Security and compliance glossary
Who can issue a formal outcome
Several terms below describe formal outcomes, such as attestation reports, audit opinions, and certificates, that only authorized independent parties can issue. Each definition says who that is.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
A
- Accreditation body
An organization that evaluates certification bodies against international standards, such as ISO/IEC 17021-1 and ISO/IEC 27006-1 for ISO/IEC 27001 certification, and accredits those that meet them. Signatories to the Global ACI MRA (formerly the IAF MLA) commit to recognizing one another's accreditation programs as equivalent. Accreditation applies to the certification body, not to the organizations it certifies.
- Administrative, physical, and technical safeguards
The three families of standards in the HIPAA Security Rule. Administrative safeguards (45 CFR 164.308) cover management processes such as risk analysis, workforce security, training, incident procedures, contingency planning, and evaluation. Physical safeguards (164.310) cover facility access, workstations, and devices and media. Technical safeguards (164.312) cover access control, audit controls, integrity, authentication, and transmission security.
- Annex A (ISO/IEC 27001:2022)
The normative annex of ISO/IEC 27001:2022 that lists 93 information security controls from ISO/IEC 27002:2022, grouped as organizational, people, physical, and technological controls. Organizations determine the controls their risk treatment needs, compare them with Annex A to check that nothing necessary is missing, and record the result, including any exclusions and why, in the Statement of Applicability.
- Approved Scanning Vendor (ASV)
A company qualified by the PCI Security Standards Council to run the external vulnerability scans that PCI DSS requires for internet-facing systems in scope. The qualification belongs to the company and its scanning solution, which must pass the Council's testing, and the company must keep trained ASV employees on staff. Scans meant to meet that requirement must come from a company on the Council's current ASV list.
- Assessor independence
The principle that whoever issues a formal outcome must be free of conflicts that could bias it, above all having designed, built, or run the controls under review. Each program sets its own rules: CPA firms follow AICPA independence rules, QSA Companies follow PCI Security Standards Council requirements, and CMMC bars ecosystem members, such as C3PAOs, their assessors and CMMC professionals, who consulted to prepare an organization for any CMMC assessment within the previous three years from taking part in its Level 2 certification assessment. In practice, the firm that helps you prepare should not be the firm that assesses you.
- Attestation
A formal written conclusion from an independent party about whether a subject, such as a system description or a set of controls, meets defined criteria. In the United States, attestation engagements such as SOC 2 examinations are performed by licensed CPA firms under AICPA standards. The party attesting must be independent of the subject it reports on, so an organization's own staff cannot attest to it, and a CPA firm that designed, implemented, or maintains the controls it would examine impairs its independence.
- Attestation of Compliance (AOC)
The official PCI SSC form a merchant or service provider uses to attest to the results of a PCI DSS assessment, as documented in a Self-Assessment Questionnaire or a Report on Compliance. An officer of the organization signs it, and for an assessment by a QSA Company, the assessor signs for the assessment it performed. The acquirer or the payment brands say where it goes.
- Audit opinion
An auditor's formal conclusion at the end of an audit or examination. In a SOC 2 report, the opinion comes from an independent licensed CPA firm and addresses whether the system description is fairly presented and whether controls were suitably designed and, for a Type 2 report, operated effectively over the review period. Consultants, software platforms, and internal teams cannot issue one.
B
- Business associate
A person or organization, other than a member of the workforce, that creates, receives, maintains, or transmits protected health information on behalf of a HIPAA covered entity, or that provides certain services to one, such as legal, accounting, or consulting services, involving protected health information. The definition includes subcontractors that do the same for a business associate, and the Security Rule applies to business associates directly.
- Business associate agreement (BAA)
The written contract or other arrangement a covered entity must have before a business associate creates, receives, maintains, or transmits electronic protected health information for it; a business associate needs the same with its subcontractors. Under the Security Rule, the contract must require the business associate to comply with the rule, flow the requirements down to subcontractors, and report security incidents, including breaches of unsecured protected health information. Counsel should draft or review it.
C
- Cardholder data environment (CDE)
In PCI DSS, the system components, people, and processes that store, process, or transmit cardholder data or sensitive authentication data, plus system components that don't handle that data but have unrestricted connectivity to components that do. The CDE is the core of PCI DSS scope, and segmentation that isolates it from other networks can reduce what an assessment covers.
- Certification body
An organization that audits a management system, such as an information security management system, against a standard like ISO/IEC 27001 and issues a certificate when the system conforms. Look for a certification body that is accredited by a recognized accreditation body. ISO writes the standards but does not certify organizations, and consultants who help build the system cannot issue the certificate.
