The terms.
In plain English.Audit Trail — An audit trail is the tamper-evident record of who did what, when, in your systems — the evidence layer every framework samples and every incident needs.
Access Review — An access review is the periodic check that everyone's system access matches their role — the most-sampled SOC 2 control and the most common exception.
Attestation vs Certification — SOC 2 is an attestation — a CPA's opinion in a report. ISO 27001 is a certification — a pass/fail certificate. The difference changes how you sell each.
Bridge Letter — A bridge letter covers the gap between your last SOC 2 report period and today, letting customers rely on your report between annual audits.
Business Associate Agreement — A BAA is the HIPAA-required contract between covered entities and vendors handling PHI — what it must contain and why missing BAAs trigger enforcement.
Compensating Control — A compensating control mitigates a risk when the standard control isn't feasible — accepted by auditors when documented, justified, and genuinely equivalent.
Business Continuity Plan (BCP) — A business continuity plan keeps the business running through disruption; disaster recovery restores the systems. Auditors expect both — and a test record.
Continuous Monitoring — Continuous monitoring is the automated, ongoing testing of security controls — replacing point-in-time evidence scrambles with always-current audit readiness.
CAIQ — The CAIQ is the Cloud Security Alliance's standard security questionnaire — a yes/no assessment cloud vendors complete once and reuse across customer reviews.
CMMC — CMMC is the DoD's cybersecurity certification for contractors — three levels, anchored to NIST 800-171, now appearing in defense contracts and flow-downs.
Control Owner — A control owner is the named person accountable for a control operating — the assignment that separates running programs from stalled ones.
Data Residency — Data residency is where data is physically stored and processed — a contract term, a GDPR transfer question, and a growing procurement filter.
Data Classification — Data classification assigns sensitivity levels to data so controls can scale with risk — three or four tiers, applied where data lives, not in a binder.
CUI (Controlled Unclassified Information) — CUI is US government information that's sensitive but not classified — export data, defense technical data, and more. Handling it triggers NIST 800-171 and CMMC.
DPO (Data Protection Officer) — A DPO is GDPR's mandated privacy overseer — required for large-scale monitoring or sensitive-data processing. Most B2B SaaS startups don't need one yet.
Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.
Encryption at Rest vs in Transit — At rest protects stored data; in transit protects moving data. Every framework requires both — here's what the evidence looks like and where gaps hide.
DPIA — A DPIA is GDPR's structured risk assessment for high-risk processing — increasingly triggered by AI features. What it covers and when you must run one.
EU AI Act — The EU AI Act regulates AI by risk tier — prohibited, high-risk, limited, minimal — with obligations phasing in through 2026–2027. What SaaS teams must do.
Evidence Collection — Evidence collection is gathering the proof that controls operate — the audit's real workload, and the part automation genuinely transformed.
Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.
HITRUST — HITRUST is a certifiable framework harmonizing HIPAA, NIST, and ISO controls — demanded by some health systems, heavier than SOC 2, and often deferrable.
ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.
Incident Response Plan — An incident response plan defines how you detect, triage, contain, and learn from security incidents — with the records SOC 2 auditors and regulators sample.
FedRAMP — FedRAMP is the US government's cloud security authorization program — mandatory for selling cloud services to federal agencies, and a major undertaking.
Least Privilege — Least privilege means every identity gets the minimum access its role requires — the principle behind access reviews, role design, and most audit samples.
ISO 42001 — ISO 42001 certifies an AI management system (AIMS) — governance for how you build and use AI. The emerging answer to 'prove your AI is responsible.'
MDM (Mobile Device Management) — MDM enforces security on laptops and phones — encryption, screen lock, patching — and produces the endpoint evidence every SOC 2 and HIPAA audit samples.
NIST 800-53 — NIST 800-53 is the US government's control catalog — hundreds of controls across 20 families — underlying FedRAMP, FISMA, and federal procurement.
NIST CSF — NIST CSF is the voluntary framework organizing security into six functions — Govern, Identify, Protect, Detect, Respond, Recover — used as a common language.
Observation Window — The observation window is the period a SOC 2 Type II report covers — typically 3 to 12 months — during which controls must demonstrably operate.
Policy vs Procedure vs Standard — Policies say what and why, standards say how much, procedures say exactly how. Mixing the three is why compliance documents rot — and what auditors notice.
Inherent vs Residual Risk — Inherent risk is exposure before controls; residual risk is what remains after. Auditors check that the gap between them maps to real, operating controls.
Penetration Test vs Vulnerability Scan — A vulnerability scan is automated and finds known issues; a penetration test is a human actively exploiting your defenses. Auditors and customers ask for both.
Risk Appetite — Risk appetite is the level of risk leadership has decided to accept — the threshold that turns a risk register from a list into a decision system.
RTO vs RPO — RTO is how fast systems must come back; RPO is how much data you can afford to lose. Together they price your disaster recovery architecture.
ROC vs SAQ — PCI DSS validation comes in two forms: a self-assessment questionnaire (SAQ) you complete yourself, or a Report on Compliance (ROC) from a QSA. Volume decides.
Risk Register — A risk register is the living record of identified risks, their scores, owners, and treatments — sampled in every SOC 2 and ISO 27001 audit.
Security Questionnaire — Security questionnaires are buyers' vendor-risk interrogations — CAIQ, SIG, or bespoke spreadsheets. The teams that answer fast win deals faster.
SBOM — An SBOM is the machine-readable ingredient list of your software — every dependency and version. Federal buyers and security reviews increasingly require one.
Shared Responsibility Model — The shared responsibility model splits security duties between cloud provider and customer — and misreading the split is a classic audit and breach root cause.
SIG Questionnaire — The SIG is Shared Assessments' standardized vendor-risk questionnaire. SIG Core and SIG Lite let buyers assess vendors with one reusable question set.
SOC 3 — A SOC 3 is the public, general-use version of a SOC 2 Type II report — same audit, no confidential detail, freely publishable on your website.
Statement of Applicability — The SoA lists every ISO 27001 Annex A control with your inclusion or exclusion decision and justification — the document certification auditors read first.
SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.
Sub-processor — A sub-processor is any third party your company uses to process customer personal data — your cloud host, email provider, analytics. You must disclose them.
SOC 1 — A SOC 1 report covers controls relevant to customers' financial reporting — payroll, billing, fund flows. SOC 2 covers security. Many companies need only one.
Standard Contractual Clauses (SCCs) — Standard Contractual Clauses are the EU-approved contract terms that make transfers of personal data outside the EU lawful — the workhorse of GDPR transfers.
Trust Center — A trust center is a public page where buyers self-serve your security posture — certifications, sub-processors, and NDA-gated reports. Now table stakes.
Tabletop Exercise — A tabletop exercise is a discussion-based rehearsal of your incident response plan — the cheapest strong evidence that the plan actually works.
Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.
vCISO — A vCISO provides fractional executive security leadership — strategy, risk decisions, and buyer-facing credibility — without a full-time CISO salary.