Skip to content
compliancebase

Glossary

Precise definitions for compliance terms engineers encounter in audits and frameworks.

  • Access control

    Policies and technical mechanisms that restrict who can access information assets, systems, and data — typically including identity provisioning, authentication, authorization, periodic access reviews, and deprovisioning.

  • Business associate

    Under HIPAA, a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (or another business associate) for covered functions — typically requiring a Business Associate Agreement (BAA) and Security Rule compliance for ePHI handled in that role.

  • ISMS

    Information Security Management System — the documented policies, processes, and controls an organization establishes to manage information security risk under ISO/IEC 27001.

  • Personal data

    Under GDPR, any information relating to an identified or identifiable natural person (data subject) — including direct identifiers (name, email) and indirect identifiers (device IDs, online identifiers, location data combined with other information). Properly anonymized data falls outside the personal-data regime; pseudonymized data typically remains personal data.

  • Protected Health Information (PHI)

    Individually identifiable health information held or transmitted by a HIPAA covered entity or business associate in any form — electronic PHI (ePHI) is PHI in electronic form. PHI triggers HIPAA Privacy, Security, and Breach Notification Rule duties that SOC 2 attestation does not replace.

  • SOC 2 Type I vs Type II

    Type I reports on the design of controls at a point in time. Type II reports on the operating effectiveness of those controls over a defined period (commonly 3–12 months).

  • Statement of Applicability (SoA)

    An ISO/IEC 27001 document listing Annex A controls, whether each is applicable, and justification for inclusions and exclusions based on the organization's risk assessment.

  • Trust Services Criteria

    The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.