Cybersecurity and Compliance Glossary: 23 Terms Defined
Posted: September 20, 2026 to Compliance.
This glossary defines 23 cybersecurity, compliance, and AI terms that defense contractors, healthcare practices, payment merchants, and IT leaders ask about most often. Each entry opens with a one-sentence definition you can quote, then explains where the term comes from, what it requires, and where it shows up in a contract, an assessment, or a security program. Every definition is tied to a primary source such as the Code of Federal Regulations, the Federal Acquisition Regulation, a NIST publication, or the standards body that owns the term. The sources are listed at the end of the page so you can read the original language yourself.
Petronella Technology Group, Inc. is a CMMC Registered Provider Organization based in Raleigh, North Carolina. The company has served regulated businesses since 2002. If a term on this page applies to a contract or an audit you are facing, call Penny at 919-348-4912 or use the contact form.
How to Use This Glossary
The entries are grouped by the setting where you will meet them: federal and defense contracting, security operations, commercial and healthcare compliance, and artificial intelligence. Terms inside a group are ordered so that each one builds on the entry before it. Controlled Unclassified Information comes before CMMC, for example, because CMMC exists to protect that information. If you arrived here looking for a single term, use the list below to jump to it.
- Federal and defense contracting: CUI, FCI, CMMC, NIST SP 800-171, SSP, POA&M, SPRS score, DFARS 252.204-7012, ITAR, FedRAMP, FIPS 140-2 and FIPS 140-3
- Security operations: SOC, SIEM, SOAR, EDR, MFA, zero trust architecture, encryption at rest, social engineering
- Commercial and healthcare compliance: PCI DSS, SOC 2, HIPAA Security Rule
- Artificial intelligence: retrieval-augmented generation (RAG)
Federal and Defense Contracting Terms
What Is CUI (Controlled Unclassified Information)?
Controlled Unclassified Information is unclassified information that a law, regulation, or government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls.
The federal definition sits in 32 CFR 2002.4(h): CUI is "information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls." The same paragraph states that CUI does not include classified information. Executive Order 13556 created the program, and the National Archives and Records Administration serves as its Executive Agent. The regulation separates CUI Basic, where the authorizing law sets no specific handling controls, from CUI Specified, where it does. For a defense contractor the practical question is whether CUI reaches your systems, because that is what triggers NIST SP 800-171 and CMMC Level 2. Read more in our CUI compliance guide and the CUI versus FCI comparison.
What Is FCI (Federal Contract Information)?
Federal Contract Information is non-public information that the government provides or a contractor generates under a contract to develop or deliver a product or service to the government.
FAR 52.204-21 defines it as "information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government." The definition excludes information the government publishes on public websites and simple transactional information such as the data needed to process payments. The same clause lists the basic safeguarding requirements that apply to any contractor system holding FCI. Under 32 CFR 170.14, those requirements, FAR 52.204-21 paragraphs (b)(1)(i) through (b)(1)(xv), are the CMMC Level 1 security requirements. FCI is a lower bar than CUI. A company that only handles FCI prepares for Level 1, while a company that handles CUI prepares for Level 2 or Level 3.
What Is CMMC (Cybersecurity Maturity Model Certification)?
CMMC is the Department of Defense program, codified at 32 CFR Part 170, that verifies a contractor has implemented the security requirements for the FCI and CUI it handles before and during a contract.
The rule defines three levels. Level 1 uses the 15 safeguarding requirements in FAR 52.204-21. The Level 2 security requirements "are identical to the requirements in NIST SP 800-171 R2," in the words of 32 CFR 170.14. Level 3 adds requirements selected from NIST SP 800-172. The contract clause at DFARS 252.204-7021 names four statuses a contracting officer can require: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC). The same clause requires an annual affirmation of continuous compliance, entered in SPRS by an affirming official. DoD is phasing the requirement into solicitations over four phases, each beginning one year after the start of the previous one. Our CMMC consulting page and CMMC overview explain how to prepare.
What Is NIST SP 800-171?
NIST Special Publication 800-171 is the catalog of security requirements for protecting the confidentiality of CUI when it resides in nonfederal systems and organizations.
NIST published Revision 2 in February 2020 and updated it on January 28, 2021. Revision 3 followed in May 2024 and supersedes Revision 2 as a NIST publication. CMMC has not moved with it: 32 CFR 170.14 incorporates Revision 2 by reference, so a Level 2 assessment today measures the 110 requirements of Revision 2. The DoD Assessment Methodology scores an organization against those same 110 requirements. The requirements apply to the components of a system that process, store, or transmit CUI, and to the components that protect them. That scoping language is why many contractors build a separate enclave for CUI instead of bringing the whole company network into scope. See our NIST SP 800-171 guide and the Revision 3 summary.
What Is an SSP (System Security Plan)?
A System Security Plan is the formal document that describes a system's security requirements and the controls in place, or planned, to meet them.
The NIST glossary, citing FIPS 200, defines it as a "formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements." The DoD Assessment Methodology states what the plan must cover for a contractor: system boundaries, environments of operation, how each security requirement is implemented, and the relationships with or connections to other systems. A Basic Assessment under DFARS 252.204-7020 is, by definition, based on the contractor's review of its System Security Plan, so a company without a plan has nothing to score. Assessors read the plan first, then test whether the environment matches it. Our page on requirement 3.12.4 covers what to include.
What Is a POA&M (Plan of Action and Milestones)?
A Plan of Action and Milestones is the document that lists the security tasks still to be completed, with the resources, milestones, and scheduled completion dates for each.
That wording follows the NIST glossary entry, which traces the term to OMB Memorandum 02-01. Under CMMC the document has hard limits. 32 CFR 170.21 allows a Conditional Level 2 status only when the assessment score divided by the total number of Level 2 requirements is at least 0.8. The regulation then requires a closeout assessment of the open items within 180 days of the Conditional CMMC Status Date. If the items are not closed in that window, the conditional status expires. A Plan of Action and Milestones is a short-term repair list with a deadline. It does not defer controls indefinitely. See requirement 3.12.2 for the underlying control.
What Is an SPRS Score?
An SPRS score is the summary result of a NIST SP 800-171 DoD Assessment, posted in the Supplier Performance Risk System, where DoD contracting staff can see it before an award.
DFARS 252.204-7019 requires an offeror that must implement NIST SP 800-171 to have a current assessment on file, which the provision defines as not more than 3 years old unless a solicitation sets a shorter period. The score starts at 110. Under the DoD Assessment Methodology, each unimplemented requirement subtracts 5, 3, or 1 point depending on its effect on the network and its data, so a company with many gaps can post a negative number. DFARS 252.204-7020 defines three assessment types. A Basic Assessment is a contractor self-assessment that yields a confidence level of Low because the score is self-generated. Medium and High Assessments are performed by the government. Use our SPRS calculator, the SPRS score page, or the guide on how to calculate your SPRS score.
What Is DFARS 252.204-7012?
DFARS 252.204-7012 is the defense contract clause that requires contractors to safeguard covered defense information and to report cyber incidents to DoD.
The clause defines "rapidly report" as "within 72 hours of discovery of any cyber incident," and it directs contractors to file those reports at dibnet.dod.mil. It also sets an evidence duty that surprises many companies. When a contractor discovers an incident, it must preserve and protect images of all known affected systems and the relevant monitoring and packet capture data for at least 90 days from the report, so that DoD can request the media or decline interest. Two operational consequences follow. A contractor needs logging and imaging capability in place before an incident, and it needs an incident response plan that starts the 72-hour clock correctly. Our DFARS 252.204-7012 page walks through the clause.
What Is ITAR (International Traffic in Arms Regulations)?
ITAR is the set of State Department regulations, 22 CFR Parts 120 through 130, that controls the export and temporary import of defense articles and defense services.