- Certified Third-Party Assessment Organization (C3PAO)
An organization authorized by the Cyber AB, the CMMC Accreditation Body, to conduct CMMC Level 2 certification assessments. The assessments are carried out by assessors certified by the CAICO (CCAs), whom the C3PAO employs or contracts. A C3PAO certifies organizations, not individuals, and it may not take part in the Level 2 certification assessment of an organization it advised on preparing for any CMMC assessment within the previous three years.
- CIS Controls
A prioritized set of cybersecurity safeguards published by the Center for Internet Security. Version 8.1 groups them into 18 Controls and uses Implementation Groups, IG1 through IG3, to suggest which safeguards to tackle first based on an organization's resources and risk. The Controls are voluntary guidance, not a regulation.
- Common criteria (CC1–CC9)
The Trust Services Criteria that apply to every category in a SOC 2 examination. CC1 through CC5 follow the COSO internal control components: control environment, information and communication, risk assessment, monitoring activities, and control activities. CC6 through CC9 add logical and physical access controls, system operations, change management, and risk mitigation. For the security category, the common criteria are the complete set.
- Compensating control
In PCI DSS, an alternative control an organization may use when a legitimate, documented technical or business constraint prevents it from meeting a requirement as written. It must meet the intent and rigor of the original requirement, must not simply be a control the standard already requires elsewhere, and must be validated again at each annual assessment. More broadly, the term describes any safeguard that reduces the same risk when the primary control isn't feasible.
- Complementary user entity controls (CUECs)
Controls that a service organization's management assumed, in designing its system, would be implemented by its customers (user entities), and that are necessary, together with the service organization's own controls, for its service commitments and system requirements to be met. A SOC 2 system description lists them, and a customer relying on the report should confirm that it actually operates each one.
- Control
A safeguard that reduces a specific risk. It can be a policy, a process, a technical setting, or a physical measure. Frameworks describe controls in their own terms, such as NIST security controls, ISO/IEC 27001 Annex A controls, or CIS Safeguards, but a working control always has an owner, a defined way of operating, and evidence that it runs as intended.
- Controlled Unclassified Information (CUI)
Information the federal government creates or possesses, or that others create or possess on its behalf, that a law, regulation, or government-wide policy requires to be safeguarded or limited in distribution, but that is not classified. The National Archives administers the CUI program for the executive branch. Defense contractors that handle CUI are generally expected to protect it using the security requirements in NIST SP 800-171.
- Covered entity
Under the HIPAA rules, one of three kinds of organization: a health plan, a health care clearinghouse, or a health care provider that transmits health information in electronic form in connection with a transaction the rules cover. Covered entities must meet the Security Rule's safeguards for electronic protected health information, and they must obtain written assurances from any business associate that handles it for them.
- Cybersecurity Maturity Model Certification (CMMC)
The Department of Defense program that checks whether defense contractors protect Federal Contract Information and Controlled Unclassified Information. Level 1 is an annual self-assessment. Level 2 is either a self-assessment or a certification assessment by an authorized C3PAO, depending on the contract, and Level 3 is assessed by the government. The program rule is 32 CFR Part 170. Program status changes; the CMMC readiness page shows the current dated update.
E
- Electronic protected health information (ePHI)
Protected health information that is transmitted by electronic media or maintained in electronic media. Protected health information is individually identifiable health information, with some exclusions, such as certain education and employment records. The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity, and availability of all the ePHI they create, receive, maintain, or transmit.
- Evidence
Records that show a control exists and works as described, such as configuration exports, access reviews, tickets, logs, signed policies, and training records. Auditors and assessors judge evidence against the scope and time period under review. Evidence has to come from the organization's real systems and activities; an advisor can help design how it is collected but cannot produce it on the organization's behalf.
F
- Federal Contract Information (FCI)
Information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. It excludes information the government makes public and simple transactional information, such as what's needed to process payments. FAR 52.204-21 sets 15 basic safeguarding requirements for contractor systems that handle it, and CMMC Level 1 consists of those requirements.
G
- Gap assessment
A comparison of current practices against a target framework or set of requirements that records what is in place, partly in place, or missing, usually with a prioritized plan to close the gaps. NIST CSF 2.0 frames this as comparing a Current Profile with a Target Profile. A gap assessment is diagnostic: it does not produce a certification, attestation, or audit opinion.
H
- Health Insurance Portability and Accountability Act (HIPAA)
The federal law enacted on August 21, 1996 as Public Law 104-191. HHS's HIPAA Privacy, Security, and Breach Notification Rules are in 45 CFR Parts 160 and 164: the Security Rule is Part 164, Subpart C, the Breach Notification Rule is Subpart D, and the Privacy Rule is Subpart E. The acronym is often misspelled “HIPPA.” There is no official HIPAA certification; the HHS Office for Civil Rights enforces these rules.
