S/MIME
See Secure Multipurpose Internet Mail Extensions (S/MIME).
sabotage
A criminal act committed against an organization by a knowledgeable employee.
safe harbor
A regulatory mechanism that includes a set of Safe Harbor Principles. The seven principles are notice, choice, onward transfer, security, data integrity, access, and enforcement. The goal is to prevent unauthorized disclosure of information, handledA regulatory mechanism that includes a set of Safe Harbor Principles. The seven principles are notice, choice, onward transfer, security, data integrity, access, and enforcement. The goal is to prevent unauthorized disclosure of information, handled by data processors and transmitted between data processors and the data controller. US companies can voluntarily opt into the program if they agree to abide by the seven principles and the requirements outlined in 15 frequently asked questions.
safeguard
Anything that removes a vulnerability or protects against one or more specific threats. Also referred to as a countermeasure.
sag
Momentary low voltage.
salami attack
An attack performed by gathering small amounts of data to construct something of greater value or higher sensitivity.
salt
A random number appended to a password before hashing to increase randomness and ensure uniqueness in the resulting stored hash value. This is also known as a cryptographic salt.
SAML
See Security Assertion Markup Language (SAML).
sampling
A form of data reduction that allows an auditor to quickly determine the important issues or events from an audit trail.
sandbox
A security boundary within which a Java applet executes.
sandboxing
A security technique that provides a security boundary for applications and prevents the application from interacting with other applications. Anti-malware applications use sandboxing techniques to test unknown applications. If the applicationA security technique that provides a security boundary for applications and prevents the application from interacting with other applications. Anti-malware applications use sandboxing techniques to test unknown applications. If the application displays suspicious characteristics, the sandboxing technique prevents the application from infecting other applications or the operating system.
sanitization
Any number of processes that prepares media for destruction. Sanitization is the process that ensures that data cannot be recovered by any means from destroyed or discarded media. Sanitization can also be the actual means by which media is destroyed. Media can be sanitized by purging or degaussing without physically destroying the media.
scanning
Similar to casing a neighborhood prior to a burglary, it's the process by which a potential intruder looks for possible entryways into a system. Scanning can indicate that illegal activity will follow, so it is a good idea to treat scans as incidents and to collect evidence of scanning activity.
scavenging
A form of dumpster diving performed electronically. Online scavenging searches for useful information in the remnants of data left over after processes or tasks are completed. This could include audit trails, log files, memory dumps, variable settings, port mappings, cached data, and so on.
scenario
In relation to risk assessment, it is a written description of a single major threat. The description focuses on how a threat would be instigated and what effects its occurrence could have on the organization, the IT infrastructure, and specific assets.
schema
The structure that holds the data that defines or describes a database. The schema is written using a Data Definition Language (DDL).
screen scraper or screen scraping
1) Remote control, remote access, or remote desktop- like services. 2) A technology that can allow an automated tool to interact with a human interface in order to parse the results to extract just the relevant information.
script kiddie
The malicious individual who doesn't understand the technology behind security vulnerabilities but downloads ready-to-use software (or scripts) from the Internet and uses them to launch attacks against systems.
scripted access
A method to automate the logon process with a script that provides the logon credentials to a system. It is considered a form of single sign-on.
search warrant
A document obtained through the judicial system that allows law enforcement personnel to acquire evidence from a location without first alerting the individual believed to have perpetrated a crime.
secondary evidence
A copy of evidence or an oral description of the contents of best evidence.
secondary memory
Magnetic/optical media and other storage devices that contain data not immediately available to the CPU.
secondary storage
Data repositories that include magnetic and optical media, such as tapes, disks, hard drives, and CD/DVD storage.
second-tier attack
An assault that relies on information or data gained from eavesdropping or other similar data-gathering techniques. In other words, it is an attack that is launched only after some other attack is completed.
secret
A government/military classification, used for data of a secret nature. Unauthorized disclosure of secret data could cause serious damage to national security.
secure communication protocol
A protocol that uses encryption to provide security for the data transmitted by it.
Secure Electronic Transaction (SET)
A security protocol for the transmission of transactions over the Internet. SET is based on RSA encryption and DES. SET had the support of major credit card companies, such as Visa and MasterCard. However, it has mostly been abandoned in light of newer and more secure alternatives.
