Glossary
Compliance terms, defined in one paragraph each
The words that come up in a first SOC 2, ISO 27001 or ISO 42001 program, defined the way a compliance lead would explain them on a call. Written and maintained by the Certifyi team.
Attestation report
An independent auditor’s written opinion on whether an organisation’s controls are designed and operating as described. SOC 2 produces an attestation report; it is not a certificate.
Audit-ready
The point at which scoped controls, policies, a risk register and evidence workflows are in place and an auditor is engaged. In Certifyi engagements this is reached in 8 to 12 weeks.
Business Associate Agreement (BAA)
A HIPAA-required contract between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
CAPA
Corrective and preventive action. The plan, owner and due date attached to an audit finding, tracked until the auditor confirms closure.
Certification body
An organisation accredited by a national body (such as UKAS or ANAB) to audit and certify management systems against ISO standards. Only a certification body can issue an ISO 27001 or ISO 42001 certificate.
Continuous monitoring
Collecting control evidence automatically and continuously from connected systems, so control health is visible every day rather than reconstructed before an audit.
Control
A specific safeguard or activity that reduces a risk, such as requiring MFA on privileged accounts or reviewing access quarterly. Frameworks are lists of required or recommended controls.
Control mapping
Linking one control to every framework requirement it satisfies, so evidence collected once counts toward SOC 2, ISO 27001, ISO 42001, HIPAA and GDPR at the same time.
Data Processing Agreement (DPA)
A GDPR-required contract between a controller and a processor that sets out how personal data is handled, secured and returned or deleted.
Evidence
Any record that shows a control operated: a configuration export, a ticket, a signed policy, an access review. Auditors sample evidence across the audit period.
Evidence integrity
The property that a piece of evidence can be shown to be unchanged since it was collected. Certifyi hashes every file on arrival and keeps superseded versions readable.
Gap assessment
A comparison of current controls against a framework’s requirements, producing the list of work needed before an audit. The first deliverable of a Certifyi engagement.
GRC
Governance, risk and compliance: the discipline of deciding how an organisation is run (governance), what could go wrong (risk) and what rules it must meet (compliance), managed as one system.
ISMS
Information security management system. The scope, policies, risk process, controls and reviews that ISO 27001 certifies. The certificate covers the system, not the product.
ISO 27001
The international standard for an information security management system. Certifiable, valid for three years with annual surveillance audits, and the framework most often requested in the EU, UK and APAC.
ISO 42001
The international standard for an AI management system, published in 2023. Certifiable, and structured like ISO 27001 so the two can be run and audited together.
Monte Carlo risk analysis
A quantitative method that runs thousands of simulated scenarios to estimate a range of financial loss from a risk, turning a heat-map colour into a number a board can steer by.
Observation period
The window, usually three to twelve months, over which a SOC 2 Type II auditor samples evidence to confirm controls operated. It starts after the controls are in place.
Penetration test
An authorised simulated attack on systems to find exploitable weaknesses. Expected annually by most frameworks and always paid to a testing firm, not included in a compliance platform.
Policy acknowledgement
A recorded confirmation that a person has read and accepted a policy. Auditors sample acknowledgements to check policies are communicated, not just written.
Risk register
The list of identified risks with owner, likelihood, impact, treatment and review date, linked to the controls that treat each one. Auditors look for it first.
SOC 2 Type I
A point-in-time attestation that controls are suitably designed and in place on a given date. Usually the first report a company obtains.
SOC 2 Type II
An attestation that controls operated effectively over an observation period. The report most enterprise buyers ultimately require.
Statement of Applicability (SoA)
The ISO 27001 document listing every Annex A control, whether it applies, why, and how it is implemented. The auditor’s map of your ISMS.
Trust Center
A public web page where an organisation shares its certifications, reports, policies and control status so prospects can complete security review without an email thread.
Trust Service Criteria
The five categories a SOC 2 report can cover: Security (mandatory), Availability, Confidentiality, Processing Integrity and Privacy.
Vendor risk management
Assessing and monitoring third parties by the data and access they hold, with questionnaires, evidence and re-assessment on a schedule. Required by SOC 2, ISO 27001 and GDPR.
Access review
A periodic check, usually quarterly, that every user’s access to systems still matches their role, with removals recorded. One of the first pieces of evidence a SOC 2 or ISO 27001 auditor samples.
Annex A
The list of 93 reference controls in ISO 27001:2022, grouped into organisational, people, physical and technological themes. You select from it and justify exclusions in the Statement of Applicability.
AI system inventory
A register of every AI model, agent and third-party AI service an organisation builds or uses, with purpose, data, owner and risk tier. The first document ISO 42001 and the EU AI Act depend on.
AI impact assessment
An ISO 42001 requirement: for each AI system, who is affected, what could go wrong, how likely and how severe, and what is done about it. High-risk EU AI Act systems require a formal version.
