Compliance glossary
Terms for buying software and services
Working definitions with questions to use in a buying conversation. Follow each term to a practical guide, then compare relevant tools or providers.
Editorial update October 2, 2026
Browse all 75 terms
A
Accreditation
Formal recognition by an accreditation body that a conformity assessment body is competent for specified activities. It is different from the certificate issued to a customer. Check the issuing body’s accreditation scope for the standard and service you are purchasing.
How to plan an ISO 27001 certification engagement · ISO certification and accreditation guidance
Application programming interface (API)
A defined interface through which software requests data or actions from another system. For an evaluation, test authentication, permission scope, supported operations, limits, and error responses. Ask whether API access and the required endpoints are included in the quoted plan.
Attack surface
The parts of a system through which an attacker could interact with it, including exposed interfaces and entry points. Review changes when services, integrations, or access paths are added. A test scope should identify relevant surfaces rather than only count domain names.
How to scope a penetration test · OWASP attack surface analysis
Audit readiness
The preparation work that makes an agreed examination or assessment practical: a defined scope, working controls, assigned owners, and evidence that can be reviewed. A readiness assessment does not issue the independent report or certificate.
Audit trail
A record of events that helps reconstruct what happened, when, and through whose action. Check which events are captured, how identities and timestamps are recorded, and who can alter or delete the history. An activity feed may provide only part of this information.
How to evaluate compliance software · NIST glossary: audit trail
B
Bridge letter
A statement from service organization management about changes after a SOC report’s covered period, also called a gap letter. Review its dates and assertions alongside the report. It does not extend the auditor’s examination or replace a new SOC report.
How to choose a SOC 2 auditor · Linford & Company: bridge letters
C
Certification scope
The stated boundary covered by a certificate, such as the named organization, services, activities, and locations. Compare it with the service a customer needs assurance about and verify the current certificate rather than relying on a logo.
Common Vulnerability Scoring System (CVSS)
A standardized method for describing vulnerability severity through defined metrics. Record the version, vector, and assumptions behind a score. Combine severity with exposure, business impact, and existing safeguards when prioritizing work; the number alone is not your organization’s risk decision.
How to review and use a penetration-test report · FIRST: Common Vulnerability Scoring System
Compensating control
An alternative safeguard used to address a risk when the intended control cannot be implemented as specified. Document the reason, coverage, limitations, and approval. Whether an alternative satisfies a particular requirement must be evaluated against that requirement.
How to plan compliance evidence collection · NIST glossary: compensating controls
Complementary user entity controls (CUECs)
Controls that a SOC report assumes customers operate for the relevant control objectives or criteria to be met. Identify the ones applicable to your use of the service and assign owners. A vendor’s report does not demonstrate that your team operates these controls.
How to assess a vendor's security · Linford & Company: customer controls in SOC reports
Continuous monitoring
Ongoing checks and review of selected conditions. Ask which systems and conditions a product checks, the refresh interval, and who resolves failures. The label does not mean all risks are covered or that an independent assessment has occurred.
Control
A measure or process used to address a risk or requirement. In a software demo, ask who performs it, how often, what record it creates, and how an exception is handled. A policy document alone does not show that the process ran.
Control mapping
Associating a control with requirements in one or more frameworks. Mapping helps organize work; it does not establish that every mapped requirement is met. Review differences in scope, expected evidence, and assessment method.
Control owner
The person accountable for a control operating as intended, including its evidence and exception handling. The owner may delegate individual tasks. In a demo, check reassignment, reminders, approvals, and what happens when the owner leaves.
Corrective action
Work to address the cause of an identified nonconformity and prevent recurrence. Keep the finding, cause analysis, assigned action, evidence, and effectiveness review connected. Ask the reviewer what response is needed before treating the issue as closed.
How to plan an ISO 27001 certification engagement · BSI corrective action planning
D
Data export
The ability to extract information from a system into a usable external format. Test a real export for attachments, relationships, history, and permissions as well as basic fields. Agree access, costs, and timing before depending on it for an audit or migration.
Data inventory
A maintained record of what data an organization handles, where it resides, how it flows, and who is responsible. Test how a privacy tool reconciles discovered systems with reviewed records and tracks changes, purposes, recipients, and retention information.
How to evaluate privacy management software · NIST Privacy Framework
Data minimization
Limiting personal information to what is needed for a defined purpose. Review fields, collection, access, and copies against the purpose instead of collecting everything available. A privacy tool can support the review, but the team still needs to decide what is necessary.