Secure Hash Algorithm (SHA) [SHA-1, SHA-2, SHA-3]
A government standard hash function developed by the National Institute of Standards and Technology (NIST) and specified in an official government publication. SHA-1 creates a 160-bit hash value output. Members of the SHA-2 family create a range of hash value outputs: 224, 256, 384 or 512. SHA-3 was still in development at the time of this writing, but the Keccak algorithm has been selected for that emerging standard.
Secure HTTP (S-HTTP)
The second major protocol used to provide security on the World Wide Web.
Secure Multipurpose Internet Mail Extensions (S/MIME)
A protocol used to secure the transmission of email and attachments.
Secure Remote Procedure Call (S-RPC)
An authentication service. S-RPC is simply a means to prevent unauthorized execution of code on remote systems.
Secure Shell (SSH)
An end-to-end encryption technique. This suite of programs provides encrypted alternatives to common Internet applications such as FTP, Telnet, and rlogin.An end-to-end encryption technique. This suite of programs provides encrypted alternatives to common Internet applications such as FTP, Telnet, and rlogin. There are two versions of SSH. SSH1 supports the DES, 3DES, IDEA, and Blowfish algorithms. SSH2 drops support for DES and IDEA but adds support for several other algorithms.
Secure Sockets Layer (SSL)
An encryption protocol developed by Netscape to protect the communications between a web server and a web browser.
Security Assertion Markup Language (SAML)
An XML-based convention for communication authentication and authorization details between security domains, often over web protocols. SAML is often used to provide a web-based SSO solution.
security assessments
Comprehensive reviews of the security of a system, application, or other tested environment. During a security assessment, a trained information securityComprehensive reviews of the security of a system, application, or other tested environment. During a security assessment, a trained information security professional performs a risk assessment that identifies vulnerabilities in the tested environment that may allow a compromise and makes recommendations for remediation, as needed.
security association (SA)
In an IPSec session, the representation of the communication session and process of recording any configuration and status information about the connection.
security audits
Evaluations performed with the purpose of demonstrating the effectiveness of controls to a third party. Security audits use many of the same techniques followed during security assessments but must be performed by independent auditors. The staff members who design, implement and monitor controls for an organization have an inherent conflict of interest when evaluating the effectiveness of those controls.
security boundary
The line of intersection between any two areas, subnets, or environments that have different security requirements or needs.
security control baselines
A mandated set of security controls that provide a starting point for implementing security and ensure a minimum security standard.
security governance
The collection of practices related to supporting, defining, and directing the security efforts of an organization.
security ID
A form of physical identification; generally contains a picture of the subject and/or a magnetic strip with additional information about a subject.
security incident
See computer security incident.
security kernel
The core set of operating system services that handles all user/application requests for access to system resources.
security label
An assigned classification or sensitivity level used in security models to determine the level of security required to protect an object and prevent unauthorized access.
security management planning
The act of thoroughly and systematically designing procedural and policy documentation to reduce risk and then to maintain risk at an acceptable level for a given environment.
security mode
The US government has designated four approved security modes for systems that process classified information; see dedicated mode, system high mode, compartmented security mode, and multilevel mode.
security perimeter
The imaginary boundary that separates the trusted computing base from the rest of the system.
security policy
A document that defines the scope of security needs of an organization, prescribes solutions to manage security issues, and discusses the assets that need protection and the extent to which security solutions should go to provide the necessary protection.
security professional
Trained and experienced network, systems, and security engineer who is responsible for following the directives mandated by senior management.
security role
The part an individual plays in the overall scheme of security implementation and administration within an organization.
security target
The evaluation element from the Common Criteria for information technology security evaluation in which a vendor states the security features of its product.
security tests
Security tests verify that a control is functioning properly. These tests include automated scans, tool-assisted penetration tests, and manual attempts to undermine security. Security testing should take place on a regular schedule, with attention paid to each of the key security controls protecting an organization.
segment
The combination of Transport layer TCP header and payload.
segmentation
The act of subdividing a network into numerous smaller units. These smaller units, groupings, segments, or subnetworks (i.e., subnets) can be used to improve various aspects of the network. Segmentation can boost performance, reduce congestion, compartmentalize communication problems (such as broadcast storms), and provide security improvements through traffic isolation. Segments can be created by using switch- based VLANs, routers, or firewalls (as well as combinations of all of these).
