Key Terms and Concepts Glossary
General Terms:
Access Control List (ACL): Security feature used to permit or restrict access.
Access Point: A device that allows wireless devices to connect to a wired network, enabling internet or local network access.
AO (Authorizing Official): The senior official with the authority to assume responsibility for operating an information system at an acceptable level of risk.
Artificial Intelligence (AI): Simulates human intelligence processes by machine, such as problem-solving or learning.
Bandwidth: The maximum rate of data transfer across a given path
CAA (Controlled Access Area): A space under direct physical control where unauthorized persons are denied access and are either escorted or under continuous surveillance.
Domain Name System (DNS): Resolves human-readable domain names to IP addresses, critical for network navigation.
Dynamic Host Configuration Protocol: Automatically assigns IP addresses to devices on a network.
Electromagnetic Interference (EMI): unwanted electromagnetic energy that disrupts the normal operation of electronic devices, originating from both natural and human-made sources.
Encryption: The process of encoding digital information so that only authorized parties can read it. While essential for network security, it is not a “cure-all” for physical layer. vulnerabilities, as it does not hide metadata or traffic patterns from sophisticated observers.
Hyper Text Transfer Protocol/Secure (HTTPS): Protocols for web traffic, with HTTPS using encryption.
Internet Protocol (IP): Provides logical addressing and packet routing across networks.
LAA (Limited Access Area): An area surrounding a PDS where unauthorized access is unlikely, or where there is legal authority to identify and remove a potential threat.
Local Area Network (LAN): Connects devices within a limited area, such as an office or building.
Meida Access Control Address (MAC): Unique identifier for network interfaces at the data link layer.
NSI (National Security Information): Sensitive information (e.g., Top Secret or Highly Classified) that must be protected from unauthorized disclosure in the interest of national security.
PDS (Protected Distribution System): A physical infrastructure system (conduits, enclosures, and monitoring tools) designed to protect unencrypted data in transit from physical tapping or tampering.
Telecommunication Room (TR): a dedicated, secure, and climate-controlled space within a building that serves as the central hub for networking infrastructure.
Transmission Control Protocol (TCP): Core protocol suite for reliable end-to-end communication.
UAA (Uncontrolled Access Area): An area where no personnel access controls can be exercised (e.g., a public parking lot or open lobby). A standard PDS is strictly prohibited in these areas; encryption is mandatory.
Wide Area Network (WAN): Network spanning broader geographic areas, often connecting multiple LANs.
PDS Alarmed Carrier Type Terms
Access: Ability and means to communicate with or otherwise interact with a system, to use system resources to handle information, to gain knowledge of the information the system contains, or to control system components and functions.
Access Control: The process of granting or denying specific requests: 1) For obtaining and using information and related information processing services.
2) to enter specific physical facilities (i.e.) Federal Buildings, military establishments, and border crossing entrances).
Access Control List (ACL): 1) A list of permissions associated with an object. The list specifies who or what is allowed to access the object and what operations are allowed to be performed on the object.
2) A mechanism that implements access control for a system resource by enumerating the system entities that are permitted to access the resource and stating, either implicitly or explicitly, the access modes granted to each entity.
Access Control Mechanism: Security safeguards (i.e., hardware and software features, physical controls, operating procedures, management procedures, and various combinations of these) designed to detect and deny unauthorized access and permit authorized access to an information system.
Access Level: A category within a given security classification limiting entry or system connectivity to only authorized persons.
Access List: Roster of individuals authorized admittance to a controlled area.
Accreditation: Formal declaration by a Designated Accrediting Authority (DAA) or Principal Accrediting Authority (PAA) that an information system is approved to operate at an acceptable level of risk, based on the implementation of an approved set of technical, managerial, and procedural safeguards.
Accreditation Boundary: 1) Identifies the information resources covered by an accreditation decision, as distinguished from separately accredited information resources that are interconnected or with which information is exchanged via messaging.
2) For the purposes of identifying the Protection Level for confidentiality of a system to be accredited, the system has a conceptual boundary that extends to all intended users of the system, both directly and indirectly connected, who receive output from the system
Accreditation Package: Product comprised of a System Security Plan (SSP) and a report documenting the basis for the accreditation decision.
