Glossary of Privileged Access and Compliance Terms
These are the terms used on this site, in plain words.

| Term | Meaning | Read more |
|---|---|---|
| Affirming official | The senior person who signs the annual CMMC affirmation that the organization is meeting the required level. | DFARS 252.204-7021 |
| Air-gapped | A system isolated from general network reach. | Air-gapped systems |
| Assessment Binder | The AIC living evidence package shared by the assessor, the Managed Service Provider, and the Customer. | Continuous compliance |
| Blast radius | How many hosts and services a single shared credential reaches. | What is password management |
| C3PAO | CMMC Third-Party Assessment Organization. The assessor for CMMC Level 2 certification. | C3PAO |
| CIEM | Cloud infrastructure entitlement management. Analysis of cloud account permissions. | Capabilities |
| Class deviation | An instruction that changes how a contracting activity applies an acquisition regulation, without amending the regulation itself. | CMMC Phase 2 |
| CMMC | Cybersecurity Maturity Model Certification. The U.S. Department of War program for protecting Federal Contract Information and Controlled Unclassified Information. | CMMC for defense contractors |
| CMMC Status | The outcome of a CMMC assessment, such as Final Level 2 (Self) or Conditional Level 2 (C3PAO). | DFARS 252.204-7021 |
| CMMC UID | The unique identifier issued for an assessed system, reported alongside the CMMC Status. | DFARS 252.204-7021 |
| Conditional status | A CMMC status granted with eligible items on a POA&M, which must be closed and verified within 180 days. | What is a POA&M |
| Continuous compliance | Keeping the compliance record current with ongoing feeds, alerts, and monitoring instead of a point-in-time check. | Continuous compliance |
| CUI | Controlled Unclassified Information. Unclassified information a law, regulation, or government-wide policy requires to be safeguarded. | What is CUI |
| CUI Basic | CUI whose authority requires safeguarding but does not specify how. | CUI marking |
| CUI Specified | CUI whose authority names specific handling, marking, dissemination, or destruction requirements. | CUI marking |
| Current State Compliance | The AIC ledger of control findings with rescan. | Continuous compliance |
| Decontrolling | Ending the CUI control on information. It does not by itself authorize public release. | CUI marking |
| Designation indicator | The block on a CUI document naming who designated it and under what authority. | CUI marking |
| DFARS | Defense Federal Acquisition Regulation Supplement. Clause 252.204-7012 is the one that requires NIST SP 800-171 safeguarding and cyber incident reporting. | DFARS 252.204-7012 |
| DIBCAC | Defense Industrial Base Cybersecurity Assessment Center. Conducts High assessments and CMMC Level 3 assessments. | NIST SP 800-171 self-assessment |
| DIBNet | The portal where a defense contractor reports a cyber incident within 72 hours. | DFARS 252.204-7012 |
| FCI | Federal Contract Information. Information provided by or generated for the government under a contract and not intended for public release. | CMMC Level 1 |
| FedRAMP | Federal Risk and Authorization Management Program. The authorization program a cloud service must meet to process CUI. | DFARS 252.204-7012 |
| Flowdown | Passing a contract clause to a subcontractor who will handle the same information. | DFARS 252.204-7021 |
| IGA | Identity governance and administration. Account lifecycle and access review. | What is IGA |
| ISPM | Identity security posture management. Findings about identity and configuration exposure. | Capabilities |
| ITDR | Identity threat detection and response. | Detect, respond, and remediate |
| JIT | Just-in-time. Privilege granted only for a limited time. | What is just-in-time access |
| Least privilege | Holding only the authority the job requires, and nothing more. | What is least privilege |
| MSP | Managed Service Provider. | Partners for MSPs |
| PAM | Privileged Access Management. Brokered and recorded privileged sessions. | What is PAM |
| PASM | Privileged account and session management. | Industry terms |
| Password management | Creating, storing, rotating, and retiring the credentials people and systems authenticate with. | What is password management |
| PEDM | Privilege elevation and delegation management. | Privileged user management |
| PIM | Privileged Identity Management. Vaulting and rotation of privileged credentials. | Privileged identity management |
| POA&M | Plan of Action and Milestones. The tracked list of requirements not yet met, each with an owner and a closure date. | What is a POA&M |
| Portion marking | The short marking on an individual paragraph of a CUI document. | CUI marking |
| PUM | Privileged User Management. The AIC module for privilege elevation and delegation management. | Privileged user management |
| RPAM | Remote privileged access management. | Industry terms |
| Secure enclave | An isolated work boundary with AIC tools built in. | Secure enclaves |
| Session recording | Capturing a privileged session so it can be replayed afterward. | What is session recording |
| SPRS | Supplier Performance Risk System. The government database where a defense contractor posts its NIST SP 800-171 assessment score. | Your SPRS score |
| SSP | System security plan. The document describing the system being assessed, as it actually is. | NIST SP 800-171 self-assessment |
| sudo | A Unix and Linux program that runs a single command as another user, usually root. | What is sudo |
| ZSP | Zero standing privileges. No permanent administrator rights. | What is ZSP |
Terms explained at length
- What is privileged access management
- What is password management
- What is least privilege
- What is just-in-time access
- What is zero standing privileges
- What is session recording
- What is sudo
- What is identity governance and administration
- What is Controlled Unclassified Information
- What is a Plan of Action and Milestones