semantic integrity mechanisms
A common security feature of a DBMS. This feature ensures that no structural or semantic rules are violated. It also checks that all stored data types are within valid domain ranges, that only logical values exist, and that any and all uniqueness constraints are met.
senior management
A person or group who is ultimately responsible for the security maintained by an organization and who should be most concerned about the protection of its assets. They must sign off on all policy issues, and they will be held liable for overall success or failure of a security solution. It is the responsibility of senior management to show prudent due care. Also referred to as organizational owner and upper management.
sensitive
A commercial business/private sector classification used for data that is more sensitive than public data. A negative impact could occur for the company if sensitive data is disclosed.
sensitivity
In regard to biometric devices, the level at which the device is configured for scanning.
separation of duties and responsibilities
A common practice to prevent any single subject from being able to circumvent or disable security mechanisms. By dividing core administration or high-authority responsibilities among several subjects, no one subject has sufficient access to perform significant malicious activities or bypass imposed security controls.
separation of privilege
The principle that builds on the principle of least privilege. It requires the use of granular access permissions-that is, different permissions for each type of privileged operation. This allows designers to assign some processes rights to perform certain supervisory functions without granting them unrestricted access to the system.
Sequenced Packet Exchange (SPX)
The Transport layer protocol of the IPX/SPX protocol suite from Novell.
sequential storage
Devices that require that you read (or speed past) all of the data physically stored prior to the desired location. A common example of a sequential storage device is a magnetic tape drive.
Serial Line Internet Protocol (SLIP)
An older technology developed to support TCP/IP communications over asynchronous serial connections, such as serial cables or modem dial- up.
service bureaus
Businesses that lease computer time through contractual agreements and provide all IT needs in the event of some disaster or business interruption that requires a disaster recovery plan or business continuity plan to be enacted. Also known as a cloud computing service.
service-level agreement (SLA)
A contractual obligation to your clients that requires you to implement sound BCP practices. Also used to assure acceptable levels of service from suppliers for sound BCP practices.
Service Organization Controls (SOC) Report
A report produced by an auditor that includes the results of security assessments of a cloud provider.
Service Provisioning Markup Language (SPML)
A markup language used with federated identity management systems to exchange user information for federated identity single sign-on purposes. It is derived from the Standard Generalized Markup Language (SGML), the Extensible Markup Language (XML), and the Generalized Markup Language (GML).
SESAME
A ticket-based authentication mechanism similar to Kerberos.
session hijacking
An attack that occurs when a malicious individual intercepts part of a communication between an authorized user and a resource and then uses a hijacking technique to take over the session and assume the identity of the authorized user.
Session layer
Layer 5 of the OSI model.
shared key authentication (SKA)
A connection scheme for wireless networks that requires that some form of authentication must take place before network communications can occur. The 802.11 standard defines one optional technique for SKA known asA connection scheme for wireless networks that requires that some form of authentication must take place before network communications can occur. The 802.11 standard defines one optional technique for SKA known as WEP.
shielded twisted-pair (STP)
A twisted-pair wire that includes a metal foil wrapper inside the outer sheath to provide additional protection from EMI.
shoulder surfing
The act of gathering information from a system by observing the monitor or the use of the keyboard by the operator.
shrink-wrap license agreement
A license written on the outside of software packaging. Such licenses get their name because they commonly include a clause stating that you acknowledge agreement to the terms of the contract simply by breaking the shrink-wrap seal on the package.
side-channel attack
A passive, noninvasive attack to observe the operation of a device. Side-channel attacks are used against smart cards. Common side-channel attacks are power monitoring attacks, timing attacks, and fault analysis attacks.
signature-based detection
The process used by antivirus software to identify potential virus infections on a system.
signature dynamics
When used as a biometric, the use of the pattern and speed of a person writing their signature to establish identity or provide authentication.
Simple Integrity Axiom (SI Axiom)
An axiom of the Biba model that states that a subject at a specific classification level cannot read data with a lower classification level. This is often shortened to "no read down."
Simple Key Management for IP (SKIP)
An encryption tool used to protect sessionless datagram protocols.
Simple Mail Transfer Protocol (SMTP)
The primary protocol used to move email messages from clients to servers and from server to server.
