Security & Compliance Glossary
Key terms and definitions in cybersecurity, compliance frameworks, and industrial control systems.
147 terms
Access Control
Access Control is a fundamental component of cybersecurity that determines who is allowed to access and interact with resources within a network. In the context of OT/IT cybersecurity, access control...
Access Control List
An Access Control List (ACL) is a set of rules that determines which users or systems are granted or denied access to specific resources within a network. ACLs are crucial for managing permissions and...
Advanced Cyber Hygiene
Advanced Cyber Hygiene refers to a comprehensive and proactive approach to maintaining and improving the security posture of an organization by implementing best practices and procedures that go beyon...
Affirming Official (CMMC)
The Affirming Official is the senior company representative who certifies CMMC compliance in SPRS under penalty of the False Claims Act, personally accountable for the accuracy of every control statement.
Air-gapped Network
An air-gapped network is physically isolated from the internet and every external network, with no wired, wireless, or cellular path in or out. Data moves only through controlled physical media.
Asset Management
Asset Management refers to the systematic process of developing, operating, maintaining, upgrading, and disposing of assets in a cost-effective manner. In the context of OT/IT cybersecurity, asset man...
Authentication Methods
Authentication methods are techniques used to verify the identity of a user, device, or system before granting access to a network or application. In the context of OT/IT cybersecurity, these methods...
Biometric Authentication
Biometric Authentication is a security process that verifies a user's identity based on unique biological characteristics, such as fingerprints or facial features. This method is increasingly utilized...
C3PAO
A C3PAO (CMMC Third-Party Assessor Organization) is a Cyber AB-authorized firm that runs the official CMMC Level 2 certification assessment for defense contractors handling Controlled Unclassified Information.
Change Management
Change Management is the systematic approach to dealing with the transition or transformation of an organization's goals, processes, or technologies. Within the realm of OT/IT cybersecurity, it specif...
Cloud Security
Cloud Security refers to the set of policies, technologies, and controls deployed to protect data, applications, and infrastructure associated with cloud computing environments. It encompasses a wide...
CMMC
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires defense contractors to prove they protect Federal Contract Information and Controlled Unclassified Information before they can win contracts.
CMMC Enduring Exception
A CMMC enduring exception documents that a specific asset cannot natively implement a required security control because of hardware or firmware limits. It does not waive the control; it requires a compensating control to cover the residual risk.
CMMC Level 1
CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, covering 15 basic safeguarding requirements from FAR 52.204-21 to protect Federal Contract Information, verified by annual self-assessment.
CMMC Level 2
CMMC Level 2 is the certification tier for defense contractors that handle Controlled Unclassified Information, requiring the 110 security controls of NIST SP 800-171 and, for most contracts, a third-party C3PAO assessment.
CMMC Shared Responsibility Matrix
A CMMC shared responsibility matrix maps every NIST 800-171 control to the party that enforces it, separating what a security tool handles, what the customer owns, and what needs compensating controls for OT assets.
Compensating Control (CMMC)
A compensating control is a security mechanism that provides equivalent protection when a NIST SP 800-171 control cannot be implemented on the asset itself, required whenever an asset qualifies for a CMMC Enduring Exception.
Compliance Auditing
Compliance auditing refers to the process of evaluating an organization's adherence to regulatory standards, policies, and guidelines. In the context of cybersecurity, it involves ensuring that system...
Compliance Framework
A compliance framework is a structured set of guidelines and best practices designed to help organizations meet regulatory requirements and manage risks effectively. In the context of OT/IT cybersecur...
Compliance Software
Compliance software is a specialized tool designed to help organizations manage and adhere to regulatory requirements, industry standards, and internal policies. It often integrates with Governance, R...
Configuration Management
Configuration Management (CM) is a process for maintaining consistency of a system's performance, functional, and physical attributes with its requirements, design, and operational information through...
Controlled Unclassified Information
Controlled Unclassified Information (CUI) is government information that is not classified but still requires safeguarding or dissemination controls under federal law. Defense contractors that handle it must protect it under NIST SP 800-171 and CMMC.
Credential Management
Credential Management refers to the processes and technologies used to securely store, manage, and utilize user credentials such as passwords, security tokens, and digital certificates. It ensures tha...
Critical Infrastructure Protection
Critical Infrastructure Protection (CIP) is the practice of securing the systems society depends on, energy, water, transportation, healthcare, and communications, against attacks and failures that would ripple far beyond the target.
Cross-Site Scripting
Cross-Site Scripting (XSS) is a type of web vulnerability that allows attackers to inject malicious scripts into webpages viewed by other users. This attack vector can be used to compromise the securi...
CUI Enclave
A CUI enclave is an isolated network segment holding every system that stores, processes, or transmits Controlled Unclassified Information, enforced by identity-based access rather than simple network separation.
Cyber Attack
A cyber attack is a deliberate attempt by an individual or organization to breach the information systems of another individual or organization. These attacks can target a wide range of digital assets...
