Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A computer network attack (CNA) is an attack via cyberspace against an enterprise’s use of cyberspace, intended to disrupt, disable, destroy, or maliciously control its computing environment or infrastructure—or to destroy data integrity or steal controlled information. That is the current definition in the NIST CSRC glossary, attributed through NIST publications to CNSSI 4009-2022.

What the CNA definition includes

NIST’s wording describes an attack by its means, target, and purpose—not by a particular tool or technique. The target is an enterprise’s use of cyberspace, and the stated purposes include:

  • Disrupting, disabling, or destroying a computing environment or infrastructure.
  • Maliciously controlling that environment or infrastructure.
  • Destroying the integrity of data.
  • Stealing controlled information.

In this definition, CNA is therefore a purpose-and-target term. It does not name one specific method, and the definition alone does not establish who carried out an attack or how it was performed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How CNA differs from broader attack terminology

The NIST glossary’s general entry for attack covers malicious activity that attempts to collect, disrupt, deny, degrade, or destroy system resources or information. Its Cyber Attack entry presents formulations from different authorities and documents, including one centered on unauthorized access or compromising confidentiality, integrity, or availability. These are related terms, but they have different scope and source contexts; they should not be merged into a single definition of CNA.

Likewise, NIST’s cyberspace attack terminology discusses denial effects and manipulation that may have consequences in physical domains. That adjacent concept is not automatically interchangeable with computer network attack.

Current wording versus an older definition

NIST’s current CSRC glossary entry uses the enterprise-focused wording above. An earlier formulation appears in NIST IR 7298 Rev. 2: “Actions taken through the use of computer networks to disrupt, deny, degrade, or destroy information resident in computers and computer networks, or the computers and networks themselves.”

The older definition emphasizes actions through computer networks and lists disruption, denial, degradation, and destruction. The current CSRC wording instead refers to an enterprise’s use of cyberspace and also expressly includes disabling, malicious control, destruction of data integrity, and theft of controlled information. Cite the version and source when using either formulation rather than presenting the older wording as NIST’s current glossary text.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How CNA relates to computer network defense

Computer network defense is a related but distinct term. CISA’s NICCS glossary describes it as actions taken to defend against unauthorized activity on computer networks. CNA names an attack purpose; computer network defense names defensive actions. The defense term is not a synonym for CNA or a category of attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.