darknet
An unused portion of network space used to monitor for network-based attacks and traffic.
data analytics
The science of raw data examination with the focus of extracting useful information out of the bulk information set. The results of data analytics could focus on important outliers or exceptions to normal or standard items, a summary of all data items, or some focused extraction and organization of interesting information.
data circuit-terminating equipment (DCE)
A networking device that performs the actual transmission of data over the Frame Relay as well as establishing and maintaining the virtual circuit for the customer.
data classification
Grouping data under labels for the purpose of applying security controls and access restrictions.
data controller
In the context of a data processor, as defined by EU data protection laws, the person or entity that controls processing of the data.
data custodian
The user who is assigned the task of implementing the prescribed protection defined by the security policy and upper management. The data custodian performs any and all activities necessary to provide adequate protection for data and to fulfill the requirements and responsibilities delegated to them from upper management.
Data Definition Language (DDL)
The database programming language that allows for the creation and modification of the database's structure (known as the schema).
data dictionary
Central repository of data elements and their relationships. Stores critical information about data usage, relationships, sources, and formats.
data diddling
The act of making small changes to data, typically malicious in intent.
Data Encryption Standard (DES)
A standard cryptosystem proposed in 1977 for all government communications. DES and 3DES were superseded by Advanced Encryption Standard (AES) in December 2001.
data extraction
The process of extracting elements of data from a large body of data to construct a meaningful representation or summary of the whole.
datagram data hiding Data Link layer
The combination of Transport layer UDP header and payload. The process of preventing data from being known by a subject. Layer 2 of the OSI model.
data loss prevention (DLP)
Systems that attempt to detect and block data exfiltration attempts.
Data Manipulation Language (DML)
The database programming language that allows users to interact with the data contained within the schema.
data mart
The storage facility used to secure metadata.
data mining
A technique or tool that allows analysts to comb through data warehouses and look for potential correlated information amid the historical data.
data owner
The person responsible for classifying information for placement and protection within the security solution.
data processor
The EU data protection law defines a data processor as "a natural or legal person which processes personal data solely on behalf of the data controller."
data remanence
Data that remains on media after the data has been supposedly removed. Purging and sanitization methods attempt to ensure that all data is removed from media without any data remanence.
data steward
See data custodian.
data stream
Data from an application sent into a protocol stack. The data stream becomes the initial payload of the top layer protocol.
data terminal equipment (DTE)
A networking device that acts like a router or a switch and provides the customer's network access to the Frame Relay network.
data warehouse
Large databases used to store large amounts of information from a variety of databases for use in specialized analysis techniques.
database
An electronic filing system for organizing collections of information. Most databases are organized by files, records, and fields.
database contamination
What happens when data or records of different values, classifications, security domains, and the like are co-mingled or mixed together. It can be a form of integrity and confidentiality violation.
database management system (DBMS)
An application that enables the storage, modification, and extraction of information from a database.
database partitioning
The act of dividing a database into smaller sections or individual databases; often employed to segregate content with varying sensitivity labels.
dead zone
A network segment using an alternative Network layer protocol instead of IP, such as IPX or AppleTalk.
decentralized access control
System of access control in which authorization verification is performed by various entities located throughout a system.
decision support system (DSS)
An application that analyzes business data and presents it so as to make business decisions easier for users. DSS is considered an informational application more so than an operational application. Often a DSS is employed by knowledge workers (such as help desk or customer support) and by sales services (such as phone operators).
declassification
The process of moving a resource into a lower classification level once its value no longer justifies the security protections provided by a higher level of classification.
decrypting
The process of reversing a cryptographic algorithm that was used to encrypt a message.
dedicated mode
See dedicated security mode.
dedicated security mode
Mode in which the system is authorized to process only a specific classification level at a time. All system users must have clearance and a need to know that information.
deencapsulation
The process of stripping a layer's header and footer from a PDU as it travels up the OSI model layers.
defense-in-depth
A layered approach to security. Multiple layers of security are implemented, requiring attackers to circumvent several security controls to be successful.
degaussing
The act of using a magnet to return media to its original pristine unused state.
degree
The number of columns in a relational database.
delegation
In the context of object-oriented programming, the forwarding of a request by an object to another object or delegate. An object delegates if it does not have a method to handle the message.
