LAN extender
A remote access, multilayer switch used to connect distant networks over WAN links. This is a strange beast of a device in that it creates WANs, but marketers of this device steer clear of the term WAN and use only the terms LAN and extended LAN. The idea behind this device was to make the terminology easier to understand and thus make the device easier to sell than a more conventional WAN device grounded in complex concepts and terms.
land attack
A type of DoS. A land attack occurs when the attacker sends numerous SYN packets to a victim and the SYN packets have been spoofed to use the same source and destination IP address and port number as the victim's. This causes the victim to thinkA type of DoS. A land attack occurs when the attacker sends numerous SYN packets to a victim and the SYN packets have been spoofed to use the same source and destination IP address and port number as the victim's. This causes the victim to think it sent a TCP/IP session opening packet to itself, which causes a system failure, usually resulting in a freeze, crash, or reboot.
lattice-based access control
A variation of nondiscretionary access controls. Lattice- based access controls define upper and lower bounds of access for every relationship between a subject and an object. These boundaries can be arbitrary, but they usually follow the military or corporate security label levels.
layer 1
The Physical layer of the OSI model.
layer 2
The Data Link layer of the OSI model.
layer 3
The Network layer of the OSI model.
layer 4
The Transport layer of the OSI model.
layer 5
The Session layer of the OSI model.
layer 6
The Presentation layer of the OSI model.
layer 7
The Application layer of the OSI model.
Layer 2 Forwarding (L2F)
A protocol developed by Cisco as a mutual authentication tunneling mechanism. L2F does not offer encryption.
Layer 2 Tunneling Protocol (L2TP)
A point-to-point tunnel protocol developed by combining elements from PPTP and L2F. L2TP lacks a built-in encryption scheme but typically relies on IPSec as its security mechanism.
layering
The use of multiple security controls in series to provide for maximum effectiveness of security deployment.
learning rule
See delta rule.
licensing
A contract that states how a product is to be used.
life cycle assurance
An assessment of the trust or reliability of a product based on its concepts of design, architecture, creation, testing, and distribution. Ultimately, a judgment as to whether a product was designed with security as a central feature.
lighting
One of the most commonly used forms of perimeter security control. The primary purpose of lighting is to discourage casual intruders, trespassers, prowlers, and would-be thieves who would rather perform their malicious activities in the dark.
link encryption
An encryption technique that protects entire communications circuits by creating a secure tunnel between two points. This is done by using either a hardware or software solution that encrypts all traffic entering one end of the tunnel and decrypts all traffic exiting the other end of the tunnel.
link state routing protocol
A routing protocol that maintains a topography map of all connected networks and uses this map to determine the shortest path to the destination.
local alarm systems
Alarm systems that broadcast an audible signal that can be easily heard up to 400 feet away. Additionally, local alarm systems must be protected from tampering and disablement, usually by security guards. In order for a local alarm system to be effective, there must be a security team or guards positioned nearby who can respond when the alarm is triggered.
local area network (LAN)
A network that is geographically limited, such as within a single office, building, or city block.
local cache
Anything that is temporarily stored on the client for future reuse. There are many local caches on a typical client, including ARP cache, DNS cache, and Internet files cache.
log analysis
A detailed and systematic form of monitoring. The logged information is analyzed in detail to look for trends and patterns as well as abnormal, unauthorized, illegal, and policy-violating activities.
logging
The activity of recording information about events or occurrences to a log file or database.
logic bomb
Malicious code objects that infect a system and lie dormant until they are triggered by the occurrence of one or more conditions.
logical access control
A hardware or software mechanism used to manage access to resources and systems and provide protection for them. They are the same as technical access controls. Examples of logical or technical access controls include encryption, smart cards, passwords, biometrics, constrained interfaces, access control lists, protocols, firewalls, routers, intrusion detection systems, and clipping levels.
logical topology
The logical operation of a network. It defines the arrangement and organization of devices as well as the means used to communicate to and with each other. Also known as signal topology.
logon credentials
The identity and the authentication factors offered by a subject to establish access.
logon script
A script that runs at the moment of user logon. A logon script is often used to map local drive letters to network shares, to launch programs, or to open links to often accessed systems.
loopback address
The IP address used to create a software interface that connects to itself via TCP/IP. The loopback address is handled by software alone. It permits testing of the TCP/IP protocol stack even if network interfaces or their device drivers are missing or damaged.
loss potential
See exposure factor (EF).
Low Water-Mark Mandatory Access Control (LOMAC)
A loadable kernel module for Linux designed to protect the integrity of processes and data. It is an OS security architecture extension or enhancement that provides flexible support for security policies.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics