Glossary
Compliance vocabulary carries specific, often narrow meanings that get flattened in casual use — "audit," for example, means something different in a SOC 2 Type II engagement than it does in a penetration test writeup. Each entry here defines a term the way it is actually used in framework text and by auditors, not the way it gets loosely used in marketing copy.
Terms are listed alphabetically below. If a term appears on a framework or control page in a way that assumes prior knowledge — CUEC, ISMS, Statement of Applicability, Trust Services Criteria — it is defined here, usually with a link back to the framework context where the distinction matters most.
This page is for quick lookup, not learning a framework from scratch. If you are new to a framework entirely, start at its overview page instead — it introduces the vocabulary in context rather than as an isolated list.
- Access control
Policies and technical mechanisms that restrict who can access information assets, systems, and data — typically including identity provisioning, authentication, authorization, periodic access reviews, and deprovisioning.
- Adequacy decision
A European Commission finding that a non-EEA country or arrangement provides essentially equivalent data protection for transfers.
- Annex A
ISO/IEC 27001:2022’s reference set of 93 information-security controls used in risk treatment.
- Anonymization
Processing that irreversibly prevents information from relating to an identified or identifiable person using reasonably likely means.
- Audit evidence
Information used to support a conclusion that a control is designed or operating as described.
- Break-glass access
Emergency privileged access used when normal identity or approval paths are unavailable.
- Business associate
Under HIPAA, a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (or another business associate) for covered functions — typically requiring a Business Associate Agreement (BAA) and Security Rule compliance for ePHI handled in that role.
- Business Associate Agreement (BAA)
A HIPAA-required contract defining permitted PHI uses and safeguard, reporting, and subcontractor duties between regulated parties.
- Change management
Controlled authorization, testing, deployment, and traceability of changes to systems and software.
- Common Criteria
SOC 2 Trust Services Criteria common to Security and relevant across governance, risk, access, operations, change, and vendors.
- Controller
The party that determines the purposes and means of processing personal data under GDPR.
- Covered entity
A HIPAA health plan, health care clearinghouse, or qualifying health care provider that conducts covered electronic transactions.
- Data processing agreement (DPA)
A contract allocating data-protection duties between a controller and processor, including Article 28 terms where GDPR applies.
- Data protection impact assessment (DPIA)
A documented GDPR assessment of high-risk processing, its necessity, risks to people, and measures that address those risks.
- Data protection officer (DPO)
An independent GDPR role required in specified circumstances to advise, monitor compliance, and serve as a contact point.
- Electronic protected health information (ePHI)
Individually identifiable health information covered by HIPAA that is created, received, maintained, or transmitted electronically.
- Encryption at rest
Cryptographic protection for stored data on disks, databases, backups, or object storage.
- Encryption in transit
Cryptographic protection for data moving across networks or service connections.
- HIPAA risk analysis
An accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- ISMS
Information Security Management System — the documented policies, processes, and controls an organization establishes to manage information security risk under ISO/IEC 27001.
- Joiner-mover-leaver (JML)
The identity lifecycle for provisioning, changing, and revoking workforce access.
- Least privilege
The principle of granting only the access needed for a defined role, task, and time.
- Logging and monitoring
Collection, protection, analysis, and alerting on events needed to detect misuse, failure, or security incidents.
- Multi-factor authentication (MFA)
Authentication requiring evidence from at least two different factor categories, such as knowledge and possession.
- Observation window
The period over which a SOC 2 Type II examination evaluates control operation.
- Personal data
Under GDPR, any information relating to an identified or identifiable natural person (data subject) — including direct identifiers (name, email) and indirect identifiers (device IDs, online identifiers, location data combined with other information). Properly anonymized data falls outside the personal-data regime; pseudonymized data typically remains personal data.
- Personal data breach
A GDPR security breach causing accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
- Processor
A party that processes personal data on documented instructions from a controller.
- Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a HIPAA covered entity or business associate in any form — electronic PHI (ePHI) is PHI in electronic form. PHI triggers HIPAA Privacy, Security, and Breach Notification Rule duties that SOC 2 attestation does not replace.
- Pseudonymization
Processing personal data so it cannot be attributed to a person without separately kept additional information.
- Recovery point objective (RPO)
The target maximum amount of data loss measured backward in time after disruption.
- Recovery time objective (RTO)
The target maximum time to restore a service after disruption.
- Security incident
An event that actually or potentially compromises security objectives or violates security policy and requires evaluation.
- SOC 2 Type I vs Type II
Type I reports on the design of controls at a point in time. Type II reports on the operating effectiveness of those controls over a defined period (commonly 3–12 months).
- Standard Contractual Clauses (SCCs)
European Commission contract clauses used as a transfer safeguard for certain exports of personal data outside the EEA.
- Statement of Applicability (SoA)
An ISO/IEC 27001 document listing Annex A controls, whether each is applicable, and justification for inclusions and exclusions based on the organization's risk assessment.
- Sub-processor
A processor engaged by another processor to handle personal data for the controller’s service.
- Trust Services Criteria
The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.
- Vulnerability management
The recurring process for identifying, prioritizing, remediating, and verifying weaknesses in systems and software.