Delphi technique
An anonymous feedback and response process used to arrive at a group consensus.
delta rule
Also known as the learning rule. It is the feature of expert systems that allows them to learn from experience.
deluge system
Another form of dry pipe (fire suppression) system that uses larger pipes and therefore a significantly larger volume of water. Deluge systems are inappropriate for environments that contain electronics and computers.
denial of service (DoS)
A type of attack that prevents a system from processing or responding to legitimate traffic or requests for resources and objects.
deny risk
See reject risk.
detective access control
An access control deployed to discover unwanted or unauthorized activity. Examples of detective access controls include security guards, supervision of users, incident investigations, and intrusion detection systems (IDSs).
detective control
See detective access control.
deterrent access control
An access control that discourages violations of a security policy.
DevOps
The DevOps approach seeks to resolve issues of software development, quality assurance, and technology operations by bringing the three functions together in a single operational model. The word DevOps is a combination of Development andThe DevOps approach seeks to resolve issues of software development, quality assurance, and technology operations by bringing the three functions together in a single operational model. The word DevOps is a combination of Development and Operations, symbolizing that these functions must merge and cooperate to meet businessThe DevOps approach seeks to resolve issues of software development, quality assurance, and technology operations by bringing the three functions together in a single operational model. The word DevOps is a combination of Development and Operations, symbolizing that these functions must merge and cooperate to meet business requirements.
dictionary attack
An attack against a system designed to discover the password to a known identity (in other words, a username). In a dictionary attack, a script of common passwords and dictionary words is used to attempt to discover an account's password.
differential backup
A type of backup that stores all files that have been modified since the time of the most recent full backup.
Diffie-Hellman algorithm
A key exchange algorithm useful in situations in which two parties might need to communicate with each other but they have no physical means to exchange key material and there is no public key infrastructure in place to facilitate the exchange of secret keys.
diffusion
Occurs when a change in the plain text results in multiple changes spread throughout the cipher text.
Digital Millennium Copyright Act
A law that establishes the prohibition of attempts to circumvent copyright protection mechanisms placed on a protected work by the copyright holder and limits the liability of Internet service providers when their circuits are used by criminals violating the copyright law.
digital rights management
A type of protection software that uses encryption to enforce copyright restrictions on digital media. Over the past decade, publishers attempted to deploy DRM schemes across a variety of media types including music, movies, and books.
digital signature
A method for ensuring a recipient that a message truly came from the claimed sender and that the message was not altered while in transit between the sender and recipient.
Digital Signature Standard (DSS)
A standard that specifies that all federally approved digital signature algorithms must use a secure hashing function.
direct addressing
A process by which the CPU is provided with the actual address of the memory location to be accessed.
direct evidence
Evidence that proves or disproves a specific act through oral testimony based on information gathered through the witness's five senses.
direct memory access (DMA)
A mechanism that allows devices to exchange data directly with real memory (RAM) without requiring assistance from the CPU.
Direct Sequence Spread Spectrum (DSSS)
A wireless technology that employs all of the available frequencies simultaneously in parallel.
directive access control
An access control that directs, confines, or controls the actions of subjects to force or encourage compliance with security policy.
directory service
A centralized database of resources available to the network, much like a telephone directory for network services and assets. Users, clients, and processes consult the directory service to learn where a desired system or resource resides.
disaster
An event that brings great damage, loss, or destruction to a system or environment.
disaster recovery plan
A document that guides the recovery efforts necessary to restore your business to normal operations as quickly as possible.
disaster recovery planning (DRP)
Term that describes the actions an organization takes to resume normal operations after a disaster interrupts normal activity.
discretionary access control
A mechanism used to control access to objects. The owner or creator of an object controls and defines the access other subjects have to it.
discretionary security property
Property that states that the system uses an access control matrix to enforce discretionary access control.
distance vector routing protocol
A routing protocol that maintains a list of destination networks along with metrics of direction and distance as measured in hops (in other words, the number of routers to cross to reach the destination).
distributed access control
A form of access control in which authorization verification is performed by various entities located throughout a system.
distributed architecture
A client/server model of networking where clients may be local or connected over WAN links, including VPNs and the Internet.
