face scan
An example of a biometric factor, which is a behavioral or physiological characteristic unique to a subject. A face scan is a process by which the shape and feature layout of a person's face is used to establish identity or provide authentication.
fail-open
The response of a system to a failure so that it defaults to an "allow" posture.
fail-safe
The response of a system to a failure so that it defaults to a "deny" posture.
fail-secure
See fail-safe.
failover
Redirecting workload or traffic to a backup system when the primary system fails.
Fair Cryptosystems
A failed government attempt to create a back door to all encryption solutions. This technology used a segmented key that was divided among several trustees.
false acceptance rate (FAR)
Error that occurs when a biometric device is not sensitive enough and an invalid subject is authenticated. Also, referred to as a Type 2 error.
false negative
Error that occurs when a vulnerability scanner misses a vulnerability and fails to alert the administrator to the presence of a dangerous situation.
false positive
The event that might trigger an alarm when a security scanner may not have enough information to conclusively determine that a vulnerability exists but still reports a vulnerability when there really is no problem. Also known as mistaking a benign issue for a malicious event.
false rejection rate (FRR)
Error that occurs when a biometric device is too sensitive and a valid subject is not authenticated. Also, referred to as a Type 1 error.
Family Educational Rights and Privacy Act (FERPA)
A specialized privacy bill that affects any educational institution that accepts any form of funding from the federal government (the vast majority of schools). It grants certain privacy rights to students older than the age of 18 and the parents of minor students.
fault
1) A momentary loss of power. 2) A failure or problem within a system, device, or process.
fault tolerance
The ability of a system to suffer a fault but continue to operate. Fault tolerance is achieved by adding redundant components such as additional disks within a redundant array of independent disks (RAID) or additional servers within a failover clustered configuration.
Federal Information Processing Standard 140 (FIPS-140)
FIPS-140 defines the hardware and software requirements for cryptographic modules that the US federal government uses.
Federal Information Security Management Act (FISMA)
A US law passed in 2002 that requires that federal agencies implement an information security program that covers the agency's operations. FISMA also requires that government agencies include the activities of contractors in their security management programs.
Federal Sentencing Guidelines
A 1991 law that provides punishment guidelines for breaking federal laws.
feedback loop characteristic
The ability in the modern waterfall model that allows development to return to the previous phase to correct defects discovered during the subsequent phase.
fence
A perimeter-defining device. Fences are used to clearly differentiate between areas that are under a specific level of security protection and those that are not. Fencing can include a wide range of components, materials, and construction methods.
Fibre Channel over Ethernet (FCoE)
A converged protocol used to encapsulate Fibre Channel communications over Ethernet networks. It typically requires 10 Gbps Ethernet in order to support the Fibre Channel protocol.
Fiber Distributed Data Interface (FDDI)
A high-speed token-passing technology that employs two rings with traffic flowing in opposite directions. FDDI offers transmission rates of 100 Mbps and is often used as a backbone to large enterprise networks.
fiber-optic
A cabling form that transmits light instead of electrical signals. Fiber-optic cable supports throughputs up to 2 Gbps and lengths of up to 2 kilometers.
field
In a database, a field is a column or attribute of a table.
file infector virus
Virus that infects different types of executable files and triggers when the operating system attempts to execute them. For Windows-based systems, these filenames end with .exe and .com.
filter(s)
A set of rules or restrictions commonly found on security devices, such as firewalls and proxies. Also known as rules and ACLs.
financial attack
A crime that is carried out to unlawfully obtain money or services.
fingerprints
The patterns of ridges on the fingers of humans. Often used as a biometric authentication factor.
firewall
A network device used to filter traffic. A firewall is typically deployed between a private network and a link to the Internet, but it can be deployed between departments within an organization. Firewalls filter traffic based on a defined set of rules.
firmware
Software that is stored in a ROM chip.
flash memory
A derivative concept from EEPROM. It is a nonvolatile form of storage media that can be electronically erased and rewritten. The primary difference between EEPROM and flash memory is that EEPROM must be fully erased to be rewritten whereas flash memory can be erased and written in blocks or pages. The most common type of flash memory is NAND flash. It is widely used in memory cards, thumb drives, mobile devices, and SSD (solid state drives).
flight time
The length of time between key presses. This is an element of the keystroke dynamics form of biometrics.
flooding
An attack that involves sending enough traffic to a victim to cause a DoS. Also referred to as a stream attack.
footer
Information added by a protocol to the end of a payload received from a higher- layer protocol.
foreign key
A primary key from another table used to cross-link or express relationships between the contents of two tables.
Fourth Amendment
An amendment to the US Constitution that prohibits government agents from searching private property without a warrant and probable cause. The courts have expanded their interpretation of the Fourth Amendment to include protections against wiretapping and other invasions of privacy.
fraggle
A form of denial-of-service attack similar to smurf, but it uses UDP packets instead of ICMP.
fragment
When a network receives a packet larger than its maximum allowable packet size, it breaks it up into two or more fragments. These fragments are each assigned a size (corresponding to the length of the fragment) and an offset (corresponding to the starting location of the fragment).
fragmentation attack
An attack that exploits vulnerabilities in the fragment reassembly functionality of the TCP/IP protocol stack.
frame
The combination of Data Link layer header, payload, and footer.
Frame Relay
A shared connection medium that uses packet-switching technology to establish virtual circuits for customers.
frequency
A measurement of the number of wave oscillations within a specific time identified using the unit Hertz (Hz), or oscillations per second. Radio waves have a frequency between 3 Hz and 300 GHz.
frequency analysis
A cryptographic analysis or attack that looks for repetition of letters in an encrypted message and compares that with the statistics of letter usage for a specific language, such as the frequency of the letters E, T, A, O, N, R, I, S, and H in the English language.
Frequency Hopping Spread Spectrum (FHSS)
An early implementation of the spread spectrum concept. This wireless access technology transmits data in a series while constantly changing the frequency in use.
full backup
A complete copy of data contained on the protected device on the backup media. This also refers to the process of making a complete copy of data, as in "performing a full backup."
full-interruption tests
A disaster recovery test that involves shutting down operations at the primary site and shifting them to the recovery site.
full-knowledge teams
These possess a full body of knowledge of the operation, configuration, and utilization of hardware and software inventory prior to a security assessment or penetration test.
fuzz testing
A specialized dynamic testing technique that provides many different types of input to software to stress its limits and find previously undetected flaws. Fuzz testing software supplies invalid input to the software, either randomly generated or specially crafted to trigger known software vulnerabilities. The fuzz tester then monitors the performance of the application, watching for software crashes, buffer overflows, or other undesirable and/or unpredictable outcomes.
fuzzy logic
A computational technique designed to more closely approximate human thought patterns than the rigid mathematics of set theory or algebraic approaches that utilize "black-and-white" categorizations of data.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics