The process of going through CMMC (the Cybersecurity Maturity Model Certification) compliance is difficult because you are dealing with digital information that needs to be protected in ways that most companies have never experienced. These terms are used often by the people responsible for ensuring compliance.
- Access Control: The process of granting or denying specific requests to obtain and use information and related information processing services.
- Authentication: The process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.
- Authorization: The process of granting or denying access to a network resource, based on the user’s identity.
- Controlled Unclassified Information (CUI): Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
- Federal Contract Information (FCI): Information that is created, collected, transmitted, or received as part of a contract with the Department of Defense.
- Encryption: The process of converting information or data into a code, especially to prevent unauthorized access.
- Information System: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
- Least Privilege: The principle that a user should be given no more privilege than necessary to perform a job.
- Multifactor Authentication (MFA): A security system that requires more than one method of authentication from independent categories of credentials to verify the user’s identity for a login or other transaction.
- Password Policy: A set of rules designed to enhance security by encouraging users to employ strong passwords and use them properly.
- Privileged Account: A user account that has more privileges than ordinary user accounts. Examples include administrator accounts and root accounts.
- Remote Access: The ability to get access to a computer or a network from over the internet instead of locally.
- Risk Assessment: The process of identifying risks to system security and determining the likelihood of occurrence, the resulting impact, and additional safeguards that mitigate this impact.
- Role-Based Access Control (RBAC): A method of regulating access to computer or network resources based on the roles of individual users within an organization.
- Security Controls: Safeguards or countermeasures to avoid, counteract, or minimize security risks.
- System Owner: The official responsible for the overall procurement, development, integration, modification, or operation and maintenance of an information system.
- User ID: A unique identifier assigned to each individual user for accessing an information system.
- Two-Factor Authentication (2FA): A method of confirming a user’s claimed identity by utilizing a combination of two different components, typically something they know (password) and something they have (security token).
- Unauthorized Access: Any access to information systems or data that is not authorized by the system owner or administrator.
- User Account: A unique identifier for each person who has access to the information system, including a username and password.
- Threat: Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
- Incident Response: The approach taken by an organization to prepare for, detect, contain, and recover from a data breach.
- Sensitive Information: Data that must be protected from unauthorized access to safeguard the privacy or security of an individual or organization.
- Vulnerability: A flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised and result in a security breach or a violation of the system’s security policy.
- System Use Notification: A warning banner displayed to users before logging into an information system, indicating the system’s legal and authorized use conditions.
- Separation of Duties: Dividing tasks and privileges among multiple users to prevent conflict of interest and fraud.
- Access Provisioning: The process of creating, managing, and deactivating user accounts and permissions for access to systems and applications.
- De-provisioning: The process of removing access rights and privileges when they are no longer required, such as when an employee leaves the company or changes roles.
- Security-relevant change – Any change to a system’s configuration, environment, information content, functionality, or users which has the potential to change the risk imposed upon its continued operations.
- Security-relevant information – Information within the system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data.
- Security functions – The hardware, software, or firmware of the systems responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.
- Information security – The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.





