Glossary of Privileged Access and Compliance Terms

These are the terms used on this site, in plain words.

A refined technical reference volume with colored indexed tabs and three translucent information tiles
Glossary of Privileged Access and Compliance Terms
Term Meaning Read more
Affirming official The senior person who signs the annual CMMC affirmation that the organization is meeting the required level. DFARS 252.204-7021
Air-gapped A system isolated from general network reach. Air-gapped systems
Assessment Binder The AIC living evidence package shared by the assessor, the Managed Service Provider, and the Customer. Continuous compliance
Blast radius How many hosts and services a single shared credential reaches. What is password management
C3PAO CMMC Third-Party Assessment Organization. The assessor for CMMC Level 2 certification. C3PAO
CIEM Cloud infrastructure entitlement management. Analysis of cloud account permissions. Capabilities
Class deviation An instruction that changes how a contracting activity applies an acquisition regulation, without amending the regulation itself. CMMC Phase 2
CMMC Cybersecurity Maturity Model Certification. The U.S. Department of War program for protecting Federal Contract Information and Controlled Unclassified Information. CMMC for defense contractors
CMMC Status The outcome of a CMMC assessment, such as Final Level 2 (Self) or Conditional Level 2 (C3PAO). DFARS 252.204-7021
CMMC UID The unique identifier issued for an assessed system, reported alongside the CMMC Status. DFARS 252.204-7021
Conditional status A CMMC status granted with eligible items on a POA&M, which must be closed and verified within 180 days. What is a POA&M
Continuous compliance Keeping the compliance record current with ongoing feeds, alerts, and monitoring instead of a point-in-time check. Continuous compliance
CUI Controlled Unclassified Information. Unclassified information a law, regulation, or government-wide policy requires to be safeguarded. What is CUI
CUI Basic CUI whose authority requires safeguarding but does not specify how. CUI marking
CUI Specified CUI whose authority names specific handling, marking, dissemination, or destruction requirements. CUI marking
Current State Compliance The AIC ledger of control findings with rescan. Continuous compliance
Decontrolling Ending the CUI control on information. It does not by itself authorize public release. CUI marking
Designation indicator The block on a CUI document naming who designated it and under what authority. CUI marking
DFARS Defense Federal Acquisition Regulation Supplement. Clause 252.204-7012 is the one that requires NIST SP 800-171 safeguarding and cyber incident reporting. DFARS 252.204-7012
DIBCAC Defense Industrial Base Cybersecurity Assessment Center. Conducts High assessments and CMMC Level 3 assessments. NIST SP 800-171 self-assessment
DIBNet The portal where a defense contractor reports a cyber incident within 72 hours. DFARS 252.204-7012
FCI Federal Contract Information. Information provided by or generated for the government under a contract and not intended for public release. CMMC Level 1
FedRAMP Federal Risk and Authorization Management Program. The authorization program a cloud service must meet to process CUI. DFARS 252.204-7012
Flowdown Passing a contract clause to a subcontractor who will handle the same information. DFARS 252.204-7021
IGA Identity governance and administration. Account lifecycle and access review. What is IGA
ISPM Identity security posture management. Findings about identity and configuration exposure. Capabilities
ITDR Identity threat detection and response. Detect, respond, and remediate
JIT Just-in-time. Privilege granted only for a limited time. What is just-in-time access
Least privilege Holding only the authority the job requires, and nothing more. What is least privilege
MSP Managed Service Provider. Partners for MSPs
PAM Privileged Access Management. Brokered and recorded privileged sessions. What is PAM
PASM Privileged account and session management. Industry terms
Password management Creating, storing, rotating, and retiring the credentials people and systems authenticate with. What is password management
PEDM Privilege elevation and delegation management. Privileged user management
PIM Privileged Identity Management. Vaulting and rotation of privileged credentials. Privileged identity management
POA&M Plan of Action and Milestones. The tracked list of requirements not yet met, each with an owner and a closure date. What is a POA&M
Portion marking The short marking on an individual paragraph of a CUI document. CUI marking
PUM Privileged User Management. The AIC module for privilege elevation and delegation management. Privileged user management
RPAM Remote privileged access management. Industry terms
Secure enclave An isolated work boundary with AIC tools built in. Secure enclaves
Session recording Capturing a privileged session so it can be replayed afterward. What is session recording
SPRS Supplier Performance Risk System. The government database where a defense contractor posts its NIST SP 800-171 assessment score. Your SPRS score
SSP System security plan. The document describing the system being assessed, as it actually is. NIST SP 800-171 self-assessment
sudo A Unix and Linux program that runs a single command as another user, usually root. What is sudo
ZSP Zero standing privileges. No permanent administrator rights. What is ZSP

Terms explained at length

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.