Simple Security Property (SS property)
A property of the Bell-LaPadula model that states that a subject at a specific classification level cannot read data with a higher classification level. This is often shortened to "no read up."
simulation tests
A test in which disaster recovery team members are presented with a scenario and asked to develop an appropriate response. Some of these response measures are then tested. This may involve the interruption of noncritical business activities and the use of some operational personnel.
single loss expectancy (SLE)
The cost associated with a single realized risk against a specific asset. The SLE indicates the exact amount of loss an organization would experience if an asset were harmed by a specific threat. SLE = asset value ($) x exposure factor (EF).
single point of failure
Any element of an infrastructure-such as a device, service, protocol, or communication link-that would cause total or significant downtime if compromised, violated, or destroyed, affecting the ability of members of your organization to perform essential work tasks.
single sign-on (SSO)
A mechanism that allows subjects to authenticate themselves only once to a system. With SSO, once subjects are authenticated, they can freely roam the network and access resources and services without being rechallenged for authentication.
single state
Systems that require the use of policy mechanisms to manage information at different levels. In this type of arrangement, security administrators approve a processor and system to handle only one security level at a time.
single-use passwords
A variant of dynamic passwords that are changed every time they are used.
site survey
A formal assessment of wireless signal strength, quality, and interference using a RF signal detector.
Skipjack
Associated with the Escrowed Encryption Standard, an algorithm that operates on 64-bit blocks of text. It uses an 80-bit key and supports the same four modes of operation supported by DES. Skipjack was proposed but never implemented by the US government. It provides the cryptographic routines supporting the Clipper and Capstone high-speed encryption chips designed for mainstream commercial use.
sliding windows
The ability of TCP to dynamically alter its transmission window size based on link reliability.
smart card
Credit-card-sized ID, badge, or security pass that has a magnetic strip,Credit-card-sized ID, badge, or security pass that has a magnetic strip, bar code, or integrated circuit chip embedded in it. Smart cards can contain information about the authorized bearer that can be used for identification and/or authentication purposes.
smurf attack
A type of DoS. A smurf attack occurs when an amplifying server or network is used to flood a victim with useless data.
sniffer attack
Any activity that results in a malicious user obtaining information about a network or the traffic over that network. A sniffer is often a packet-capturing program that duplicates the contents of packets traveling over the network medium into a file. Also referred to as a snooping attack.
sniffing
A form of network traffic monitoring. Sniffing often involves the capture or duplication of network traffic for examination, re-creation, and extraction.
sniping
Using an automated agent to submit a last-second bid on an online auction.
snooping attack
See sniffer attack.
social engineering
A skill by which an unauthorized person gains the trust of someone inside an organization and encourages the victim to make a change to the IT system in order to grant the attacker access. It can also be used as a means to trick a victim into disclosing information to the attacker.
socket
Another name for a port.
software analysis
Conducting forensic reviews of applications or the activity that takes place within a running application.
Software as a Service (SaaS)
A cloud computing concept that provides on-demand online access to specific software applications or suites without the need for local installation.
software-defined networks (SDN)
A unique approach to network operation, design, and management. The concept is based on the theory that the complexities of a traditional network with on-device configuration (i.e., routers and switches) often forceA unique approach to network operation, design, and management. The concept is based on the theory that the complexities of a traditional network with on-device configuration (i.e., routers and switches) often force an organization to stick with a single device vendor, such as Cisco, and limit the flexibility of the network to changing physical and business conditions. SDN aims at separating the infrastructure layer (i.e., hardware and hardware-based settings) from the control layer (i.e., network services of data transmission management).
software escrow arrangement
A tool used to protect a company against the failure of a software developer to provide adequate support for its products or against the possibility that the developer will go out of business and no technical support will be available for the product.
software IP encryption (swiPe)
A layer 3 security protocol for IP. It provides authentication, integrity, and confidentiality using an encapsulation protocol.
spam
The term describing unwanted email, newsgroup, or discussion forum messages. Spam can be as innocuous as an advertisement from a well-meaning vendor or as malignant as floods of unrequested messages with viruses or Trojan horses attached.
spamming attacks or spamming
Sending significant amounts of spam to a system in order to cause a DoS or general irritation, consume storage space, or consume bandwidth and processing capabilities.
spear phishing
A form of phishing that targets a specific group of individuals.
spike
Momentary high voltage.
split knowledge
The specific application of the ideas of separation of duties and two-man control into a single solution. The basic idea is that the information or privilege required to perform an operation is divided among multiple users. This ensures that no single person has sufficient privileges to compromise the security of the environment.