Advanced Encryption Standard (AES): A U.S. Government-approved cryptographic algorithm that can be used to protect electronic data. The AES algorithm is a symmetric block cipher that can encrypt (encipher) and decrypt (decipher) information.
Alarmed Carrier: A PDS that uses electronic sensors (acoustic, vibration, or optical) to provide 24/7 monitoring of the conduit’s physical integrity. It is designed to detect tampering the moment it occurs.
Approval to Operate (ATO): The official management decision issued by a DAA or PAA to authorize operation of an information system and to explicitly accept the residual risk to agency operations (including mission, functions, or reputation), agency assets, or individuals.
Audit Log: A chronological record of system activities. Includes records of system accesses and operations performed in a given period.
Authentication: The process of verifying the identity or other attributes claimed by or assumed of an entity (user, process, or device), or to verify the source and integrity of data. See (NIST SP 800-53).
Authorized Vendor: Manufacturer of information assurance equipment authorized to produce quantities in excess of contractual requirements for direct sale to eligible buyers. Eligible buyers are typically U.S. Government organizations or U.S. Government contractors.
Buried Carrier: Conduit or pathway systems installed underground, typically used to route data securely between separate buildings.
Category 1 PDS: A simpler, lower-cost protection level authorized exclusively for use within Controlled Access Areas (CAAs).
Category 2 PDS: A fortified protection level required when routing unencrypted data through Limited Access Areas (LAAs). It includes robust options like Hardened, Buried, or Alarmed carriers.
Classified National Security Information: Information that has been determined pursuant to Executive Order 13526 or any predecessor order to require protection against unauthorized disclosure and is marked to indicate its classified status when in documentary form.
Classification: A designation (e.g., Confidential, Secret, Top Secret, SCI) assigned to National Security Information (NSI). The classification level dictates the required protection level for the PDS and the frequency of required inspections.
Clearance: Formal certification of authorization to have access to classified information other than that protected in a special access program (including SCI). Clearances are of three types: confidential, secret, and top secret. A top secret clearance permits access to top secret, secret, and confidential material; a secret clearance, to secret and confidential material; and a confidential clearance, to confidential material.
CNSSI 7003: The Committee on National Security Systems Instruction 7003, the authoritative policy document governing the design, installation, and inspection of Protected Distribution Systems for National Security Information.
Common Access Card (CAC): Standard identification/smart card issued by the Department of Defense that has an embedded integrated chip storing public key infrastructure (PKI) certificates.
Communications Security (COMSEC): A component of Information Assurance that deals with measures and controls taken to deny unauthorized persons information derived from telecommunications and to ensure the authenticity of such telecommunications. COMSEC includes crypto security, transmission security, emissions security, and physical security of COMSEC material.
Compensating Security Control: A management, operational, and/or technical control (i.e., safeguard or countermeasure) employed by an organization in lieu of a recommended security control in the low, moderate, or high baselines that provides equivalent or comparable protection for an information system. (See NIST SP 800.53)
Continuous Monitoring: The process is implemented to maintain current security status for one or more information systems or for the entire suite of information systems on which the operational mission of the enterprise depends. The process includes: 1) The development of a strategy to regularly evaluate selected IA controls/metrics, 2) Recording and evaluating IA relevant events and the effectiveness of the enterprise in dealing with those events, 3) Recording changes to IA controls, or changes that affect IA risks, and 4) Publishing the current security status to enable information sharing decisions involving the enterprise.
Continuously Viewed Carrier: A physical pathway that is monitored 24/7 by human security personnel or dedicated CCTV cameras to provide absolute visual oversight.
Controlled Access Area: Physical area (e.g., building, room, etc.) to which only authorized personnel are granted unrestricted access. All other personnel are either escorted by authorized personnel or are under continuous surveillance.
Critical Infrastructure: System and assets, whether physical or virtual, so vital to the U.S. that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.
Cyber Attack: An attack, via cyberspace, targeting an enterprise’s use of cyberspace for the purpose of disrupting, disabling, destroying, or maliciously controlling a computing environment/infrastructure; or destroying the integrity of the data or stealing controlled information.
Cybersecurity: The ability to protect or defend the use of cyberspace from cyber-attacks.
Defense-in-Breadth: A planned, systematic set of multi-disciplinary activities that seek to identify, manage, and reduce risk of exploitable vulnerabilities at every stage of the system, network, or sub-component lifecycle (system, network, or product design and development; manufacturing; packaging; assembly; system integration; distribution; operations; maintenance; and retirement).
Defense-in-Depth: Information Security strategy integrating people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.
EMI/RFI Shielding: The ability of a conduit to block Electromagnetic Interference and Radio Frequency Interference. Ferrous metal PDS components provide this secondary benefit, protecting data from signal leakage and eavesdropping.
Fiber Tap: An unauthorized device or technique used to intercept light signals from a fiber optic cable. This is the primary “threat” that Alarmed Carrier systems are designed to detect.
Ferrous Metal: Metals containing iron (like steel). CNSSI 7003 requires these for Hardened Carriers because they provide both physical durability and the specific magnetic properties required for baseline electrical profiling during inspections.
Hardened Carrier: A pathway constructed of heavy-duty, ferrous metal tubing. It is designed to be physically resistant to drilling, cutting, or tampering, and is a staple of Category 2 PDS.
Information Assurance (IA): Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. These measures include providing for restoration of information systems by incorporating protection, detection, and reaction capabilities.
Information Security: The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.
Information Technology (IT): Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. For purposes of the preceding sentence, equipment is used by an executive agency if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency which 1) requires the use of such equipment or 2) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term information technology includes computers, ancillary equipment, software, firmware and similar procedures, services (including support services), and related resources.
Insider Threat: An entity with authorized access (i.e., within the security domain) that has the potential to harm an information system or enterprise through destruction, disclosure, modification of data, and/or denial of service.
Intrusion: Unauthorized act of bypassing the security mechanisms of a system.
Intrusion Detection System (IDS): Hardware or software products that gather and analyze information from various areas within a computer or a network to identify possible security breaches, which include both intrusions (attacks from outside the organizations) and misuse (attacks from with the organizations).
Intrusion Detection Systems (IDS/Host Based): computer system. This vantage point allows host-based IDSs to determine exactly which processes and user accounts are involved in a particular attack on the Operating System. Furthermore, unlike network-based IDSs, host based IDSs can more readily “see” the intended outcome of an attempted attack, because they can directly access and monitor the data files and system processes usually targeted by attacks.
Intrusion Detection Systems (IDS/Network Based): IDSs which detect attacks by capturing and analyzing network packets. Listening on a network segment or switch, one network-based IDS can monitor the network traffic affecting multiple hosts that are connected to the network segment.
Open Storage: Any storage of classified national security information outside of approved containers. This includes classified information that is resident on information systems media and outside of an approved storage container, regardless of whether or not that media is in use (i.e., unattended operations).
Operations Security (OPSEC): Systematic and proven process by which potential adversaries can be denied information about capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence of the planning and execution of sensitive activities. The process involves five steps: identification of critical information, analysis of threats, analysis of vulnerabilities, assessment of risks, and application of appropriate countermeasures.
Outsider Threat: An unauthorized entity outside the security domain that has the potential to harm an information system through destruction, disclosure, modification of data, and/or denial of service.
Protective Distribution System (PDS): Wire line or fiber optic system that includes adequate safeguards and/or countermeasures (e.g., acoustic, electric, electromagnetic, and physical) to permit its use for the transmission of unencrypted information through an area of lesser classification or control.
Protective Technologies: Special tamper-evident features and materials employed for the purpose of detecting tampering and deterring attempts to compromise, modify, penetrate, extract, or substitute information processing equipment and keying material.
Secure Communications: Telecommunications deriving security through use of NSA-approved products and/or protected distribution systems (PDSs).
Sensitive Compartmented Information (SCI): Classified information concerning or derived from intelligence sources, methods, or analytical processes, which is required to be handled within formal access control systems established by the Director of National Intelligence.
Social Engineering: An attempt to trick someone into revealing information (e.g., a password) that can be used to attack an enterprise.
Suspended Carrier: A physical conduit pathway that is elevated (usually in an open plenum or ceiling space) and used for short, direct runs between points.