The authority comes from Section 38 of the Arms Export Control Act, 22 U.S.C. 2778. The items under control make up the U.S. Munitions List in 22 CFR Part 121. The Directorate of Defense Trade Controls administers the rules. Registration reaches further than many manufacturers expect. Under 22 CFR 122.1, any person who engages in the United States in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, must register, and "a manufacturer who does not engage in exporting must nevertheless register." One occasion of that activity is enough to count as engaging in the business. For IT teams, ITAR turns into a question about who can access technical data and where it is stored. See our ITAR compliance page.
What Is FedRAMP?
FedRAMP, the Federal Risk and Authorization Management Program, is the government-wide program that standardizes security assessment and authorization for cloud products and services used by federal agencies.
The General Services Administration describes it as "a governmentwide program that provides a standardized approach to security and risk assessment for cloud products and services." The program office sits inside GSA and keeps a repository of authorizations so that one agency can reuse another agency's security package. A FedRAMP Board of seven federal technology executives acts as the voting body. Contractors meet FedRAMP most often through DFARS 252.204-7012. When a contractor uses an external cloud service for covered defense information, the clause requires the provider to meet "security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline." If your CUI lives in a commercial cloud service, the authorization status of that service becomes part of your own compliance evidence. Our FedRAMP page explains the options.
What Are FIPS 140-2 and FIPS 140-3?
FIPS 140-2 and FIPS 140-3 are the federal standards that set security requirements for cryptographic modules, the hardware or software components that perform encryption.
FIPS 140-3 supersedes FIPS 140-2, which dates from December 3, 2002. The newer standard provides four increasing, qualitative levels of security, and its supporting documents build on the international standard ISO/IEC 19790:2012. The transition reaches a milestone this month. According to the NIST Cryptographic Module Validation Program, all FIPS 140-2 certificates move to the Historical List on September 22, 2026. NIST adds that the program still supports the purchase and use of those modules for existing systems. The distinction that matters in an assessment is between an algorithm and a validated module. Running AES is different from running a module that holds a validation certificate. The DoD Assessment Methodology states that FIPS-validated encryption is required to protect the confidentiality of CUI. See requirement 3.13.11.
Security Operations Terms
What Is a SOC (Security Operations Center)?
A Security Operations Center is the team, with its processes and tools, that monitors an organization's systems for threats, investigates alerts, and coordinates the response to security incidents.
The NIST glossary lists SOC as the abbreviation for Security Operations Center and points readers to several publications for context, including SP 800-53 Revision 5 and the incident response guide SP 800-61 Revision 3. A SOC can be staffed in-house, outsourced to a provider, or split between the two. The abbreviation causes real confusion because SOC also stands for System and Organization Controls, the AICPA reporting framework behind a SOC 2 report. One is a monitoring function and the other is an audit report. A SOC depends on the tools defined in the next three entries: a SIEM collects the data, a SOAR platform automates the routine response steps, and EDR supplies visibility on each device. Read about SOC as a service or our managed XDR suite.
What Is SIEM (Security Information and Event Management)?
A SIEM is an application that gathers security data from across an organization's systems and presents it as actionable information through a single interface.
That definition comes from NIST SP 800-128. In practice a SIEM ingests logs from firewalls, servers, cloud services, and endpoints, then correlates events so that an analyst sees one incident instead of thousands of separate log lines. CISA published joint guidance on SIEM and SOAR platforms with the Australian Signals Directorate's Australian Cyber Security Centre and other partners. The practitioner volume in that set deals with a problem every SIEM owner meets, which is deciding which log sources to ingest first. For compliance work, a SIEM is the usual way to meet audit logging, log review, and event correlation requirements in NIST SP 800-171. See our managed SIEM service.
What Is SOAR (Security Orchestration, Automation, and Response)?
SOAR is a category of security platform that connects an organization's security tools and automates predefined response actions when specific conditions are detected.