SPML
See Service Provisioning Markup Language.
spoofing
The act of replacing the valid source and/or destination IP address and node numbers with false ones.
spoofing attack
Any attack that involves spoofed or modified packets.
spread spectrum
A means or method of communication that occurs over multiple frequencies at the same time.
spyware
Software that monitors your actions and transmits important details to a remote system that spies on your activity. Sometimes used for malicious and illicit purposes, such as identity theft or account takeover.
SQL injection
An attack against vulnerable web applications where a hacker submits SQL database expressions and script code in order to bypass authentication and interact directly with the DBMS or underlying operating system.
stand-alone mode
A wireless network that uses a wireless access point to connect wireless clients together, but does not offer any access to a wired network.
standards
Documents that define compulsory requirements for the homogenous use of hardware, software, technology, and security controls. They provide a course of action by which technology and procedures are uniformly implemented throughout an organization. Standards are tactical documents that define steps or methods to accomplish the goals and overall direction defined by security policies.
state
A snapshot of a system at a specific instance in time.
state machine model
A system that is designed so that no matter what function is performed, it is always a secure system.
stateful inspection firewall
A firewall that evaluates the state or the context of network traffic. By examining source and destination address, application usage, source of origin, and relationship between current packets with the previous packets of the same session, stateful inspection firewalls are able to grant a broader range of access for authorized users and activities and actively watch for and block unauthorized users and activities. Stateful inspection firewalls are known as third-generation firewalls.
stateful NAT
The ability or means by which NAT maintains information about the communication sessions between clients and external systems. NAT operates byThe ability or means by which NAT maintains information about the communication sessions between clients and external systems. NAT operates by maintaining a mapping between requests made by internal clients, a client's internal IP address, and the IP address of the Internet service contacted.
static packet-filtering firewall
A firewall that filters traffic by examining data from a message header. Usually the rules are concerned with source, destination, and port addresses. Static packet-filtering firewalls as known as first-generation firewalls.
static password
Password that does not change over time or that remains the same for a significant period of time.
static system or static environment
A set of conditions, events, and surroundings that don't change. In theory, once understood, a static environment doesn't offer new or surprising elements. A static IT environment is any system that is intended to remain unchanged by users and administrators. The goal is to prevent or at least reduce the possibility of a user implementing change that could result in reduced security or functional operation.
static testing
Evaluates the security of software without running it by analyzing either the source code or the compiled application.
static token
A physical means to provide identity, usually not employed as an authentication factor. Examples include a swipe card, a smart card, a floppy disk, a USB RAM dongle, or even something as simple as a key to operate a physical lock.
station set identifier (SSID)
The name of a wireless network that each wireless client must know in order to communicate with the host access point.
statistical attack
This type of attack exploits statistical weaknesses in a cryptosystem, such as such as floating-point errors or an inability to produce random numbers. It attempts to find vulnerabilities in the hardware or operating system hosting the cryptography application.
statistical intrusion detection
See behavior-based detection.
stealth virus
A virus that hides itself by tampering with the operating system to fool antivirus packages into thinking that everything is functioning normally.
steganography
The act of embedding messages within another message, commonly used within an image or a WAV file.
stop error
The security response of an operating system, such as Windows, when an application performs an illegal operation, such as accessing hardware or modifying/ accessing the memory space of another process.
stopped state
The state in which a process is finished or must be terminated. At this point, the operating system can recover all memory and other resources allocated to the process and reuse them for other processes as needed.
storage segmentation
A device management technique used to artificially compartmentalize various types or values of data on a storage medium. On a mobile device, the device manufacturer and/or the service provider may use storage segmentation to isolate the device's OS and preinstalled apps from user-installed apps and user data. Some mobile device-management systems further impose storage segmentation in order to separate company data and apps from user data and apps.
store-and-forward device
A networking device that uses a memory buffer to store packets until they can be forwarded onto a slower network segment.
strategic plan
A long-term plan that is fairly stable. It defines the organization's goals, mission, and objectives. A strategic plan is useful for about five years if it is maintained and updated annually. The strategic plan also serves as the planning horizon.
stream attack
A type of DoS. A stream attack occurs when a large number of packets are sent to numerous ports on the victim system using random source and sequence numbers. The processing performed by the victim system attempting to make sense of the data will result in a DoS. Also referred to as flooding.
stream ciphers
Ciphers that operate on each character or bit of a message (or data stream) one character/bit at a time.
streaming audio
An audio transmission that is being presented to the end user as it is received based on an ongoing transmission from the provider/server. Streaming media is commonly served over the Internet either in real time (i.e., live) or on demand.
streaming video
A video transmission that is being presented to the end user as it is received based on an ongoing transmission from the provider/server. Streaming media is commonly served over the Internet either in real time (i.e., live) or on demand.
strong password
Password that is resistant to dictionary and brute-force attacks.
Structured Query Language (SQL)
The standard language used by relational databases to enter and extract the information stored in them.
structured walkthrough
A type of disaster recovery test, often referred to as a "table-top exercise," in which members of the disaster recovery team gather in a large conference room and role-play a disaster scenario.
subject
An active entity that seeks information about or data from passive objects through the exercise of access. A subject can be a user, a program, a process, a file, a computer, a database, and so on.
subpoena
A court order that compels an individual or organization to surrender evidence or to appear in court.
substitution cipher
Cipher that uses an encryption algorithm to replace each character or bit of the plain-text message with a different character, such as a Caesar cipher.
supervisor state (or supervisory state)
The state in which a process is operating in a privileged, all-access mode.
supervisory control and data acquisition (SCADA)
An ICS unit that can operate as a stand-alone device, be networked together with other SCADA systems, or be networked with traditional IT systems. Most SCADA systems are designed with minimal human interfaces. Often, they use mechanical buttons and knobs or simple LCD screen interfaces (similar to what you might have on a business printer or a GPS navigation device). However, networked SCADA devices may have more complex remote-control software interfaces.
supervisory mode
Mode in which processes at layer 0 run. Layer 0 is the ring where the operating system itself resides.
surge
Prolonged high voltage.
Sutherland model
An integrity model that focuses on preventing interference in support of integrity.
swIPe
See software IP encryption (swIPe).
switch
A network device that is an intelligent hub because it knows the addresses of the systems connected on each outbound port. Instead of repeating traffic on every outbound port, a switch repeats only traffic out of the port on which the destination is known to exist. Switches offer greater efficiency for traffic delivery, create separate broadcast and collision domains, and improve the overall throughput of data.
Switched Multimegabit Data Service (SMDS)
A connectionless network communication service. SMDS provides bandwidth on demand. SMDS is a preferred connection mechanism for linking remote LANs that communicate infrequently.
switched virtual circuit (SVC)
A virtual circuit that must be rebuilt each time it is used; similar to a dial-up connection.
symmetric key
An algorithm that relies on a "shared secret" encryption key that is distributed to all members who participate in communications. This key is used by all parties to both encrypt and decrypt messages.
symmetric multiprocessing (SMP)
A type of system in which the processors share not only a common operating system but also a common data bus and memory resources. In this type of arrangement, it is not normally possible to use more than 16 processors.
SYN flood attack
A type of DoS attack. A SYN flood attack is waged by not sending the final ACK packet, which breaks the standard three-way handshake used by TCP/IP to initiate communication sessions.
Synchronous Data Link Control (SDLC)
A layer 2 protocol employed by networks with dedicated or leased lines. SDLC was developed by IBM for remote communications with SNA systems. SDLC is a bit-oriented synchronous protocol.
synchronous dynamic password token
Token used in a token device that generates passwords at fixed time intervals. Time interval tokens require that the clock of the authentication server and the token device be synchronized. The generated password is entered by the subject along with a PIN, passphrase, or password.
synthetic transactions
Scripted transactions with known expected results. The testers run the synthetic transactions against the tested code and then compare the output of the transactions to the expected state. Any deviations between the actual and expected results represent possible flaws in the code and must be further investigated.
system call
A process by which an object in a less-trusted protection ring requests access to resources or functionality by objects in more trusted protection rings.
system compromise
A situation in which the security of a system has been breached. Also known as a security breach, security compromise, intrusion, or violation.
system high mode
See system-high security mode.
system-high security mode
Mode in which systems are authorized to process only information that all system users are cleared to read and have a valid need to know. Systems running in this mode are not trusted to maintain separation between security levels, and all information processed by these systems must be handled as if it were classified at the same level as the most highly classified information processed by the system.
system resilience
The ability of a system to maintain an acceptable level of service during an adverse event. It relies on fault-tolerant components and also effective intrusion- detection and intrusion-prevention systems.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics