Skip to main contentSkip to main content
    99 Terms

    Compliance Glossary

    Master compliance terminology with our comprehensive glossary. Every term explained in plain English.

    All Glossary Terms

    A(11 terms)

    compliance
    Acceptable Use Policy (AUP)

    An AUP defines the rules for using an organization's IT resources, outlining permitted and prohibited activities.

    security
    Access Control

    Access control is a security mechanism that regulates who can view or use resources in a computing environment, ensuring only authorized users can access systems and data.

    compliance
    AI Governance

    AI governance is the framework of policies, processes, and controls that ensure AI systems are developed and used responsibly, ethically, and in compliance with regulations.

    process
    AI Risk Management

    AI risk management systematically identifies, assesses, and mitigates risks unique to artificial intelligence systems throughout their lifecycle.

    compliance
    Algorithmic Accountability

    Algorithmic accountability ensures that organizations can explain, justify, and take responsibility for the outcomes of automated decision-making systems.

    process
    Annualized Loss Expectancy (ALE)

    ALE is a risk calculation that estimates the expected monetary loss from a risk over a one-year period, calculated by multiplying Single Loss Expectancy (SLE) by Annual Rate of Occurrence (ARO).

    security
    API Security

    API security encompasses practices and technologies used to protect Application Programming Interfaces from attacks and misuse, including authentication, authorization, rate limiting, and input validation.

    process
    Asset Inventory

    An asset inventory is a comprehensive list of all hardware, software, data, and information assets within an organization, serving as the foundation for security management and compliance.

    security
    Audit Trail

    An audit trail (or audit log) is a chronological record of system activities that provides documentary evidence of the sequence of events that have affected an operation or procedure.

    security
    Authentication

    Authentication is the process of verifying the identity of a user, device, or system before granting access to resources.

    security
    Authorization

    Authorization is the process of determining what actions or resources an authenticated user is permitted to access.

    B(5 terms)

    C(10 terms)

    framework
    CCPA/CPRA

    CCPA (California Consumer Privacy Act) and its amendment CPRA grant California residents rights over their personal data and impose obligations on businesses.

    process
    Change Management

    Change management is a structured process for planning, approving, implementing, and documenting changes to IT systems to minimize risk of unintended disruptions or security issues.

    security
    Cloud Security

    Cloud security encompasses the technologies, policies, and controls used to protect data, applications, and infrastructure in cloud computing environments.

    framework
    CMMC

    CMMC (Cybersecurity Maturity Model Certification) is a DoD requirement for defense contractors that combines cybersecurity standards and third-party assessment to protect Controlled Unclassified Information (CUI).

    tool
    Compliance Automation

    Compliance automation uses software platforms to automatically collect evidence, monitor controls, and streamline audit preparation, reducing manual effort by 60-80% compared to traditional approaches.

    security
    Container Security

    Container security protects containerized applications throughout their lifecycle, from image building through deployment and runtime.

    security
    Continuous Monitoring

    Continuous monitoring is the ongoing, automated observation of security controls, systems, and networks to detect issues, ensure compliance, and respond to threats in real-time.

    compliance
    Controls Testing

    Controls testing is the process of evaluating whether security and compliance controls are properly designed and operating effectively to achieve their intended objectives.

    security
    CSPM

    Cloud Security Posture Management (CSPM) continuously monitors cloud infrastructure for misconfigurations, compliance violations, and security risks.

    process
    Cyber Insurance

    Cyber insurance provides financial protection against losses from cyber incidents including data breaches, ransomware, and business interruption.

    D(7 terms)

    E(6 terms)

    F(3 terms)

    G(3 terms)

    H(2 terms)

    I(6 terms)

    J(1 term)

    K(1 term)

    L(3 terms)

    M(4 terms)

    N(3 terms)

    O(3 terms)

    P(6 terms)

    Q(2 terms)

    R(4 terms)

    S(8 terms)

    T(4 terms)

    V(4 terms)

    W(2 terms)

    Z(1 term)

    Need Help Understanding Compliance?

    Our experts can explain any concept and help you implement the right controls for your organization.

    Talk to an Expert