CISA's guidance describes the practitioner value of these platforms as using them to "streamline incident response processes by automating predefined actions based on detected anomalies." A typical playbook receives an alert from the SIEM, enriches it with threat intelligence, isolates the affected device through the EDR tool, opens a ticket, and notifies the analyst on call. The automation pays off on high-volume, low-ambiguity alerts. It also carries a risk. A platform that acts automatically needs careful tuning, because a playbook that isolates the wrong server can disrupt the business on its own. Small organizations usually consume SOAR as part of a managed service. Our MDR versus SIEM comparison explains the service models.
What Is EDR (Endpoint Detection and Response)?
Endpoint Detection and Response is security software on laptops, servers, and other endpoints that records activity, detects malicious behavior, and lets responders contain and remediate a threat on the device.
Executive Order 14028, Improving the Nation's Cybersecurity, made the capability federal policy in May 2021. Section 7(b) directs civilian agencies to deploy an EDR initiative "to support proactive detection of cybersecurity incidents within Federal Government infrastructure, active cyber hunting, containment and remediation, and incident response." The four functions in that sentence are a fair test of any product that claims the label. EDR differs from traditional antivirus because it keeps a record of what happened on the device, which lets an investigator reconstruct an attack after the fact. Read our EDR explainer for a longer treatment.
What Is MFA (Multi-Factor Authentication)?
Multi-factor authentication is authentication that uses two or more different factors: something you know, something you have, or something you are.
The NIST glossary, citing CNSSI 4009-2022, gives examples of each factor: a PIN or password, a cryptographic identification device or token, and a biometric. Two passwords do not qualify, because both are the same kind of factor. The DoD Assessment Methodology shows how much weight assessors give the control. Five points are subtracted from the SPRS score of 110 if MFA is not implemented for any users. Three points are subtracted if it is implemented only for remote and privileged users. Few single controls move the score that much. See requirement 3.5.3 for the CMMC language.
What Is Zero Trust Architecture?
Zero trust architecture is an enterprise cybersecurity plan built on the idea that no user, device, or network location is trusted by default, so every access request is verified.
NIST SP 800-207 defines it as "an enterprise's cybersecurity plan that utilizes zero trust concepts and encompasses component relationships, workflow planning, and access policies." A second NIST publication, SP 800-160 Volume 2, adds that the model "eliminates implicit trust in any one element, component, node, or service" and requires continuous verification. Zero trust is a design approach and cannot be bought as a product. It replaces the old assumption that anything inside the office network is safe. Typical building blocks are strong identity, device health checks, segmentation, and logging of every access decision. Read how zero trust architecture works.
What Is Encryption at Rest?
Encryption at rest is the protection of stored data, on a disk, a phone, a backup, or removable media, so that someone who obtains the storage cannot read the information.
NIST SP 800-111 calls this storage encryption and describes it as "the process of using encryption and authentication to restrict access to and use of stored information." The rules treat it differently by sector. NIST SP 800-171 requires contractors to protect the confidentiality of CUI at rest. The HIPAA Security Rule lists encryption and decryption of electronic protected health information as an addressable implementation specification at 45 CFR 164.312(a)(2)(iv). Addressable means the organization must assess the safeguard and document its decision. It does not mean the safeguard is optional. For laptops and phones that leave the building, full-disk encryption is the control that turns a lost device into an inconvenience and not a reportable breach. See requirement 3.13.16.
What Is Social Engineering?
Social engineering is an attempt to trick a person into revealing information or taking an action that an attacker can use against systems or networks.
NIST SP 800-82 Revision 3 defines it as "an attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks." Phishing email is the best-known form. Phone calls to a help desk, text messages, and in-person pretexts all count. The defense is part technical and part human. Email filtering and MFA limit what a stolen password can do. Training and realistic testing teach staff to slow down when a request is urgent, unusual, or secretive. Our social engineering testing service measures how your team responds.
Commercial and Healthcare Compliance Terms
What Is PCI DSS (Payment Card Industry Data Security Standard)?
PCI DSS is the global security standard for organizations that store, process, or transmit payment card account data.
The PCI Security Standards Council, which maintains it, says the standard "provides a baseline of technical and operational requirements designed to protect payment account data." American Express, Discover, JCB International, MasterCard, and Visa Inc. founded the Council in 2006. Each brand incorporates PCI DSS into its own compliance program, which is why enforcement reaches a merchant through its acquiring bank and card brand contracts and not through a government agency. Two assessor roles appear throughout the standard. Qualified Security Assessors are independent organizations that the Council has qualified to perform PCI DSS assessments. Approved Scanning Vendors conduct the external vulnerability scans the standard requires. Start with our PCI DSS compliance page or the PCI DSS compliance checklist.
What Is SOC 2?
SOC 2 is an AICPA reporting framework in which an independent CPA firm examines a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.
The AICPA's own guide carries the full name: "SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy." Those five categories are the Trust Services Criteria. The word examination matters. The result of a SOC 2 engagement is a report that contains the auditor's opinion. Nobody receives a certificate, so the accurate phrases are "SOC 2 report" and "SOC 2 examination." The AICPA describes its SOC 2 guide as the authoritative resource for CPAs who perform these examinations. Buyers of software and cloud services ask for the report during vendor review. The difference between a Type 1 and a Type 2 report is covered in our SOC 2 Type 2 guide, linked below. See our SOC 2 compliance services, the SOC 2 compliance checklist, and the SOC 2 Type 2 guide.
What Is the HIPAA Security Rule?
The HIPAA Security Rule is the federal regulation, in 45 CFR Part 164, that requires covered entities and business associates to protect electronic protected health information.
Its general rule at 45 CFR 164.306(a) requires those organizations to "ensure the confidentiality, integrity, and availability of all electronic protected health information" they create, receive, maintain, or transmit. The rule is deliberately flexible. Section 164.306(b) lets an organization choose security measures that fit its size, complexity, capabilities, and technical infrastructure. That flexibility comes with a documentation burden, because each decision has to be justified. The rule also requires a periodic technical and nontechnical evaluation under 45 CFR 164.308(a)(8). The regulation describes compliance and evaluation, and it does not describe a government-issued certificate. For that reason we describe an organization as HIPAA compliant and never as certified. See our HIPAA compliance page and the HIPAA security risk assessment.
Artificial Intelligence Terms
What Is RAG (Retrieval-Augmented Generation)?
Retrieval-augmented generation is an AI system design in which a language model is paired with a separate information retrieval system, so the model answers from documents retrieved at the time of the question.
NIST AI 100-2 (2025 edition) defines a RAG system as one where, "based on a user query, the RAG system identifies relevant information within the knowledge base and provides it to the GenAI model in context for the model to use in formulating its response." NIST adds that these systems allow a model's knowledge to be modified without retraining. The term comes from a 2020 research paper by Patrick Lewis and 11 co-authors, "Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks." For a regulated business the security question is where the knowledge base lives and who can query it. A RAG system that indexes contracts, patient records, or CUI inherits every obligation attached to that data. That is the main reason some organizations run the model and the index on infrastructure they control. See our AI services, private LLM deployment, and the private AI deployment guide.
How These Terms Fit Together
The contracting terms form a chain, and a worked example shows how they connect. A machine shop in North Carolina wins a subcontract to produce parts from drawings that a prime contractor marks as CUI. The drawings are CUI under 32 CFR Part 2002. The rest of the contract paperwork is FCI. Because the drawings describe a defense article, ITAR may also restrict who can see them.
The subcontract flows down DFARS 252.204-7012, so the shop must safeguard the information and must be able to report a cyber incident within 72 hours. It must implement NIST SP 800-171 Revision 2. The shop writes a System Security Plan that describes the enclave where the drawings live, scores itself against the 110 requirements, and posts the result in SPRS. Gaps go into a Plan of Action and Milestones. When the contract calls for CMMC Level 2 (C3PAO), an assessor tests the same requirements, and any conditional result must be closed out within 180 days.
The security operations terms describe how the shop meets those requirements each day. MFA protects logins. EDR watches the workstations that open the drawings. A SIEM collects the logs that the audit requirements call for, and a SOC, in-house or outsourced, reviews them. FIPS-validated encryption protects the files at rest and in transit. If the shop stores the drawings in a cloud service, the FedRAMP status of that service becomes part of the evidence.