C3PAO
CMMC Third-Party Assessment Organisation: a company accredited by the Cyber AB to perform CMMC Level 2 assessments for US defence contractors.
CMMC
Cybersecurity Maturity Model Certification, the US Department of Defense programme that verifies contractors protect Federal Contract Information and Controlled Unclassified Information. Three levels; Level 2 maps to NIST SP 800-171.
Compensating control
An alternative safeguard used when a required control cannot be implemented as written, documented with the reason and accepted by the risk owner.
Controlled Unclassified Information (CUI)
US government information that is not classified but must be protected under law or policy. Handling CUI triggers CMMC Level 2.
Cyber Essentials
The UK government-backed certification of five baseline technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Cyber Essentials Plus adds an independent technical audit.
Data Protection Impact Assessment (DPIA)
A GDPR-required assessment of processing that is likely to result in high risk to individuals, documenting the risks and the measures that reduce them.
DORA
The EU Digital Operational Resilience Act, in force from January 2025, which makes financial entities responsible for the ICT risk of their third-party providers and flows contract requirements down to SaaS vendors.
Essential Eight
The Australian Cyber Security Centre’s eight mitigation strategies (application control, patching, MFA, backups and others) with maturity levels 0 to 3. The Australian counterpart to Cyber Essentials.
EU AI Act
Regulation (EU) 2024/1689, which classifies AI systems by risk tier and imposes obligations on providers and deployers, phasing in from February 2025 to August 2027.
Exception (audit)
An instance where a control did not operate as described during the audit period. Exceptions are reported in a SOC 2 report; readers judge their severity.
Federal Contract Information (FCI)
Information provided by or generated for the US government under a contract, not intended for public release. Handling FCI triggers CMMC Level 1.
Gap
A requirement of a framework that the organisation does not yet meet. Gaps are listed in the gap assessment and tracked to closure before the audit.
HIPAA Security Rule
The part of HIPAA that sets administrative, physical and technical safeguards for electronic protected health information. Compliance is evidenced, not certified.
HITRUST CSF
A certifiable framework, common in US healthcare, that consolidates HIPAA, ISO 27001, NIST and other requirements. Assessed at e1, i1 and r2 levels.
Internal audit
A review of the management system by someone independent of the area audited, required by ISO 27001 and ISO 42001 before certification and at planned intervals after it.
Lead Implementer
A person certified to design and implement an ISO management system. Certifyi engagements for ISO 27001 and ISO 42001 are run by Lead Implementers.
Management review
A documented meeting where leadership reviews the performance of the management system: audit results, risks, incidents, objectives and resources. Required by ISO standards.
NIS2
The EU Network and Information Security Directive (2022), transposed into national law from late 2024, which imposes security and incident-reporting duties on essential and important entities and their suppliers.
NIST AI RMF
The US National Institute of Standards and Technology AI Risk Management Framework, a voluntary set of practices organised as Govern, Map, Measure and Manage.
NIST SP 800-171
The US standard of 110 security requirements for protecting Controlled Unclassified Information in non-federal systems. The control set behind CMMC Level 2.
Nonconformity
An ISO audit finding that a requirement is not met. Minor nonconformities need a corrective action plan; major ones must be closed before the certificate is issued.
PCI DSS
The Payment Card Industry Data Security Standard, twelve requirements for any organisation that stores, processes or transmits cardholder data. Version 4.0 is current.
Personnel security
Controls covering people: background checks where lawful, onboarding and offboarding, training, acceptable-use acknowledgement and access removal when someone leaves.
Plan of Action and Milestones (POA&M)
The CMMC and NIST document listing unmet requirements, the planned remediation, owner and date. Only a limited set of controls may sit on a POA&M at assessment.
Protected Health Information (PHI)
Individually identifiable health information handled by a HIPAA covered entity or business associate.
Responsible disclosure
Reporting a security vulnerability privately to the affected organisation and allowing time for a fix before any publication. The basis of most bug bounty programmes.
Sub-processor
A third party that processes personal data on behalf of a processor. GDPR requires processors to disclose sub-processors and to notify customers of changes.
System Security Plan (SSP)
The CMMC and NIST SP 800-171 document describing the system boundary and how each of the 110 requirements is implemented. The assessor’s starting point.
Surveillance audit
The annual audit between ISO certification and recertification, checking that the management system is maintained. Shorter than the initial Stage 2 audit.
Threat-led penetration testing (TLPT)
Intelligence-led, scenario-based testing of live systems required under DORA for critical financial entities, and sometimes requested from their key providers.
Type I / Type II
The two SOC 2 report types. Type I covers control design at a point in time; Type II covers operating effectiveness over an observation period.
Missing a term?
Email [email protected] and we will add it, or book a call and ask the person who will run your program.