Compliance glossary
The vocabulary of GRC, plainly defined.
The terms that run through frameworks, controls, evidence, risk and audit, without the jargon.
Frameworks & compliance
- Framework
- A structured set of requirements and controls, such as ISO 27001 or SOC 2, that an organisation aligns its programme to.
- Control
- A safeguard or measure that reduces risk and satisfies a requirement, from access reviews to encryption.
- Unified control library
- One harmonised set of controls mapped across every framework that needs them, so you implement a control once and inherit it everywhere.
- Gap analysis
- A comparison of your current controls against a framework to surface exactly what is missing.
- Statement of Applicability
- The ISO 27001 document that records which Annex A controls apply, and the justification for any excluded.
- Cross-framework reuse
- Using a single piece of evidence to satisfy requirements in several frameworks at once, collected only once.
Evidence & audit
- Evidence
- An artifact, a log, policy, configuration or report, that proves a control is designed and operating.
- Audit package
- The assembled set of controls and evidence handed to an assessor, built from links that already exist.
- Type I / Type II
- SOC 2 report kinds: a point-in-time test of control design (I) versus operating effectiveness over a period (II).
- Attestation
- A formal, recorded acknowledgement that a policy or control has been read, reviewed or accepted.
- Continuous control monitoring
- Automated, ongoing checks that a control keeps working between formal audits, not just at assessment time.
Risk
- Risk register
- The catalogue of identified risks, each with an owner, a score and a treatment decision.
- Inherent vs residual risk
- The level of risk before controls are applied (inherent) versus what remains after them (residual).
- Risk appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives.
- Key Risk Indicator (KRI)
- A metric that signals a rising level of risk as it approaches or breaches a defined threshold.
- RCSA
- Risk and Control Self-Assessment: a structured review in which the business rates its own risks and control effectiveness.
- Treatment
- The decision on how to handle a risk: accept, mitigate, transfer or avoid it.
Governance & policy
- Policy lifecycle
- The path a document travels: draft, review, approve, publish and attest, with version history at every step.
- Exception
- A documented, approved deviation from a policy or control, mapped back to what it departs from.
- Committee
- A governance body, such as a security steering committee, that owns decisions, charters and action items.
- Regulatory change
- A tracked update to a law or standard that triggers a review of the affected controls and policies.
Security & third parties
- Vulnerability
- A weakness in a system, application or process that could be exploited by a threat.
- EPSS / KEV
- The Exploit Prediction Scoring System and CISA's Known Exploited Vulnerabilities catalogue, used to prioritise fixes by real exploitability.
- Remediation SLA
- The agreed time allowed to fix a finding, tracked from the day it is raised.
- TPRM
- Third-Party Risk Management: assessing and continuously monitoring vendors across their whole lifecycle.
- CIA triad
- Confidentiality, Integrity and Availability, the three properties that information security controls protect.
The Compliverse model
- The linkage graph
- The connected data model that ties frameworks, policies, controls, evidence, risks and audits together as one graph.
- Tenant isolation
- Keeping each customer's data separated in its own scope, so answers and evidence never cross tenants.
Want to see these turned into a running programme on your own frameworks?
Book a live demo