- Access
- Access Authority
- Access Control
- Access Control Policy
- Access Profile
- Accountability
- Activity
- Administrative Safeguards
- Advanced Persistent Threat
- Adversarial Assessment
- Adversary
- Air Gap
- Alert
- Anti-Malware Tools
- Anti-Spyware Software
- Anti-Tamper
- Anti-Virus Software
- Assessment
- Asset
- Asset Custodian
- Asset Management
- Asset Owner
- Asset Types
- Attack Surface
- Attribute-Based Access Control
- Audit
- Audit Log
- Audit Record
- Authentication
- Authenticator
- Authoritative Source
- Authorization
- Availability
- Awareness
- Awareness and Training Program
- Backup
- Baseline
- Baseline Configuration
- Baseline Security
- Baselining
- Blacklist
- Blacklisting Software
- Blue Team
- Breach
- Change Control (Change Management)
- Cipher
- Ciphertext
- CMMC Assessment Scope
- CMMC Asset Categories
- Compliance
- Component
- Confidentiality
- Configuration Item
- Configuration Management
- Consequence
- Container (Information Asset Container)
- Context Aware
- Continuity of Operations
- Continuous
- Continuous Monitoring
- Contractor Risk Managed Assets
- Control
- Controlled Unclassified Information (CUI)
- Covered Defense Information (CDI)
- Cryptographic Hashing Function
- CUI Assets
- Custodian
- Cybersecurity
- Defense Industrial Base
- Demilitarized Zone
- Dependency
- Domain
- Enclave
- Encryption
- Encryption Policies
- Endorse
- Enterprise
- Enterprise Architecture
- Environment of Operations
- Establish and Maintain
- Event
- Event Correlation
- Exercise
- Facility
- Federal Contract Information
- Federated Trust
- Federation
- Firewall
- Flash Drive
- Government Property
- High-Value Asset
- High-Value Service
- Identification
- Identity
- Identity-Based Access Control
- Identity, Credential, and Access Management
- Identity Management System
- Incident
- Incident Response
- Incident Stakeholder
- Industrial Control System
- Information Flow
- Information System
- Information System Component
- Insider
- Insider
- Insider Threat
- Insider Threat
- Insider Threat Program
- Insider Threat Program
- Integrity
- Integrity
- Internet of Things
- Inventory
- Least Privilege
- Life Cycle
- Maintenance
- Malicious Code
- Malware
- Maturity Model
- Media
- Media Sanitization
- Mobile Code
- Mobile Device
- Monitor
- Multifactor Authentication
- Ongoing Basis
- Operational Resilience
- Operational Technology
- Organization
- Organizational Asset
- Organizationally Defined
- Organizational System
- Organization Seeking Certification
- Out-of-Scope Asset
- Patch
- Penetration Testing
- Periodically
- Personally Identifiable Information
- Plan
- Policy
- Portable Storage Device
- Practice
- Privilege
- Privileged Account
- Privileged User
- Procedure
- Process
- Proxy
- Real-Time
- Recovery
- Red Team
- Red Teaming
- Regularly
- Remote Access
- Removable Media
- Reporting
- Residual Risk
- Resilience
- Restricted Information Systems
- Risk
- Risk Analysis
- Risk Assessment
- Risk Management
- Risk Mitigation
- Risk Mitigation Plan
- Risk Tolerance
- Root-Cause Analysis
- Root Directory
- Safeguards
- Sandboxing
- Scanning
- Security Assessment
- Security Control Assessment
- Security Domain
- Security Operations Center
- Security Policy
- Security Practice Assessment
- Security Protection Assets
- Sensitive Information
- Separation of Duties
- Service Continuity Plan
- SHA-256
- Situational Awareness
- Specialized Asset
- Split Tunneling
- Spyware
- Standard Process
- Standards
- Subnetwork
- Supply Chain
- Supply Chain Attack
- Supply Chain Risk Management
- Sustain
- System Assets
- System Boundary
- System Integrity
- System Interconnection
- System Security Plan
- Tampering
- Test Equipment
- Threat
- Threat Actor
- Threat Intelligence
- Threat Monitoring
- Trigger
- Trojan Horse
- Tunneling
- Unauthorized Access
- User
- Virus
- Vulnerability
- Vulnerability Assessment
- Vulnerability Management
- Web Proxy
- Whitelist
