A

Access Control
The set of technical and administrative measures that determine who can view or use a system, application, or piece of data, and what they can do with it.
AML
Anti-Money Laundering: the laws, regulations, and internal controls aimed at preventing criminal proceeds from being disguised as legitimate funds, primarily enforced in the financial sector.
Audit Committee
A board-level committee, typically composed of independent directors, responsible for overseeing financial reporting, internal controls, and the internal and external audit functions.
Audit Trail
A chronological record of who did what, when, and to what system or data, used to reconstruct events and demonstrate accountability during an audit or investigation.

B

Business Continuity Plan (BCP)
A documented plan for keeping critical business functions running, or restoring them quickly, during and after a disruption such as an outage, natural disaster, or cyberattack.
Business Impact Analysis (BIA)
The exercise of identifying an organization’s critical business functions and estimating the operational and financial impact of disrupting each one, used to prioritize business continuity and disaster recovery planning.

C

CCPA
The California Consumer Privacy Act, a state law giving California residents rights over the personal information businesses collect about them, including the right to know, delete, and opt out of its sale.
Change Management
The formal process for proposing, reviewing, approving, and documenting changes to systems or processes, so changes do not introduce unmanaged risk.
CIA Triad
The three core properties information security aims to protect: confidentiality (keeping data from unauthorized parties), integrity (keeping it accurate and unaltered), and availability (keeping it accessible when needed).
CISO
Chief Information Security Officer: the executive responsible for an organization’s information security strategy and program.
Compliance
The state of meeting the requirements set by laws, regulations, industry standards, or an organization’s own policies.
Control
A safeguard or countermeasure, whether a policy, process, or technical mechanism, put in place to manage a specific risk.
Control Owner
The individual accountable for a specific control’s design, operation, and ongoing effectiveness.
Corrective Action
The steps taken to fix the root cause of an identified control failure or compliance gap, distinct from simply remediating the immediate symptom.
COSO Framework
A widely used internal-control framework from the Committee of Sponsoring Organizations of the Treadway Commission, built around five components: control environment, risk assessment, control activities, information and communication, and monitoring.
CPRA
The California Privacy Rights Act, which expanded and amended the CCPA effective 2023, adding a dedicated enforcement agency and new rights around sensitive personal information and automated decision-making.

D

Data Governance
The overall set of policies, roles, and processes that determine how an organization manages the availability, quality, and security of its data throughout its lifecycle.
Data Minimization
The principle of collecting and retaining only the personal data actually needed for a stated purpose, and no more.
Data Subject
The individual a piece of personal data is about, a term used throughout privacy law including GDPR.
Disaster Recovery Plan (DRP)
The technical counterpart to a business continuity plan, focused specifically on restoring IT systems and data after a disruptive event.
DORA
The EU’s Digital Operational Resilience Act, effective January 2025, which sets binding ICT risk management, incident reporting, and resilience testing requirements for banks, insurers, and other financial entities, along with oversight of their critical technology providers.
DPIA
Data Protection Impact Assessment: a required assessment, under GDPR and a growing number of U.S. state privacy laws, of the privacy risks a planned data processing activity poses before it begins.
DPO
Data Protection Officer: an independent role required under GDPR and some other privacy laws, responsible for advising on and monitoring an organization’s data protection compliance.
Due Diligence
The investigation an organization performs before entering a relationship, such as a vendor contract or acquisition, to understand and evaluate the risk involved.

E

Enterprise Risk Management (ERM)
A structured, organization-wide approach to identifying, assessing, and managing risk across all business units, rather than in isolated silos.
ESG
Environmental, Social, and Governance: a framework for evaluating an organization’s practices and risks beyond pure financial performance, increasingly tied to its own disclosure and reporting obligations.

F

Framework
A structured set of guidelines, best practices, and controls (such as NIST CSF or ISO 27001) that an organization adopts as the backbone of its risk or security program.

G

GDPR
The EU’s General Data Protection Regulation, a comprehensive privacy law governing how organizations collect, use, and protect the personal data of people in the EU, regardless of where the organization itself is based.
Governance
The structures, policies, and processes by which an organization is directed and controlled, including how decisions are made and who is accountable for them.
GRC
Governance, Risk, and Compliance: the umbrella term for the integrated set of practices that align an organization’s objectives, risk management, and regulatory obligations.

H

HIPAA
The Health Insurance Portability and Accountability Act, the U.S. law that sets national standards for protecting health information.

