Glossary
Precise definitions for compliance terms engineers encounter in audits and frameworks.
- Access control
Policies and technical mechanisms that restrict who can access information assets, systems, and data — typically including identity provisioning, authentication, authorization, periodic access reviews, and deprovisioning.
- Business associate
Under HIPAA, a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (or another business associate) for covered functions — typically requiring a Business Associate Agreement (BAA) and Security Rule compliance for ePHI handled in that role.
- ISMS
Information Security Management System — the documented policies, processes, and controls an organization establishes to manage information security risk under ISO/IEC 27001.
- Personal data
Under GDPR, any information relating to an identified or identifiable natural person (data subject) — including direct identifiers (name, email) and indirect identifiers (device IDs, online identifiers, location data combined with other information). Properly anonymized data falls outside the personal-data regime; pseudonymized data typically remains personal data.
- Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a HIPAA covered entity or business associate in any form — electronic PHI (ePHI) is PHI in electronic form. PHI triggers HIPAA Privacy, Security, and Breach Notification Rule duties that SOC 2 attestation does not replace.
- SOC 2 Type I vs Type II
Type I reports on the design of controls at a point in time. Type II reports on the operating effectiveness of those controls over a defined period (commonly 3–12 months).
- Statement of Applicability (SoA)
An ISO/IEC 27001 document listing Annex A controls, whether each is applicable, and justification for inclusions and exclusions based on the organization's risk assessment.
- Trust Services Criteria
The AICPA criteria (security, availability, processing integrity, confidentiality, privacy) used as the basis for SOC 2 examinations under TSP Section 100.