NAC
See network access control (NAC).
natural disaster
A disaster that is not caused by man, such as earthquakes, mudslides, sinkholes, fires, floods, hurricanes, tornadoes, falling rocks, snow, rainfall, ice, humidity, heat, extreme cold, and so on.
need to know
The requirement to have access to, knowledge about, or possession of data or a resource in order to perform specific work tasks. A user must have a need to know in order to gain access to data or resources. Even if that user has an equal or greater security classification than the requested information, if they do not have a need to know, they are denied access.
negligence
Failure to exercise the degree of care considered reasonable under the circumstances, resulting in an unintended injury to another party.
Nessus
A vulnerability scanner.
NetBEUI
NetBEUI (NetBIOS Extended User Interface, aka NetBIOS Frame protocol or NBF) is most widely known as a Microsoft protocol developed in 1985 to support file and printer sharing. Microsoft has enabled support of NetBEUI on modern networks by devising NBT (NetBIOS over TCP/IP). This in turn supports the Windows sharing protocol of SMB (Server Message Block), which is also known as CIFS (Common Internet File System). NetBEUI is no longer supported as a lower-layer protocol; only its SMB and CIFS variants are still in use.
network access control (NAC)
A concept of controlling access to an environment through strict adherence to and enforcement of a security policy. The goals of NAC are to prevent/reduce zero-day attacks, enforce security policy compliance throughout the network, and use identities to perform access control.
Network Address Translation (NAT)
A mechanism for converting the internal private IP addresses found in packet headers into public IP addresses for transmission over the Internet.
network analysis or network forensic analysis
A means of collecting and correlating information from disparate networked sources and producing as comprehensive a picture of network activity as possible.
network-based IDS (NIDS)
An IDS installed onto a host to monitor a network. Network- based IDSs detect attacks or event anomalies through the capture and evaluation of network packets.
network discovery scanning
A variety of techniques used to scan a range of IP addresses, searching for systems with open network ports. Network discovery scanners do not actually probe systems for vulnerabilities but provide a report showing the systems detected on a network and the list of ports that are exposed through the network and server firewalls that lie on the network path between the scanner and the scanned system.
Network layer
Layer 3 of the OSI model.
network monitoring
The act of monitoring traffic patterns to obtain information about a network.
network segmentation
See segmentation.
network topology (aka physical topology)
The physical layout and organization of computers and networking devices.
network vulnerability scanning
See vulnerability scan.
neural network
A system in which a long chain of computational decisions that feed into each other and eventually add up to produce the desired output is set up.
next-generation firewall
see unified threat management.
nmap
A penetration testing tool capable of performing port scans, ping sweeps, banner grabbing, network discovery, and more.
noise
A steady interfering disturbance.
nonce
A random number generator variable used in cryptography software; creates a new and unique value every time it is used, often based on a timestamped seed value.
noncompete agreement (NCA)
A document that attempts to prevent an employee with special knowledge of secrets from one organization from working in a competingA document that attempts to prevent an employee with special knowledge of secrets from one organization from working in a competing organization in order to prevent that second organization from benefiting from the worker's special knowledge of secrets.
nondisclosure agreement (NDA)
A document used to protect the confidential information within an organization from being disclosed by a former employee. When a person signs an NDA, they agree not to disclose any information that is defined asA document used to protect the confidential information within an organization from being disclosed by a former employee. When a person signs an NDA, they agree not to disclose any information that is defined as confidential to anyone outside the organization. Often, violations of an NDA are met with strict penalties.
nondiscretionary access control
An access control mechanism that regulates subject access to objects by using roles or tasks.
noninterference model
A model loosely based on the information flow model. The noninterference model is concerned with the actions of one subject affecting the system state or actions of another subject.
non-IP protocols
Non-IP protocols are protocols that serve as an alternative to IP at the OSI Network layer (3). In the past, non-IP protocols were widely used. However, with the dominance and success of TCP/IP, non-IP protocols have become the purview of special- purpose networks. The three most recognized non-IP protocols are IPX, AppleTalk, and NetBEUI.
nonrepudiation
A feature of a security control or an application that prevents the sender of a message or the subject of an activity or event from denying that the event occurred.
nonvolatile
See nonvolatile storage.
nonvolatile storage
A storage system that does not depend on the presence of power to maintain its contents, such as magnetic/optical media and nonvolatile RAM (NVRAM).
normal forms
Various levels of database organization designed to improve efficiency.
normalization
The database process that removes redundant data and ensures that all attributes are dependent on the primary key.
NOT
An operation (represented by the > symbol) that reverses the value of an input variable. This function operates on only one variable at a time.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics