// KNOWLEDGE BASE · GLOSSARY · HANS STUDY

Glossary

31 terms that come up across the networking, Windows hardening, structured cabling, access control, and CPCSC reference on this site. Each definition is short on purpose; the linked page is where the full detail lives.

VLAN

A VLAN is a logical subdivision of a switched network that keeps groups of devices separated at Layer 2 even when they share the same physical switches. Cameras, access control panels, and office computers each get their own VLAN, so a compromise on one doesn't reach the others. VLAN 1, the default on most switches, should carry nothing and should never be treated as a security boundary.

From VLAN segmentation for physical security networks.

Trunk port

A trunk port carries traffic for multiple VLANs between switches using 802.1Q tagging, which is how an uplink from an access switch to the core or a firewall passes every VLAN that needs to move between them. A trunk that allows every VLAN by default is a gap; it should carry only the VLANs the devices on that segment actually use.

From VLAN segmentation for physical security networks.

IGMP snooping

IGMP snooping is a switch feature that listens to IGMP membership requests and forwards a multicast stream only to the ports that asked for it, instead of flooding it to every port the way broadcast traffic does. Without it, a camera VLAN carrying 200 multicast streams pushes all of them out every port.

From Multicast for CCTV networks.

IGMP querier

An IGMP querier is the device on a VLAN that sends the periodic IGMP queries which keep a switch's snooping tables alive. A video VLAN with IGMP snooping on and no querier looks fine at commissioning, then drops streams a few minutes after clients connect, a fault that gets misdiagnosed as a camera or driver problem more often than it should.

From Multicast for CCTV networks.

PoE class (802.3af, at, bt)

PoE class sets how much power a switch port can deliver: 802.3af (Type 1) tops out at 15.4 W, 802.3at (Type 2) at 30 W, and 802.3bt (Types 3 and 4) at 60 or 90 W. The switch's power supply, not the port's rated class, is what actually limits how many high-draw devices like PTZs and heated domes a switch can carry.

From PoE budgets for camera and access control switches.

CIDR

CIDR notation states how many bits of an IP address belong to the network versus the host, so 10.42.67.0/24 means 24 network bits and 8 host bits. It is how every subnet on a modern security network gets sized, and it replaced the older class-based addressing scheme.

From Subnet calculator.

DHCP snooping

DHCP snooping stops unauthorized DHCP servers from handing out addresses on a VLAN by only accepting DHCP replies from ports marked trusted, normally just the uplink. A camera or access control port is untrusted by default, so a device plugged into one can't act as a rogue DHCP server.

From Cisco Catalyst 9200 and 9300 base configuration.

Dynamic ARP inspection

Dynamic ARP inspection, or DAI, checks ARP packets against the DHCP snooping binding table and drops anything that doesn't match, which is what stops ARP spoofing attacks that redirect traffic by poisoning a device's ARP cache. DAI depends on DHCP snooping being configured first, since it reads the same binding table.

From Cisco Catalyst 9200 and 9300 base configuration.

LAPS

LAPS, the Local Administrator Password Solution, rotates and stores a unique local administrator password per machine in Active Directory instead of leaving the same password on every box. Windows LAPS has shipped in Server 2019 and 2022 since the April 2023 update and is built into Server 2025; Server 2016 still needs the deprecated legacy LAPS.

From Hardening Windows Server 2016, 2019, and 2022 with Group Policy.

SMB signing

SMB signing adds a cryptographic signature to SMB traffic so it can't be tampered with in transit without detection. It should be required on every server in an environment, not only domain controllers, and Windows Server 2025 requires it by default on outbound connections.

From Hardening Windows Server 2016, 2019, and 2022: other considerations.

NTLM restriction

NTLM is the legacy Windows authentication protocol that Kerberos replaced in Active Directory, and restricting it means auditing what still depends on it, since systems accessed by IP address, older applications, and some NAS devices and printers can still rely on it. At minimum, NTLMv1 and LM authentication, the weakest variants, should be disabled everywhere.

From Hardening Windows Server 2016, 2019, and 2022 with Group Policy.

Credential Guard

Credential Guard isolates domain credentials inside a virtualization-based container so a compromised kernel can't read them, and it's on by default on a fresh Server 2025 install with UEFI, Secure Boot, and a TPM. It can break integrations that depend on unconstrained Kerberos delegation or older NTLMv1 flows, which is worth testing before moving a production VMS or access control host to it.

From Hardening Windows Server 2025: what changed.

Delegated managed service account

A delegated managed service account, or dMSA, is a Server 2025 account type that can take over an existing service account's permissions, which makes migrating a security system service off a password-bearing domain account far less disruptive. It sits alongside group managed service accounts (gMSA), the safer way to run a service without a password since Server 2012.

From Hardening Windows Server 2025: what changed.

Windows Event Forwarding

Windows Event Forwarding collects security logs from VMS and access control hosts into a central collector using source-initiated subscriptions pushed by Group Policy, so nothing on the collector needs credentials to reach into the servers it collects from. A SIEM can then read from the collector instead of running an agent on every host.

From Windows Event Forwarding for security systems.

Advanced audit policy

Advanced Audit Policy is the Windows setting that audits specific subcategories within each event category, rather than the coarse, all-or-nothing basic audit policy it replaces. It should be configured through Group Policy, and it should never be mixed with the basic policy on the same system, since the advanced setting takes precedence and the mix gets confusing fast.

From Hardening Windows Server 2016, 2019, and 2022: audit logging.

TMGB

The Telecommunications Main Grounding Busbar is the single point in a building, normally the main equipment room at the service entrance, where the telecommunications grounding system bonds to the building's electrical ground. CSA T607 and its ANSI parallel J-STD-607-A set its sizing and installation, and every commercial building gets exactly one.

From CSSIR-04: grounding and bonding.

TGB

A Telecommunications Grounding Busbar sits in every telecom space in a building other than the one holding the TMGB, so every IDF closet, equipment room, and dedicated security room gets its own TGB. Each TGB bonds back to the TMGB through the telecommunications bonding backbone.

From CSSIR-04: grounding and bonding.

TBB

The Telecommunications Bonding Backbone is the conductor that bonds a TGB back to the building's TMGB, sized per the CSA T607 / J-STD-607-A tables rather than guessed at. It's the connection that makes the TMGB and every TGB one grounding system instead of several isolated ones.

From CSSIR-04: grounding and bonding.

OLTS (Tier 1)

An Optical Loss Test Set measures end-to-end insertion loss on a fibre link at its operating wavelengths, and running it is Tier 1 testing under ANSI/TIA-568.3-E. Every fibre link on an institutional install gets a Tier 1 test.

From CSSIR-10: cable testing and certification.

OTDR (Tier 2)

An optical time-domain reflectometer sends a light pulse down a fibre and reads the reflections back to locate splices, connectors, and faults along its length, which is Tier 2 testing under ANSI/TIA-568.3-E. Tier 2 goes beyond the single loss number Tier 1 gives and shows where a problem actually sits on the run.

From CSSIR-10: cable testing and certification.

AHJ

The Authority Having Jurisdiction is the inspector or office that enforces code on a given project, and their local interpretation of a clause is what actually governs on site, not the federal text alone. Different AHJs read the same clause differently, so the right response to a disagreement is to comply on site and raise the interpretation through formal channels afterward, not argue with the inspector at rough-in.

From CSSIR-01: codes and standards.

REX

A Request-to-Exit device unlocks a door from the secure side for egress and shunts the door-forced alarm while someone is leaving, commonly a PIR sensor over the door or a pushbutton on the frame. REX alone doesn't break a fail-safe maglock's power circuit; most maglock installs need a separate REX-triggered release for that.

From CSSIR-13: access control at the door.

Door position switch

A door position switch, or DPS, reports whether a door is open or closed back to the access control panel, normally mounted at the top of the frame on the strike side where it isn't user-accessible. It's what the system uses to tell a held-open door apart from a forced one.

From CSSIR-13: access control at the door.

Pixels per foot

Pixels per foot is the camera's horizontal resolution divided by the width of the scene at a given distance, and it's the number that decides whether a camera can identify, recognize, observe, or just detect a subject at that range. The rough tiers run about 80 PPF for identification, 40 for recognition, 20 for observation, and 10 for detection.

From CSSIR-14: CCTV and video.

OSDP

OSDP, the Open Supervised Device Protocol, is the access control reader protocol that replaced Wiegand with two-way, encrypted communication between reader and controller. Version 2.2 with Secure Channel is the specification for new institutional work; Wiegand belongs on retrofits only, with a stated migration path.

From CSSIR-13: access control at the door.

CCSRA

The Contract Cyber Security Risk Assessment is the review PSPC runs on each individual defence contract to decide whether CPCSC applies and which level it carries, based on the information the contract exposes rather than the supplier's size or the contract's dollar value. The result is stated in the RFP and the contract clauses; a supplier doesn't choose its own level.

From The CCSRA: how DND decides your CPCSC level.

Flow-down

Flow-down is how a certification requirement moves from a prime contractor down through every tier of its supply chain, usually arriving as a questionnaire and a deadline from the customer a supplier actually deals with, rather than from the government directly. Allied programs in the UK and US already work this way, and CPCSC is expected to cascade through Canadian defence subcontracts the same way.

From Flow-down is coming: what your prime will ask.

CPCSC level

A CPCSC level is set per contract, not chosen by the supplier, through the contract cyber security risk assessment PSPC runs against what that specific contract exposes. Level 1 is a 13-control annual self-assessment, Level 2 is a 98-control third-party assessment, and Level 3 is 130-plus controls assessed by National Defence.

From CPCSC, explained.

iDMZ

An industrial DMZ sits between the plant network and the corporate network so nothing on the business side talks directly to a controller. Data that has to cross, such as historian replication or a remote view, moves through brokered services in the iDMZ instead, so a compromise on the corporate side hits the DMZ rather than the plant.

From Security controls for OT networks that hold up in production.

Zones and conduits

Zones and conduits is the IEC 62443 model for segmenting an OT network: group assets into zones by function and risk, then define exactly what's allowed to cross between them through controlled conduits, defaulting to deny everything else. It's the structure behind the Purdue model layers most OT segmentation designs start from.

From Security controls for OT networks that hold up in production.

Looking for the full reference?

The Canadian Security Install Reference, the hardening guides, and the how-tos each go well past a glossary entry.