How to evaluate privacy management software · UK government: data protection and individual rights
Data retention
How long information is kept for a stated purpose and how it is removed or anonymized afterward. Record the rationale, relevant obligations, and exceptions. Test whether schedules reach connected systems and backups rather than assuming a policy automatically causes deletion.
How to evaluate privacy management software · UK government: data protection and individual rights
Data subject request
A request by an individual to exercise a right concerning their personal information, such as access or correction. Available rights, exceptions, and deadlines depend on the applicable law. Test identity checks, routing, search, review, and response tracking using an appropriate sample workflow.
How to evaluate privacy management software · UK government: data protection and individual rights
E
Engagement scope
The agreed boundary of the work: legal entity, services, systems, locations, criteria, and deliverables. Ask the firm to record included and excluded areas and explain how changes affect the proposal.
Evidence
Records used to evaluate a control or substantiate an answer. For buying purposes, track the system of origin, owner, date or period, and review history. A connected data feed still needs an explanation of what it demonstrates.
Evidence freshness
How current a record is for the question being reviewed. Its collection date, covered period, and subsequent changes all matter. Agree review intervals by evidence type; a recently downloaded copy can still describe an old period or configuration.
Evidence gap
A missing, incomplete, or unsuitable record for a particular request. Record what is missing, who investigates, and when it will be reviewed. A missing record and a failed control are different questions; ask the reviewer how each affects the assessment.
Evidence provenance
The origin and history of a record: source system, collector, collection date, covered period, changes, and reviews. Preserve this context so a reviewer can understand what an item demonstrates and whether it applies to the request.
Evidence retention
The rules for how long supporting records are kept and how they are disposed of. Consider assessment needs, contracts, applicable obligations, and sensitive contents. Check retention settings, access, backups, and deletion behavior before importing evidence into a tool.
Exception management
A workflow for recording, reviewing, and resolving departures from an expected rule or control. Capture scope, reason, risk, approval, any alternative safeguard, and expiry. Keep an approved temporary exception distinguishable from an unexplained failure.
F
False positive
A reported condition that investigation shows is not actually present in the relevant context. Record the reasoning and evidence for dismissing it. A genuine weakness with low business impact is a different decision and should not be relabeled as a false positive.
How to review and use a penetration-test report · NIST glossary: false positive
G
GRC
Governance, risk, and compliance. Software sold under this label can cover quite different jobs, from risk registers to audit requests. Specify the workflows and modules you need instead of relying on the category name.
I
Inherent risk
An assessment of risk before the specific management actions being evaluated are taken into account. State the baseline and assumptions: teams may use different scoring conventions. Compare inherent and residual scores only when they use compatible scope and methods.
Integration
A connection that lets systems exchange information or trigger work. Inspect the actual objects, permissions, synchronization frequency, error handling, and deletion behavior. A product listing an integration does not establish that it supports the workflow your team needs.
Internal audit
An organized assessment performed for the organization to evaluate processes against defined criteria. It can be performed by qualified internal staff or an external resource. For an ISMS, agree scope, objectivity, reporting, and follow-up before scheduling the work.
How to plan an ISO 27001 certification engagement · Schellman ISO 27001 guide
ISMS
An information security management system: the organizational system for managing information security risks and improving how they are handled. ISO/IEC 27001 sets requirements for an ISMS; software can support the work but does not replace management responsibility.
How to evaluate compliance software · ISO/IEC 27001 overview
L
Least privilege
Giving a person or system only the access needed for its authorized work. Apply this to evidence collectors, integrations, and external reviewers as well as employees. Check permission scope, review frequency, and how unnecessary access is removed.
How to evaluate compliance software · NIST glossary: least privilege
M
Management review
A leadership review of how a management system is performing and what decisions or improvements are needed. Preserve the inputs, decisions, assigned actions, and follow-up. A calendar invitation alone does not demonstrate that the review took place.
How to plan an ISO 27001 certification engagement · Schellman ISO 27001 guide
Multi-factor authentication (MFA)
Authentication using more than one distinct type of factor, such as something known and something possessed. Two passwords are not two different factor types. Check enforcement, recovery, administrator access, and whether stronger methods are available for sensitive workflows.
How to evaluate compliance software · NIST glossary: multi factor authentication
N
Nonconformity
A finding that a specified requirement has not been fulfilled. Identify the requirement and supporting evidence before deciding the response. Ask the reviewer how the finding is classified, what deadlines apply, and how corrective action will be evaluated.
How to plan an ISO 27001 certification engagement · BSI corrective action planning
P
Penetration testing
Security testing that attempts to identify and validate ways to compromise a system within an agreed scope. The report describes work performed against particular assets and conditions; it is not proof that all possible weaknesses were found.
How to scope a penetration test · NIST SP 800-115: testing and assessment
Penetration testing as a service (PTaaS)
A delivery model combining testing services with a platform or recurring engagement. Packages differ. Compare manual testing, assets, staffing, scheduling, report access, retesting, and contract terms rather than assuming the label promises a particular level of coverage.
Personal data
Information relating to an identified or identifiable person. Identification can involve combinations of information rather than a name alone. Legal definitions and obligations vary by jurisdiction; review the actual data and context before classifying a workflow or choosing privacy software.
How to evaluate privacy management software · UK government: data protection and individual rights
Policy
An approved statement of organizational direction and expectations. Check its owner, scope, approval date, and review process. When answering a questionnaire, distinguish what the policy requires from evidence that people and systems follow it.
How to plan compliance evidence collection · NIST glossary: policy
Privacy impact assessment (PIA)
A structured review of how an activity handles personal information and what privacy risks and safeguards need consideration. Keep decisions and follow-up connected to the project. A general PIA workflow may need additional requirements to meet a particular law’s assessment obligation.
How to evaluate privacy management software · NIST glossary: privacy impact assessment
Procedure
Instructions for carrying out a particular process, including steps, roles, and handling of exceptions. A useful procedure lets another person perform the work consistently. Ask what records it produces and how changes are approved.
R
Recertification
An assessment to renew certification for a further certification cycle. Include it in the engagement plan alongside surveillance activities. Confirm the issuing body’s scope, timing, required preparation, fees, and handling of unresolved findings before the current certificate expires.
How to plan an ISO 27001 certification engagement · Schellman certification and recertification process
Remediation
Work to address an identified weakness or problem. Define the intended outcome, owner, due date, and verification method. A ticket marked complete is useful workflow information, but closure should also reflect evidence that the agreed change resolved the finding.
How to review and use a penetration-test report · Cobalt remediation and retesting documentation
Reporting period
The date or span of time addressed by a report. It is separate from fieldwork dates and the date the report is delivered. Confirm that the proposed period meets the customer request and that records exist for it.
Residual risk
The risk remaining after controls or other treatment measures are considered. Record which measures are actually operating and what evidence supports the assessment. A planned fix should not silently become an assumed reduction in the current risk score.
Retesting
Follow-up testing of specified findings after a change. Agree the assets, environment, access, deadline, and result format with the provider. A retest result applies to the work performed; it does not automatically cover new features or every asset.
Risk acceptance
An accountable decision to retain an identified risk under an organization's decision process. Record the approver, rationale, conditions, and review date. This decision is separate from fixing a technical issue or having a tester verify the change.
Risk appetite
The amount and kinds of risk an organization is willing to pursue or retain in working toward its objectives. Ask how leadership turns this direction into decision criteria and escalation rules; a broad statement alone does not approve a particular exception.
Risk assessment
A structured review of what could go wrong, how likely it is, and the consequences for a defined activity or system. Record the scope, assumptions, scoring method, and existing controls so another reviewer can understand the decision.
How to choose a virtual CISO · NIST glossary: risk assessment
Risk owner
The person accountable for managing a particular risk and ensuring that decisions and follow-up happen. This person may coordinate several action owners. Agree who can approve treatment or acceptance and who receives an escalation when work is overdue.
Risk register
A maintained record of identified risks, their owners, assessments, decisions, and follow-up actions. Ask whether the tool preserves changes over time and makes overdue treatment work visible rather than only displaying a current score.
Risk treatment
The selected response to a risk, such as reducing it, avoiding the activity, sharing it, or accepting it under an approval process. Connect the decision to owners, actions, deadlines, and a review of the risk that remains.
How to choose a virtual CISO · NIST glossary: risk treatment
Role-based access control (RBAC)
An access model in which permissions are assigned to roles and people receive permissions through their role assignments. Test the roles your team needs, including reviewer and auditor access, and check who can change assignments or grant exceptional access.
How to evaluate compliance software · NIST glossary: role based access control
Rules of engagement
The agreed permissions and operating boundaries for a security test. Record authorized assets, allowed techniques, timing, contacts, stop conditions, and handling of sensitive data before work starts.
How to scope a penetration test · NIST SP 800-115: testing and assessment
S
Security questionnaire
A set of questions a customer uses to understand a supplier's security practices. Formats vary. CSA's CAIQ is one cloud-security example. Responses describe practices and should be supported by current, approved information.
Build a security questionnaire workflow · CSA security questionnaire (CAIQ)
Security rating
A provider’s assessment of selected security signals, often summarized as a score. Review the underlying observations, asset attribution, dates, and correction process. A rating is one review input and does not provide the same coverage as an examination of internal controls.
How to assess a vendor's security · SecurityScorecard data collection documentation
Single sign-on (SSO)
A way for a user to access multiple services through a shared sign-in arrangement. During evaluation, test the identity provider, account linking, access removal, and fallback accounts. SSO support alone does not establish which authentication protections are enforced.
How to evaluate compliance software · NIST glossary: single sign on
SOC 2
An examination and report on a service organization’s controls relevant to selected Trust Services Criteria. Check the issuing CPA firm, system description, criteria, report type, period, and results. The label alone does not tell you which services or controls were examined.
SOC Type 1 report
A SOC report addressing the suitability of control design at a specified date. Confirm the systems and criteria covered and whether a customer accepts this report type. It does not cover operating effectiveness over a period.
SOC Type 2 report
A SOC report addressing control design and operating effectiveness over a specified period. Agree that period with the examination firm and plan records showing how controls operated throughout it.
Statement of Applicability (SoA)
An ISMS document recording necessary controls, the rationale for including them, their implementation status, and the justification for excluding Annex A controls. Review it against the actual certification scope and risk treatment work rather than treating it as a generic checklist.
How to plan an ISO 27001 certification engagement · Schellman ISO 27001 guide
Subprocessor
In a controller–processor privacy arrangement, another processor engaged by a processor to carry out processing for the controller. Review the services, data, locations, and contract terms involved. Applicable authorization and notification requirements depend on the governing law and agreement.
How to assess a vendor's security · ICO: processor responsibilities under UK GDPR
Subservice organization
Another organization whose services and controls support the service organization’s delivery of the system addressed in a SOC report. Check whether its controls are included in the examination or carved out, and what additional evidence and responsibilities need review.
How to assess a vendor's security · Schellman: subservice organizations in SOC reports
Surveillance audit
A follow-up audit within a certification program to review continued conformity. Confirm the schedule, coverage, preparation, and fees with the issuing body. Surveillance and recertification are different activities to include in your planning.
How to plan an ISO 27001 certification engagement · SGS ISO/IEC 27001 certification process
System of record
The designated authoritative place for a particular type of information in your workflow. Decide which system owns the current value, how conflicts are resolved, and how copies are updated. Connecting two tools does not by itself establish which record is authoritative.
T
Threat
A circumstance or event with the potential to cause harm. It is distinct from the weakness that may enable that harm. When reviewing a finding, connect plausible threats to affected business activities, existing safeguards, and the consequences your team is trying to prevent.
How to review and use a penetration-test report · NIST glossary: threat
Threat modeling
A structured analysis of how a system could be harmed and what design or operational changes would reduce that risk. Review architecture, data flows, trust boundaries, and assumptions. Use the results to inform controls and testing as the system changes.
Trust center
A place to share approved security information with customers or prospects. Some materials may be public and others access-controlled. Check document approval, access rules, expiry, and who owns updates before treating it as an answer source.
Trust Services Criteria
AICPA criteria used to evaluate controls related to security, availability, processing integrity, confidentiality, and privacy. Confirm the categories selected for a SOC 2 engagement and why they fit the service commitments; do not assume every report includes all five.
V
Vendor due diligence
The investigation used to understand a supplier before making or revisiting a business decision. Scope it to the service, access, dependencies, and potential impact. Combine relevant evidence with documented findings, decision ownership, and follow-up rather than using a questionnaire score alone.
How to assess a vendor's security · NIST SP 1326: ICT supplier due diligence
Vendor risk management
The process your team uses to assess and manage risks from suppliers. A practical workflow assigns ownership, records a decision, tracks follow-up work, and revisits important changes. Questionnaire completion is one input to that decision.
Vulnerability
A weakness that could be exploited or triggered to harm a system or its information. A finding needs context: affected assets, conditions, exposure, and supporting evidence. Confirm applicability before deciding the remediation priority and closure criteria.
How to review and use a penetration-test report · NIST glossary: vulnerability
Vulnerability scanning
Automated checks for potential weaknesses in selected systems or applications. Coverage depends on configuration, credentials, signatures, and reachable assets. Review untested areas and validate findings; a scan result does not establish the coverage of a manual penetration test.
How to scope a penetration test · NIST SP 800-115: testing and assessment