I

Incident Response Plan
A documented, predefined set of steps for detecting, containing, investigating, and recovering from a security incident.
Inherent Risk
The level of risk that exists before any controls are applied, used as the baseline against which the effect of controls is measured.
Insider Threat
The risk that a current or former employee, contractor, or partner with legitimate access will misuse it, whether maliciously or through negligence, to cause harm.
Internal Audit
An independent function within an organization that evaluates the effectiveness of governance, risk management, and controls, and reports its findings to management and the audit committee rather than to the areas it reviews.
ISO 31000
The international standard providing principles and generic guidelines on risk management, applicable across industries rather than specific to information security.
ISO/IEC 27001
The international standard for information security management systems, most recently updated in 2022, against which organizations can be independently certified.
IT General Controls (ITGCs)
Controls over the IT environment as a whole, such as access management, change management, and backups, that support the reliable operation of the specific application-level controls built on top of them.

K

KPI
Key Performance Indicator: a measure used to track how well a process or program is performing against its objectives.
KRI
Key Risk Indicator: a measure used to signal that a particular risk is increasing before it results in an actual loss or incident.
KYC
Know Your Customer: the due diligence process financial institutions and some other regulated businesses use to verify a customer’s identity and assess their risk before establishing a relationship.

M

Materiality
A judgment of whether an error, omission, or risk is significant enough to influence the decisions of someone relying on the information, such as an investor or regulator.
MFA
Multi-Factor Authentication: a login method requiring two or more independent forms of verification, such as a password plus a one-time code, so a single stolen credential is not enough to gain access.

N

NIST CSF
The NIST Cybersecurity Framework, a voluntary framework widely adopted across industries. Version 2.0, released in 2024, added a sixth core function, Govern, alongside Identify, Protect, Detect, Respond, and Recover.

P

PCI DSS
The Payment Card Industry Data Security Standard, a set of security requirements that any organization handling credit card data must meet, enforced through the card networks rather than a government regulator.
PHI
Protected Health Information: individually identifiable health data covered by HIPAA, including medical records, treatment history, and billing information tied to a specific patient.
Phishing
A social engineering attack that uses fraudulent emails, messages, or websites to trick someone into revealing credentials, payment details, or other sensitive information.
PII
Personally Identifiable Information: any data that can identify a specific individual, either on its own, such as a name or Social Security number, or combined with other data, such as a birthdate plus a zip code.
Policy vs. Procedure
A policy states what an organization requires and why; a procedure describes the specific, repeatable steps for carrying that policy out in practice.

R

Ransomware
Malicious software that encrypts an organization’s systems or data and demands payment, typically in cryptocurrency, in exchange for restoring access or not leaking what was stolen.
RCSA
Risk and Control Self-Assessment: a structured exercise in which a business unit identifies its own risks and evaluates how well its controls address them.
Residual Risk
The risk that remains after controls have been applied, which an organization then decides to accept, transfer, or further reduce.
Risk Appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives, typically set by the board or senior leadership.
Risk Assessment
The process of identifying risks, and evaluating their likelihood and potential impact, in order to prioritize how they should be managed.
Risk Register
A structured, living record of an organization’s identified risks, including their assessed severity, owner, and current treatment status.
Risk Tolerance
The specific, measurable boundaries within which an organization is willing to operate for a given risk, a narrower and more concrete expression of its broader risk appetite.

S

Segregation of Duties
The practice of dividing critical tasks among more than one person, so that no single individual can both execute and conceal a fraudulent or erroneous action.
SOC 2
A widely used attestation report, based on the AICPA’s Trust Services Criteria, that evaluates a service organization’s controls related to security, availability, processing integrity, confidentiality, and privacy.
SOX
The Sarbanes-Oxley Act of 2002, a U.S. law enacted after major accounting scandals, which requires public companies to maintain and attest to the effectiveness of their internal financial controls.

T

Third-Party Risk Management
The discipline of identifying, assessing, and monitoring the risk an organization takes on through its vendors, suppliers, and other external partners.
Threat
Anything with the potential to cause harm to an asset, whether a malicious actor, a natural event, or a system failure.
Three Lines of Defense
A model for organizing risk and control responsibilities: operational management that owns and manages risk day to day, risk and compliance functions that oversee and challenge it, and internal audit that independently assures the whole system works.
Tone at the Top
The ethical and risk-management example set by senior leadership and the board, which research consistently links to how seriously the rest of the organization takes compliance and controls.

V

Vulnerability
A weakness in a system, process, or control that a threat could exploit to cause harm.

W

Walkthrough
An auditor’s step-by-step review of how a process or control actually operates in practice, typically by observing it or tracing a transaction through it, used to confirm that documentation matches reality.

Z

Zero Trust
A security model built on the assumption that no user or device should be trusted by default, even inside the network perimeter, so every access request is verified individually regardless of its source.