The commercial terms follow the same logic with different owners. A medical practice answers to the HIPAA Security Rule. A retailer answers to PCI DSS through its card brand contracts. A software company answers to its customers, who ask for a SOC 2 report. In every case the work starts by identifying which data you hold, because the data type decides which rule applies.
Frequently Asked Questions
What is the difference between CUI and FCI?
FCI is any non-public information provided by or generated for the government under a contract, as defined in FAR 52.204-21. CUI is a narrower category defined in 32 CFR 2002.4: information that a law, regulation, or government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls. FCI maps to CMMC Level 1, and CUI maps to Level 2 or Level 3.
What is the highest possible SPRS score?
The highest score is 110, which means all 110 requirements of NIST SP 800-171 Revision 2 are implemented. The DoD Assessment Methodology subtracts 5, 3, or 1 point for each requirement that is not implemented, so the total can fall below zero.
Is SOC the same thing as SOC 2?
No. A SOC is a Security Operations Center, the team that monitors and responds to threats. SOC 2 is an AICPA report on a service organization's controls, where the letters stand for System and Organization Controls. A company can have either one without the other.
Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?
Revision 2. NIST published Revision 3 in May 2024, and it supersedes Revision 2 as a NIST document. The CMMC rule at 32 CFR 170.14 incorporates Revision 2 by reference and states that the Level 2 requirements are identical to it.
Are FIPS 140-2 validated modules still acceptable?
NIST moves all FIPS 140-2 certificates to the Historical List on September 22, 2026. The Cryptographic Module Validation Program states that it still supports the purchase and use of those modules for existing systems. New purchases should favor modules validated under FIPS 140-3, and you should confirm what your contract or assessor expects.
Does the government certify HIPAA compliance?
The HIPAA Security Rule requires compliance and periodic evaluation. It does not describe a certificate issued by the government. Treat a vendor's certification claim as marketing language, and ask for the risk analysis and evaluation records instead.
Sources
Every definition on this page was checked against the following primary sources on September 20, 2026.
- 32 CFR 2002.4, Controlled Unclassified Information definitions, and the National Archives CUI program overview
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- 32 CFR 170.3, 170.14, and 170.21, Cybersecurity Maturity Model Certification Program
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021
- NIST SP 800-171 Revision 2 and Revision 3 publication records, and the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1
- 22 CFR 120.1, 120.2, and 122.1, International Traffic in Arms Regulations
- General Services Administration, FedRAMP program description
- FIPS 140-3 publication record and the NIST FIPS 140-3 Transition Effort page
- NIST Computer Security Resource Center glossary entries for Security Operations Center, SIEM tool, multi-factor authentication, zero trust architecture, system security plan, plan of action and milestones, social engineering, and retrieval-augmented generation
- CISA, Guidance for SIEM and SOAR Implementation
- Executive Order 14028, Improving the Nation's Cybersecurity, Section 7(b)
- NIST SP 800-111, Guide to Storage Encryption Technologies for End User Devices
- PCI Security Standards Council, PCI DSS standard page and About Us page
- AICPA, SOC 2 resources
- 45 CFR 164.302, 164.306, 164.308, and 164.312, HIPAA Security Rule
- Lewis et al., Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks, arXiv 2005.11401
Talk to a Compliance Team That Works With These Rules Daily
Petronella Technology Group, Inc. is a CMMC Registered Provider Organization. Founder Craig Petronella holds the CMMC Registered Practitioner credential, along with CCNA and CWNE certifications, and he is a North Carolina Licensed Digital Forensic Examiner (license 604180). He has more than 30 years of experience in IT and cybersecurity, and the company has served clients from Raleigh since 2002.
If one of these terms just appeared in a contract, a security questionnaire, or an audit request, call Penny at 919-348-4912 and describe what you were asked for. You can also reach us through the contact form.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.