OAuth
An open SSO standard designed to work with HTTP and it allows users to log on with one account across multiple sites/locations.
object
A passive entity that provides information or data to subjects. An object can be a file, a database, a computer, a program, a process, a file, a printer, a storage media, and so on.
object linking and embedding (OLE)
A Microsoft technology used to link data objects into or from multiple files or sources on a computer.
object-oriented programming (OOP)
A method of programming that uses encapsulated code sets called objects. OOP is best suited for eliminating error propagation and mimicking or modeling the real world.
object-relational database
A relational database combined with an object-oriented programming environment.
off-boarding
The removal of an employee's identity from the identity and access management system once they have left the organization.
on-boarding
The process of adding new employees to the identity and access management system of an organization. The on-boarding process is also used when the role or position of an employee changes or when they are awarded additional levels of privilege or access.
one-time pad
An extremely powerful type of substitution cipher that uses a different key for each message. The key length is the same length as the message.
one-time password
A variant of dynamic passwords that is changed every time it is used.
one-upped constructed password
A password with a single-character difference from its present form in a dictionary list.
one-way encryption
A mathematical function performed on passwords, messages, CRCs, and so on, that creates a cryptographic code that cannot be reversed.
one-way function
A mathematical operation that easily produces output values for each possible combination of inputs but makes it impossible to retrieve the input values. Public key cryptosystems are all based on some sort of one-way function.
OpenID
An open SSO standard maintained by the OpenID Foundation that can be used in conjunction with OAuth or on its own.
open relay agent
An SMTP server that is configured to accept email messages from any source and will forward them on to their destination. Open relay agents are commonly hijacked by spammers.
open system authentication (OSA)
A connection scheme for wireless networks where no real authentication is required; as long as a radio signal can be transmitted between the client and WAP, communications are allowed.
Open Systems Interconnection (OSI) model
A standard model developed to establish a common communication structure or standard for all computer systems.
Open Web Application Security Project (OWASP)
A nonprofit security project focusing on improving security for online or web-based applications.
operational plans
Short-term and highly detailed plans based on the strategic and tactical plans. Operational plans are valid or useful only for a short time. They must be updated often (such as monthly or quarterly) to retain compliance with tactical plans. Operational plans are detailed plans on how to accomplish the various goals of the organization.
operations security triple
The relationship between asset, vulnerability, and threat.
OR
An operation (represented by the the input values is true. symbol) that checks to see whether at least one of
organizational owner
See senior management.
Orthogonal Frequency-Division Multiplexing (OFDM)
A wireless technology that employs a digital multicarrier modulation scheme that allows for a more tightly compacted transmission.
OSI model
See Open Systems Interconnection (OSI) model.
Output Feedback (OFB)
A mode in which the Data Encryption Standard XORs plain text with a seed value. For the first encrypted block, an initialization vector is used to create the seed value. Future seed values are derived by running the DES algorithm on the preceding seed value. The major advantage of OFB mode is that transmission errors do not propagate to affect the decryption of future blocks.
overt channel
An obvious, visible, detectable, known method of communicating that is addressed by a security policy and subsequently controlled by logical or technical access controls.
overwriting
See clearing.
OWASP
See Open Web Application Security Project (OWASP).
owner
The person who has final corporate responsibility for the protection and storage of data. The owner may be liable for negligence if they fail to perform due diligence in establishing and enforcing security policy to protect and sustain sensitive data. The owner is typically the CEO, president, or department head.
ownership
The formal assignment of responsibility (i.e., making someone an owner) to an individual or group.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics