Glossary
Plain-language definitions for SOC 2, ISO 27001, HIPAA, and general audit terminology.
Availability is one of the SOC 2 Trust Services Criteria. It focuses on whether systems, applications, data, and services are available for operation and use as committed or agreed.
An audit period is the timeframe covered by an audit. It defines the period of activity, evidence, control operation, and business process performance that an auditor will review.
An audit trail is a chronological record of actions, changes, approvals, and system events that provides visibility into who performed an action, what was changed, when it occurred, and, in some cases, why it happened.
Audit evidence is the documentation, records, and supporting information used to demonstrate that a control was operating effectively during an audit period.
A security practice that determines who can access systems, applications, and data, and what actions they are permitted to perform.
It explains what went wrong, what needs to be corrected, who is responsible, when the work should be completed, and how the organization will confirm the issue has been resolved.
Instead of creating controls from scratch, companies often use a recognized framework to understand what areas they need to cover, how controls should be organized, and what auditors or assessors may expect to review.
In compliance and security, controls are used to show that an organization has safeguards in place to protect data, manage access, respond to incidents, review changes, and operate systems responsibly.
In a traditional audit process, teams often scramble near the end of the audit period to gather screenshots, exports, access reviews, policy acknowledgements, tickets, approvals, and other records. Continuous compliance changes that rhythm. Instead of treating compliance as a once-a-year project, the organization collects and organizes evidence as work happens.
Compliance is the act of following laws, regulations, standards, contractual obligations, and internal policies that apply to an organization.
A compensating control is an alternative control used when the primary or expected control cannot be implemented, but the organization still needs to reduce risk to an acceptable level.
Change management is the process used to review, approve, test, and implement modifications to systems, infrastructure, applications, configurations, or policies.
CAPA stands for Corrective and Preventive Action. It is a structured process for identifying issues, correcting them, and preventing them from happening again.