Cyber-Physical Systems
Cyber-physical systems (CPS) tie computation and networking to physical processes through sensors and actuators, so software directly monitors and controls machinery, energy, and industrial operations in a feedback loop.
Cybersecurity Awareness Training
Cybersecurity Awareness Training is an educational process aimed at equipping employees and stakeholders with the knowledge and skills necessary to protect an organization's information systems from c...
Cybersecurity Frameworks
Cybersecurity frameworks are structured sets of guidelines and best practices designed to help organizations manage and reduce cybersecurity risks. They provide a strategic approach to securing inform...
Cybersecurity Incident (OT)
An OT cybersecurity incident is any event that threatens the safety, availability, or integrity of a control system. Stuxnet, Colonial Pipeline, Norsk Hydro, Oldsmar, and Ukraine grid attacks are the reference cases, each illustrates a different OT incident shape.
Cybersecurity Maturity
Cybersecurity maturity refers to the extent to which an organization has developed and optimized its cybersecurity practices across various dimensions, including technology, processes, and human facto...
›Browse all entries (147)
- Access Control
- Access Control List
- Advanced Cyber Hygiene
- Affirming Official (CMMC)
- Air-gapped Network
- Asset Management
- Authentication Methods
- Biometric Authentication
- C3PAO
- Change Management
- Cloud Security
- CMMC
- CMMC Enduring Exception
- CMMC Level 1
- CMMC Level 2
- CMMC Shared Responsibility Matrix
- Compensating Control (CMMC)
- Compliance Auditing
- Compliance Framework
- Compliance Software
- Configuration Management
- Controlled Unclassified Information
- Credential Management
- Critical Infrastructure Protection
- Cross-Site Scripting
- CUI Enclave
- Cyber Attack
- Cyber-Physical Systems
- Cybersecurity Awareness Training
- Cybersecurity Frameworks
- Cybersecurity Incident (OT)
- Cybersecurity Maturity
- Data Breach
- Data Encryption
- Data Integrity
- Data Loss Prevention
- Defense Contracting
- Defense Industrial Base
- Deny-by-Default (OT)
- Device Management
- DFARS (Defense Federal Acquisition Regulation Supplement)
- Digital Forensics
- Domestic Manufacturing
- Domestic Sourcing
- DTM 25-003
- Encrypted Email
- Encryption
- Endpoint Protection
- Export Control Classification Number
- Firewall
- Firewall Configuration
- GCC High
- Governance Risk and Compliance Software
- Identity and Access Management
- Identity Management
- IEC 62443
- Incident Response
- Industrial Control Systems Security
- Industrial Cybersecurity Standards
- Industrial DMZ
- Industrial Networking
- Information Governance
- Information Technology Security
- Insider Threat
- Intrusion Detection System
- Intrusion Prevention System
- IoT in Manufacturing
- IoT Security
- ISO/IEC 27001
- Least Privilege Principle
- Lollipop Architecture
- Machine Network
- Made in USA
- Malware in OT Environments
- Micro-DMZ
- Multi-Factor Authentication
- NERC CIP
- Network Access Control
- Network and Information Systems Directive
- Network Security
- Network Segmentation
- NIST SP 800-171
- NIST SP 800-82
- OIV et OSE (NIS2)
- Operational Technology Security
- OT/IT Convergence
- Overlay Networking (OT context)
- Passive Asset Discovery (OT)
- Password Management
- Password Policy
- Patch Management
- Patch Update
- Phishing in OT Environments
- Physical Security
- Physical Security Information Management
- Programmable Logic Controllers
- Protocol Filtering (OT)
- Public Key Infrastructure
- Purdue Model
- Ransomware in OT Environments
- Remote Access
- Remote Desktop Protocol
- Risk Assessment
- Risk Management
- Risk Management Framework (RMF for ICS/OT)
- Role-Based Access Control
- Root Cause Analysis
- Ruggedized Devices
- Secure Access Gateway
- Secure Communications
- Secure Email
- Secure File Sharing
- Secure Network
- Secure Sockets Layer and Transport Layer Security
- Security Audit
- Security Checklist
- Security Configuration
- Security Information and Event Management
- Security Patching
- Security Policy
- Security Tokens
- Server Room
- Single Sign-On
- Social Engineering
- Spear Phishing
- Specialized Asset (CMMC)
- SQL Injection
- Supervisory Control and Data Acquisition
- Supply Chain Security
- Third-Party Risk Management
- Threat Intelligence
- Transport Layer Security
- Two-Factor Authentication
- User Access Management
- User Authentication
- User Permissions
- Vendor Assessment
- VPN
- Vulnerability Assessment
- Vulnerability Management
- Wireless Encryption Standards
- Workstation
- Zero Trust Architecture
- Zero Trust for OT
- Zero Trust Network Access
- Zero Trust Security
- Zero-Day Exploit