Terms starting with “C”
848 election security terms starting with C, with direct links to full definitions and source-backed context.
Commodity Service
VerifiedAn information system service (e.g., telecommunications service) provided by a commercial service provider typically to a large and diverse set of consumers. The organization acqui...
Common Access Card (cac)
Standard identification/smart card issued by the Department of Defense (DoD) that has an embedded integrated chip storing public key infrastructure (PKI) certificates. Note: As per...
Common Carrier
VerifiedIn a telecommunications context, a telecommunications company that holds itself out to the public for hire to provide communications transmission services. Note: In the United Stat...
Common Configuration
VerifiedA nomenclature and dictionary of software security configurations.
Common Configuration Enumeration (cce)
VerifiedA SCAP specification that provides unique, common identifiers for configuration settings found in a wide variety of hardware and software products. (SP 800-128) (NISTIR)
Common Configuration Scoring System (ccss)
VerifiedA set of measures of the severity of software security configuration issues. (NISTIR 7502) (NISTIR)
Common Control
VerifiedA security control that is inherited by one or more organizational information systems. See security control inheritance. Source: NIST SP 800-37 Rev 1
Common Control Provider
VerifiedAn organizational official responsible for the development, implementation, assessment, and monitoring of common controls (i.e., security controls inherited by information systems)...
Common Criteria
VerifiedGoverning document that provides a comprehensive, rigorous method for specifying security function and assurance requirements for products and systems.
Common Data Format
VerifiedStandard and practice of storing and creating data in a common, described format that can be read by other systems.
Common Fill Device
VerifiedOne of a family of devices developed to read-in, transfer, or store key. (CNSSI-4009) (NISTIR)
Common Fill Device (cfd)
VerifiedAny one of a family of devices developed to read-in, transfer, or store key. Source: NSA/CSS Manual Number 3-16 (adapted) (COMSEC)
Common Industry Format
VerifiedA "format described in ISO/IEC 25062:2006, 'Common Industry Format (CIF) for Usability Test Reports'." VVSG. Abbreviated CIF.
Common Industry Format (cif)
VerifiedRefers to the format described in ANSI/INCITS 354-2001 "Common Industry Format (CIF) for Usability Test Reports."
Common Misuse Scoring System
Verified(CMSS) A set of measures of the severity of software feature misuse vulnerabilities. A software feature is a functional capability provided by software. A software feature misuse v...
Common Platform Enumeration
Verified(CPE) A SCAP specification that provides a standard naming convention for operating systems, hardware, and applications for the purpose of providing consistent, easily parsed names...
Common Platform Enumeration (cpe)
VerifiedA nomenclature and dictionary of hardware, operating systems, and applications. Source: NIST SP 800-126 Rev 2
Common Services Provider (csp)
VerifiedA federal organization that provides National Security System-Public Key Infrastructure (NSS-PKI) support to other federal organizations, academia and industrial partners requiring...
Common User Application Software (cuas)
VerifiedUser application software developed to run on top of the local COMSEC management software (LCMS) on the local management device/key processor (LMD/KP). Source: CNSSI No. 4005 (COMS...
Common Vulnerabilities And
VerifiedA nomenclature and dictionary of security-related software flaws.
Common Vulnerabilities And Exploits
VerifiedThe generic name for known cybersecurity vulnerabilities that have been catalogued by the CVE program. There is one CVE Record for each vulnerability in the catalog.
Common Vulnerabilities And Exposures (cve)
VerifiedA dictionary of common names for publicly known information system vulnerabilities. (SP 800-51; CNSSI-4009) (NISTIR)
Common Vulnerability Scoring
VerifiedA system for measuring the relative severity of software flaw vulnerabilities.
Common Vulnerability Scoring System (cvss)
VerifiedAn SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity. (SP 800-128) (NISTIR)