- HIPAA risk analysis
The Security Rule's required “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of electronic protected health information (45 CFR 164.308(a)(1)(ii)(A)). It pairs with risk management, which reduces the risks found to a reasonable and appropriate level. People often call it a HIPAA risk assessment or security risk assessment, but the rule's own term is risk analysis.
- HIPAA Security Rule
The federal rule that sets administrative, physical, and technical safeguards for electronic protected health information held by HIPAA covered entities and their business associates. It requires an accurate and thorough risk analysis and ongoing risk management, and the HHS Office for Civil Rights enforces it. There is no official HIPAA certification: HHS does not certify organizations, and a private “HIPAA certified” label does not change an organization's obligations.
I
- Incident response plan
A documented, approved plan for how an organization prepares for, detects, escalates, contains, recovers from, and communicates about security incidents. A useful plan names roles and decision rights, lists internal and external contacts, and covers legal, contractual, and regulatory notification steps. Tabletop exercises test whether the plan works in practice.
- Information security management system (ISMS)
The policies, processes, roles, risk assessments, and improvement cycle an organization uses to manage information security as an ongoing program rather than a one-time project. ISO/IEC 27001 specifies the requirements for an ISMS, and certification applies only to the ISMS scope the organization defines.
- ISO/IEC 27001
The international standard, published jointly by ISO and IEC, that specifies requirements for establishing, running, and improving an information security management system. As of 2026-09-26, the current edition is ISO/IEC 27001:2022, including Amendment 1:2024, and its Annex A lists 93 reference controls. Organizations are certified against it by certification bodies after an independent audit, and an accredited certificate comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1. ISO itself does not issue certificates.
N
- Network segmentation (PCI DSS)
Isolating the systems that store, process, or transmit cardholder data from those that don't. PCI DSS doesn't require segmentation, but it can reduce the scope of an assessment; without it, the entire network is in scope. When segmentation is used to isolate the cardholder data environment, penetration tests must confirm it at least once every 12 months and after changes, or every six months for service providers (Requirements 11.4.5 and 11.4.6).
- NIST Cybersecurity Framework (CSF)
Voluntary guidance from the National Institute of Standards and Technology that describes cybersecurity outcomes an organization can aim for. Version 2.0, released in February 2024, organizes those outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. NIST does not certify organizations against the CSF; it is a tool for assessing, prioritizing, and communicating about risk.
- NIST SP 800-171
The NIST publication Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. NIST published Revision 3 in May 2024 and withdrew Revision 2 on May 14, 2024. Revision 2's 110 security requirements are still the CMMC Level 2 baseline, because the CMMC rule incorporates Revision 2 by reference (32 CFR 170.14). DFARS 252.204-7012 applies NIST SP 800-171 to covered contractor information systems.
P
- Payment Card Industry Data Security Standard (PCI DSS)
The security standard for organizations that store, process, or transmit payment card account data, or that can affect its security. It is maintained by the PCI Security Standards Council, and as of 2026-09-26 version 4.0.1 is the only active version. The Council sets the standard, but payment card brands and acquiring banks decide who must validate compliance and how, for example through an assessment by a QSA Company or a Self-Assessment Questionnaire.
- Payment page script
In PCI DSS, any programming language commands or instructions on a payment page that the consumer's browser processes or interprets, such as JavaScript. Requirement 6.4.3 requires each script to be authorized, integrity-assured, inventoried, and justified, and Requirement 11.6.1 requires a mechanism that alerts on unauthorized changes to scripts and security-impacting HTTP headers as the browser receives them.
- Penetration test
An authorized, time-limited attempt to find and exploit weaknesses in specific systems the way a real attacker might, to show which weaknesses are reachable and what they could lead to. Unlike a vulnerability assessment, it relies on manual testing and can chain findings together. It requires written permission from someone with authority over the systems, an agreed scope, and rules of engagement before any testing starts.
- Plan of action and milestones (POA&M)
A plan that describes how unimplemented security requirements will be met and how planned mitigations will be carried out (NIST SP 800-171, requirement 3.12.2). The CMMC rule restricts its use: a Level 1 self-assessment never permits one, and at Level 2 a POA&M can support only a conditional status, for certain requirements, and must be closed out within 180 days (32 CFR 170.21).
- Points of focus
Descriptions of important characteristics of each Trust Services criterion, following the approach of the COSO framework. They help management design controls and help management and the service auditor evaluate them. They aren't a checklist: the AICPA says using the criteria doesn't require assessing whether every point of focus is addressed. The current points of focus were revised in 2022; the criteria themselves date from 2017.
Q
- Qualified Security Assessor (QSA)
An assessor qualified by the PCI Security Standards Council to perform formal PCI DSS assessments. The Council qualifies companies first, so an individual QSA holds that status only while employed by a qualified QSA Company and assesses on its behalf. The QSA Company is responsible for the resulting Report on Compliance, and an assessor may not evaluate a control they designed or implemented.
R
- Readiness assessment
A review of how prepared an organization is for a specific audit, assessment, or certification, and what it should fix first. Internal staff or outside advisors can perform one, and it has no formal standing: a good readiness result does not mean an independent auditor or assessor will reach the same conclusion.
- Recognized security practices
A term from Public Law 116-321 (January 5, 2021). When HHS makes decisions about fines, the length and extent of audits, or other remedies under the HIPAA Security Rule, it must consider whether an organization had recognized security practices in place for the previous 12 months. The law defines them to include standards and guidance developed under the NIST Act and approaches under section 405(d) of the Cybersecurity Act of 2015.
- Report on Compliance (ROC)
The detailed record of a PCI DSS assessment, documenting how each requirement was tested and what was found. For a third-party assessment it is prepared by the QSA Company, and the outcome is summarized in an Attestation of Compliance that the organization provides to its acquirer or the payment brands as required.
- Required and addressable implementation specifications
The two labels the HIPAA Security Rule gives its implementation specifications. Required specifications must be implemented. For an addressable one, the organization assesses whether it is reasonable and appropriate in its environment, then either implements it or documents why not and implements an equivalent alternative measure if that is reasonable and appropriate. Addressable does not mean optional.
- Risk assessment
A structured process for identifying threats and weaknesses, estimating how likely and how damaging each risk would be, and ranking the results so leaders can decide how to treat them: reduce, transfer, avoid, or accept. Several frameworks require one, including the risk analysis in the HIPAA Security Rule and the risk assessment process in ISO/IEC 27001.
- Risk register
A living list of an organization's identified risks, each with an owner, a rating, a treatment decision, and a status. Kept current, it connects risk assessments to the work that follows and records when leaders accept a risk rather than reduce it.
- Rules of engagement
The written terms for a security test: what may be tested, which techniques are allowed or off-limits, when testing may happen, who the contacts are on each side, how urgent findings are reported, and when testing must stop. Both parties agree to them in writing before testing begins.
S
- Scope
The boundary of an assessment, test, audit, or certification: which systems, locations, processes, data, people, and time period are included. A result applies only to what was in scope. In PCI DSS, for example, scope covers the cardholder data environment and the systems connected to it or able to affect its security.
- Self-Assessment Questionnaire (SAQ)
A PCI DSS validation form that an eligible merchant or service provider completes itself instead of undergoing a full assessment by a QSA Company. Different SAQ types match different ways of handling card data, and the acquirer or payment brand decides whether an SAQ is acceptable and which one applies. The organization signs its own attestation, even if an advisor helped it prepare.
- Service auditor
The AICPA's term for the CPA who performs a SOC examination and expresses the opinion in the report. A SOC 2 examination is performed under AICPA attestation standards AT-C section 105 and AT-C section 205, and the service auditor must be independent of the service organization. A readiness advisor, a software platform, or the organization's own staff can't act as its service auditor.
- SOC 1 report
A report from a CPA firm's examination of controls at a service organization that are relevant to its customers' internal control over financial reporting, performed under AICPA attestation standards (AT-C section 320). A SOC 1 report is aimed at financial reporting, while a SOC 2 report addresses security, availability, processing integrity, confidentiality, or privacy.
- SOC 2
An attestation report on a service organization's controls relevant to the AICPA's Trust Services Criteria. SOC stands for System and Organization Controls. A Type 1 report covers the design of controls at a point in time; a Type 2 report also covers how they operated over a period. Only an independent licensed CPA firm can perform the examination and issue the report, so there is no such thing as being “SOC 2 certified.”
- SOC 2 Type 1 report
A SOC 2 report in which the service auditor gives an opinion on the service organization's system description and on whether its controls were suitably designed, as of a specific date, to meet its service commitments and system requirements based on the applicable Trust Services Criteria. It doesn't include tests of whether the controls operated effectively over time.
- SOC 2 Type 2 report
A SOC 2 report that covers everything in a Type 1 report plus the operating effectiveness of the controls throughout a period of time. It includes the service auditor's detailed description of the tests of controls it performed and their results, which is where a reader finds any exceptions. The period covered is agreed for each examination.
- SOC 3 report
A report from a CPA firm's examination of a service organization's controls relevant to one or more Trust Services Criteria categories. Like a SOC 2 Type 2 report, it contains an opinion on the operating effectiveness of controls, but it doesn't include the detailed description of tests of controls and their results. The AICPA describes it as a general use report that can be freely distributed.
- Stage 1 and stage 2 audits
The two stages of an initial certification audit under ISO/IEC 17021-1. Stage 1 reviews the management system's documentation, evaluates the organization's readiness for stage 2, and gathers the information needed to plan it. Stage 2 evaluates the implementation, including the effectiveness, of the management system. Areas of concern found in stage 1 can be raised as nonconformities in stage 2.
- Statement of Applicability
An ISO/IEC 27001 document that lists the Annex A controls, states whether each is included and implemented, and explains the reason for including or excluding it. It links the organization's risk treatment decisions to its controls and is a required document for certification.
- Subservice organization
A vendor used by a service organization that performs controls needed, together with the service organization's own controls, to meet its service commitments and system requirements; a cloud hosting provider is a common example. A SOC 2 description treats it in one of two ways: the inclusive method brings the relevant parts of its system and controls into the description, and the carve-out method leaves them out while identifying the controls the vendor is assumed to operate.
- Supplier Performance Risk System (SPRS)
The Department of Defense system where summary level scores of NIST SP 800-171 DoD Assessments are posted and where CMMC affirmations are entered. Under DFARS 252.204-7019, an offeror required to implement NIST SP 800-171 needs a current assessment, not more than 3 years old unless the solicitation says less, with scores posted in SPRS, to be considered for award.
- Surveillance audit
A periodic audit a certification body performs between certification and recertification to confirm that a certified management system, such as an ISO/IEC 27001 ISMS, still meets the standard. Under ISO/IEC 17021-1, surveillance audits take place at least once each calendar year except in recertification years, and the first comes no more than 12 months after the certification decision.
- System description (SOC 2)
Service organization management's description of the system a SOC 2 report covers, prepared against the AICPA's 2018 description criteria (DC 200). It covers the services provided, principal service commitments and system requirements, system components, relevant incidents, the applicable criteria and controls, complementary user entity controls, subservice organizations, and, for a Type 2 report, significant changes during the period. Management owns it; the service auditor gives an opinion on it.
- System security plan (SSP)
A document that describes a system's boundaries, its environments of operation, how each security requirement is implemented, and its relationships with or connections to other systems. NIST SP 800-171 Revision 2 requires contractors to develop, document, and periodically update one (requirement 3.12.4), and a DFARS Basic Assessment starts from the contractor's review of its system security plans.
T
- Tabletop exercise
A facilitated, discussion-based session in which people with response roles walk through a realistic incident scenario to test decisions, escalation paths, and communication, without touching production systems. The findings are used to improve the incident response plan and assign follow-up work.
- Targeted risk analysis
A documented analysis that PCI DSS v4.0.1 calls for wherever a requirement specifies one, for example to set how often the payment page tamper-detection check in Requirement 11.6.1 runs. Requirement 12.3.1 says it must identify the assets protected, the threats, and the factors affecting likelihood and impact, justify the chosen frequency or process, and be reviewed at least once every 12 months.
- Trust Services Criteria
The criteria the AICPA publishes for SOC 2 examinations, organized into five categories: security, availability, processing integrity, confidentiality, and privacy. The security category is addressed in most SOC 2 examinations, and the common criteria (CC1 to CC9) apply to every category included. The organization chooses any other categories based on the commitments it makes to customers.
V
- Vendor risk management
The practice of identifying, assessing, and monitoring the security risks that come from third parties, such as software providers, contractors, and service partners, that handle your data or connect to your systems. It covers due diligence before onboarding, security terms in contracts, periodic review, and offboarding. NIST CSF 2.0 treats it as part of cybersecurity supply chain risk management.
- Virtual CISO (vCISO)
A part-time or fractional chief information security officer, usually engaged under contract, who provides security strategy, governance, policy direction, and reporting to leadership. The organization keeps accountability for its security decisions and for accepting risk; the vCISO advises and leads the program within the authority the organization grants. The role is also called a fractional CISO.
- Vulnerability assessment
A systematic review, usually driven by automated scanning and followed by validation and prioritization, that identifies known weaknesses across a set of systems. It is broader and shallower than a penetration test and does not normally attempt exploitation.
Further reading
- Is SOC 2 a certification? Who can issue what
- All insights: articles, the glossary, and tools
- Search the site
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.