backdoor or back door
Undocumented command sequences that allow individuals with knowledge of the backdoor to bypass normal access restrictions. Backdoors may be placed and left by the manufacturer or planted by hackers using exploits.
badges
Forms of physical identification and/or of electronic access control devices.
bandwidth on demand
A feature/benefit provided by service providers that allows clients to consume more bandwidth when needed and if the carrier network has the capacity. Such consumption is often charged at a much higher rate.
Base+Offset addressing
An addressing scheme that uses a value stored in one of the CPU's registers as the base location from which to begin counting. The CPU then adds the offset supplied with the instruction to that base address and retrieves the operand from the computed memory location.
baseband
A communication medium that supports only a single communication signal at a time.
baseline
The minimum level of security that every system throughout the organization must meet. A baseline can be more than a security baseline. It can also be a performance baseline (used by behavior-based IDSs) or a configuration baseline (used for configuration management).
Basic Input/Output System (BIOS)
The operating system-independent primitive instructions that a computer needs to start up and load the operating system from disk.
Basic Rate Interface (BRI)
An ISDN service type that provides two B, or data, channels and one D, or management, channel. Each B channel offers 64 Kbps, and the D channel offers 16 Kbps.
beacon frame
A type of wireless network packet that broadcasts the presence of the wireless network by announcing the network's SSID or network name.
behavior
In the context of object-oriented programming terminology and techniques, the results or output from an object after processing a message using a method.
behavior-based detection
An intrusion discovery mechanism used by IDS. Behavior- based detection finds out about the normal activities and events on your system through watching and learning. Once it has accumulated enough data about normal activity, it can detect abnormal and possible malicious activities and events. Also known as statistical intrusion detection, anomaly detection, and heuristics-based detection.
Bell-LaPadula model
A confidentiality-focused security model based on the state machine model and employing mandatory access controls and the lattice model.
best evidence rule
A rule that states that when a document is used as evidence in a court proceeding, the original document must be introduced. Copies will not be accepted as evidence unless certain exceptions to the rule apply.
Biba model
An integrity-focused security model based on the state machine model and employing mandatory access controls and the lattice model.
binary mathematics
The rules of computation of bits and bytes used by a computer. Also known as Boolean.
bind variable
A placeholder for SQL literal values, such as numbers or character strings.
biometric factors
Characteristics of any person that can be used to identify or authenticate the person. Physiological biometric methods include fingerprints, face scans, retina scans, iris scans, palm scans, hand geometry, and voice patterns. Behavioral biometric methods include signature dynamics and keystroke patterns.
biometrics
The use of human physiological or behavioral characteristics as authentication factors for logical access and identification for physical access.
birthday attack
An attack in which the malicious individual seeks to substitute a digitally signed communication with a different message that produces the same message digest, thereby maintaining the validity of the original digital signature. This is based on the statistical anomaly that in a room with 23 people, the probability of two of more people having the same birthday is greater than 50 percent.
bit flipping
The activity of changing a bit to its opposite value. A technique commonly used in fuzzing to slightly modify input data.
bit size
The number of binary digits or bits in a value, such as a key, block size, or hash value.
black-box testing
A form of program testing that examines the input and output of a program without focusing on its internal logical structures.
black box
A device used to manipulate line voltages to steal long-distance services.
blackout
A complete loss of power.
block cipher
A cipher that applies the encryption algorithm to an entire message block at the same time. Transposition ciphers are examples of block ciphers.
Blowfish
A block cipher that operates on 64-bit blocks of text and uses variable-length keys ranging from a relatively insecure 32 bits to an extremely strong 448 bits.
blue box
A device used to simulate 2600 Hz tones to interact directly with telephone network trunk systems (that is, backbones).
bluebugging
An attack that grants hackers remote control over the features and functions of a Bluetooth device. This could include the ability to turn on the microphone to use the phone as an audio bug.
bluejacking
Hijacking a Bluetooth connection to eavesdrop or extract information from devices.
bluesnarfing
An attack that allows hackers to connect with your Bluetooth devices without your knowledge and extract information from them. This form of attack can offer attackers access to your contact lists, your data, and even your conversations.
Bluetooth (802.15)
A wireless standard commonly used to pair accessories to mobile phones or computers.
boot sector
The portion of a storage device used to load the operating system and the types of viruses that attack that process.
bot
An intelligent agent that continuously crawls a variety of websites retrieving and processing data on behalf of the user.
botmaster
The hacker who is in control of a botnet. Also called bot herder.
botnet
A collection of computers (sometimes thousands or even millions!) across the Internet under the control of an attacker known as the botmaster.
bounds
The limits to the memory and resources a process can access.
breach
The occurrence of a security mechanism being bypassed or thwarted by a threat agent.
Brewer and Nash model (aka Chinese Wall)
A security model designed to permit access controls to change dynamically based on a user's previous activity (making it a kind of state machine model as well).
bridge
A network device used to connect networks with different speeds, cable types, or topologies that still use the same protocol. A bridge is a layer 2 device.
bridge mode
A form of wireless access point deployment that is used to link two wired networks together over a wireless bridged connection.
bring your own device (BYOD)
A policy allowing employees to connect their personally owned device to an organization's network. While the devices are the property of their owners, organizational data stored on the devices is still an asset of the organization.
broadband
A communication medium that supports multiple communication signals simultaneously.
broadcast
A communications transmission to multiple but unidentified recipients.
broadcast address
The address that all devices within a given network grouping or container receive data on.
broadcast domain
A group of networked systems in which all other members receive a broadcast signal when one of the members of the group transmits it.
broadcast technology
A communication system based on or dependent on broadcasts rather than unicast signaling.
brouter
A network device that first attempts to route and then defaults to bridging if routing fails.
brownout
A period of prolonged low voltage.
brute force
An attack pattern characterized by a mechanical series of sequential or combinatorial inputs utilized in an automated attempt to identify security properties (usually passwords) in a given system (see brute-force attack).
brute-force attack
An attack made against a system to discover the password to a known identity (in other words, username). A brute-force attack uses a systematic trial of all possible character combinations to discover an account's password.
buffer overflow
A vulnerability that can cause a system to crash or allow the user to execute shell commands and gain access to the system. Buffer overflow vulnerabilities are especially prevalent in code developed rapidly for the Web using CGI or other languages that allow unskilled programmers to quickly create interactive web pages.
business attack
An attack that focuses on illegally obtaining an organization's confidential information.
business continuity planning (BCP)
The assessment of a variety of risks to organizational processes and the creation of policies, plans, and procedures to minimize the impact those risks might have on the organization if they were to occur.
business impact analysis (BIA)
See business impact assessment (BIA).
business impact assessment (BIA)
An analysis that identifies the resources that are critical to an organization's ongoing viability and the threats posed to those resources. It also assesses the likelihood that each threat will actually occur and the impact those occurrences will have on the business. Also known as business impact analysis (BIA).

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics