Skip to content
compliancebase

Glossary

Compliance vocabulary carries specific, often narrow meanings that get flattened in casual use — "audit," for example, means something different in a SOC 2 Type II engagement than it does in a penetration test writeup. Each entry here defines a term the way it is actually used in framework text and by auditors, not the way it gets loosely used in marketing copy.

Terms are listed alphabetically below. If a term appears on a framework or control page in a way that assumes prior knowledge — CUEC, ISMS, Statement of Applicability, Trust Services Criteria — it is defined here, usually with a link back to the framework context where the distinction matters most.

This page is for quick lookup, not learning a framework from scratch. If you are new to a framework entirely, start at its overview page instead — it introduces the vocabulary in context rather than as an isolated list.

  • Access control

    Policies and technical mechanisms that restrict who can access information assets, systems, and data — typically including identity provisioning, authentication, authorization, periodic access reviews, and deprovisioning.

  • Adequacy decision

    A European Commission finding that a non-EEA country or arrangement provides essentially equivalent data protection for transfers.

  • Annex A

    ISO/IEC 27001:2022’s reference set of 93 information-security controls used in risk treatment.

  • Anonymization

    Processing that irreversibly prevents information from relating to an identified or identifiable person using reasonably likely means.

  • Audit evidence

    Information used to support a conclusion that a control is designed or operating as described.

  • Break-glass access

    Emergency privileged access used when normal identity or approval paths are unavailable.

  • Business associate

    Under HIPAA, a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (or another business associate) for covered functions — typically requiring a Business Associate Agreement (BAA) and Security Rule compliance for ePHI handled in that role.

  • Business Associate Agreement (BAA)

    A HIPAA-required contract defining permitted PHI uses and safeguard, reporting, and subcontractor duties between regulated parties.

  • Change management

    Controlled authorization, testing, deployment, and traceability of changes to systems and software.

  • Common Criteria

    SOC 2 Trust Services Criteria common to Security and relevant across governance, risk, access, operations, change, and vendors.

  • Controller

    The party that determines the purposes and means of processing personal data under GDPR.

  • Covered entity

    A HIPAA health plan, health care clearinghouse, or qualifying health care provider that conducts covered electronic transactions.

  • Data processing agreement (DPA)

    A contract allocating data-protection duties between a controller and processor, including Article 28 terms where GDPR applies.

  • Data protection impact assessment (DPIA)

    A documented GDPR assessment of high-risk processing, its necessity, risks to people, and measures that address those risks.

  • Data protection officer (DPO)

    An independent GDPR role required in specified circumstances to advise, monitor compliance, and serve as a contact point.

  • Electronic protected health information (ePHI)

    Individually identifiable health information covered by HIPAA that is created, received, maintained, or transmitted electronically.

  • Encryption at rest

    Cryptographic protection for stored data on disks, databases, backups, or object storage.

  • Encryption in transit

    Cryptographic protection for data moving across networks or service connections.

  • HIPAA risk analysis

    An accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

  • ISMS

    Information Security Management System — the documented policies, processes, and controls an organization establishes to manage information security risk under ISO/IEC 27001.

  • Joiner-mover-leaver (JML)

    The identity lifecycle for provisioning, changing, and revoking workforce access.

  • Least privilege

    The principle of granting only the access needed for a defined role, task, and time.

  • Logging and monitoring

    Collection, protection, analysis, and alerting on events needed to detect misuse, failure, or security incidents.

  • Multi-factor authentication (MFA)

    Authentication requiring evidence from at least two different factor categories, such as knowledge and possession.

  • Observation window

    The period over which a SOC 2 Type II examination evaluates control operation.

  • Personal data

    Under GDPR, any information relating to an identified or identifiable natural person (data subject) — including direct identifiers (name, email) and indirect identifiers (device IDs, online identifiers, location data combined with other information). Properly anonymized data falls outside the personal-data regime; pseudonymized data typically remains personal data.

  • Personal data breach

    A GDPR security breach causing accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

  • Processor

    A party that processes personal data on documented instructions from a controller.

  • Protected Health Information (PHI)

    Individually identifiable health information held or transmitted by a HIPAA covered entity or business associate in any form — electronic PHI (ePHI) is PHI in electronic form. PHI triggers HIPAA Privacy, Security, and Breach Notification Rule duties that SOC 2 attestation does not replace.

  • Pseudonymization

    Processing personal data so it cannot be attributed to a person without separately kept additional information.

  • Recovery point objective (RPO)

    The target maximum amount of data loss measured backward in time after disruption.

  • Recovery time objective (RTO)

    The target maximum time to restore a service after disruption.

  • Security incident

    An event that actually or potentially compromises security objectives or violates security policy and requires evaluation.

  • SOC 2 Type I vs Type II

    Type I reports on the design of controls at a point in time. Type II reports on the operating effectiveness of those controls over a defined period (commonly 3–12 months).

  • Standard Contractual Clauses (SCCs)

    European Commission contract clauses used as a transfer safeguard for certain exports of personal data outside the EEA.

  • Statement of Applicability (SoA)

    An ISO/IEC 27001 document listing Annex A controls, whether each is applicable, and justification for inclusions and exclusions based on the organization's risk assessment.

  • Sub-processor

    A processor engaged by another processor to handle personal data for the controller’s service.

  • Trust Services Criteria

    The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.

  • Vulnerability management

    The recurring process for identifying, prioritizing, remediating, and verifying weaknesses in systems and software.