-detection parameters and filtering rules as items requiring access controls and least-privilege protections.DR-088 backfill from the noun definition column