Distributed Component Object Model (DCOM)
An extension of COM to support distributed computing. This is Microsoft's answer to CORBA.
distributed control systems (DCS)
Industrial control system (ICS) units that are typically found in industrial process plans where the need to gather data and implement control over a large-scale environment from a single location is essential. An important aspect of DCSIndustrial control system (ICS) units that are typically found in industrial process plans where the need to gather data and implement control over a large-scale environment from a single location is essential. An important aspect of DCS is the controlling elements are distributed across the monitored environment, such as a manufacturing floor or a production line, while the centralized monitoring location sends commands out of those localized controllers while gathering status and performance data.
distributed data model
In a distributed data model, data is stored in more than one database but remains logically connected. The user perceives the database as a single entity, even though it consists of numerous parts interconnected over a network. Each field may have numerous children as well as numerous parents. Thus, the data mapping relationship is many-to-many.
distributed denial of service (DDoS)
A distributed denial of service occurs when the attacker compromises several systems to be used as launching platforms against one or more victims. The compromised systems used in the attack are often called slaves or zombies. A DDoS attack results in the victims being flooded with data from numerous sources.
distributed reflective denial of service (DRDoS)
DRDoS attacks take advantage of the normal operation mechanisms of key Internet services, such as DNS and router update protocols. DRDoS attacks function by sending numerous update, session, or control packets to various Internet service servers or routers with a spoofed source address of the intended victim. A DRDoS attack can result in so much traffic that upstream systems are adversely affected by the sheer volume of data focused on the victim.
DNS poisoning
The act of altering or falsifying DNS information at a source location (i.e., HOSTS file, caching DNS server, or authoritative DNS server) in order to route or misdirect legitimate traffic.
DNS spoofing
The act of altering or falsifying DNS information using a rogue DNS server to send false DNS replies in order to route or misdirect legitimate traffic.
documentary evidence
Any written items brought into court to prove a fact at hand. This type of evidence must also be authenticated.
documentation review
The process of reading the exchange materials and verifying them against standards and expectations.
domain
1) A realm of trust or a collection of subjects and objects that share a common security policy. Each domain's access control is maintained independently of other domains' access control. This results in decentralized access control when multiple domains are involved. 2) An area of study for the CISSP exam.
DREAD
A risk rating system designed to provide a flexible rating solution based on asking five main questions of each threat: damage potential, reproducibility, exploitability, affected users, and discoverability.
drive-by download
Code downloaded and installed on a user's system without the user's knowledge. Attackers sometimes modify code on legitimate websites to include drive-by downloads. They also host their own malicious websites and use phishing or redirection methods to get users to the malicious website.
dry pipe system
A fire suppression system that contains compressed air. Once suppression is triggered, the air escapes, which opens a water valve that in turn causes the pipes to fill and discharge water into the environment.
due care
The steps taken to ensure that assets and employees of an organization have been secured and protected and that upper management has properly evaluated and assumed all unmitigated or transferred risks.
due diligence
The extent to which a reasonable person will endeavor under specific circumstances to avoid harming other people or property.
dumb cards
Human-readable-only card IDs that usually have a photo and written information about the authorized bearer. Dumb cards are for use in environments where automated controls are infeasible or unavailable but security guards are practical.
dumpster diving
The act of digging through the refuse, remains, or leftovers from an organization or operation in order to discover or infer information about the organization.
durability
One of the four required characteristics of all database transactions (the other three are atomicity, consistency, and isolation). The concept that database transactions must be resilient. Once a transaction is committed to the database, it must be preserved. Databases ensure durability through the use of backup mechanisms, such as transaction logs.
dwell time
The length of time a key on the keyboard is pressed. This is an element of the keystroke dynamics biometric factor.
Dynamic Host Configuration Protocol (DHCP)
A protocol used to assign TCP/IP configuration settings to systems upon bootup. DHCP uses UDP port 67 for server point- to-point response and port 68 for client request broadcast. DHCP supports centralized control and management of network addressing.
dynamic packet-filtering firewalls
A firewall that enables real-time modification of the filtering rules based on traffic content. Dynamic packet-filtering firewalls are known as fourth-generation firewalls.
dynamic passwords
Passwords that do not remain static for an extended period of time. Dynamic passwords can change on each use or at a regular interval, such as every 30 days.
dynamic testing
Evaluates the security of software in a runtime environment and is often the only option for organizations deploying applications written by someone else.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics