Glossary
Plain-language definitions for SOC 2, ISO 27001, HIPAA, and general audit terminology.
Availability is one of the SOC 2 Trust Services Criteria. It focuses on whether systems, applications, data, and services are available for operation and use as committed or agreed.
An audit period is the timeframe covered by an audit. It defines the period of activity, evidence, control operation, and business process performance that an auditor will review.
An audit trail is a chronological record of actions, changes, approvals, and system events that provides visibility into who performed an action, what was changed, when it occurred, and, in some cases, why it happened.
Audit evidence is the documentation, records, and supporting information used to demonstrate that a control was operating effectively during an audit period.
A security practice that determines who can access systems, applications, and data, and what actions they are permitted to perform.
Learn how control mapping connects security controls to requirements across SOC 2, ISO 27001, NIST, HIPAA, PCI DSS, and other frameworks.
Learn what a control owner does, how control ownership supports compliance, and what auditors expect control owners to demonstrate.
Confidentiality is the principle that sensitive information should only be accessed, used, or disclosed by authorized people, systems, and organizations.
Learn what a compliance framework is, how it organizes regulatory and security requirements, and how organizations use frameworks to manage controls and audit evidence.
It explains what went wrong, what needs to be corrected, who is responsible, when the work should be completed, and how the organization will confirm the issue has been resolved.
Instead of creating controls from scratch, companies often use a recognized framework to understand what areas they need to cover, how controls should be organized, and what auditors or assessors may expect to review.
In compliance and security, controls are used to show that an organization has safeguards in place to protect data, manage access, respond to incidents, review changes, and operate systems responsibly.
In a traditional audit process, teams often scramble near the end of the audit period to gather screenshots, exports, access reviews, policy acknowledgements, tickets, approvals, and other records. Continuous compliance changes that rhythm. Instead of treating compliance as a once-a-year project, the organization collects and organizes evidence as work happens.
Compliance is the act of following laws, regulations, standards, contractual obligations, and internal policies that apply to an organization.
A compensating control is an alternative control used when the primary or expected control cannot be implemented, but the organization still needs to reduce risk to an acceptable level.
Change management is the process used to review, approve, test, and implement modifications to systems, infrastructure, applications, configurations, or policies.
CAPA stands for Corrective and Preventive Action. It is a structured process for identifying issues, correcting them, and preventing them from happening again.
Disaster recovery is the set of plans, systems, and tested steps used to restore critical technology and data after a major disruption.
Learn how data classification categorizes information by sensitivity, risk, and handling requirements to support security, privacy, and compliance.
In compliance and security, data retention helps organizations manage records responsibly. This can include customer data, employee records, contracts, audit evidence, logs, tickets, access reviews, security alerts, policy acknowledgements, and other business records.
Exception management is the day-to-day process of identifying, assessing, approving or accepting, remediating, and closing control or policy deviations with clear ownership and time bounds.
Evidence collection is the practice of gathering, organizing, and retaining proof that controls operated as intended, so auditors and stakeholders can evaluate compliance over time.
Encryption is the process of converting readable data into protected ciphertext so only authorized parties with the right keys can read it.
Governance, risk, and compliance (GRC) is the coordinated program that sets direction and accountability, identifies and treats risk, and meets external and internal obligations with owned controls and evidence.
A gap analysis compares your current security and compliance practices against a target framework or set of controls, then lists the missing or weak areas that need remediation before an audit or certification effort.
ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Internal audit is an independent assurance function inside an organization that evaluates whether governance, risk management, and internal controls are designed and operating as intended.
An information security policy is the top-level written statement of your organization's security principles, roles, and expectations for protecting systems, data, and services.
Incident management is the process to detect, triage, contain, eradicate, recover from, and learn from security or operational incidents, with severity, roles, timelines, communication, and evidence for audits.
Logical access is the ability to interact with systems, applications, data, and digital resources through credentials and permissions, as distinct from physical access to buildings or hardware.
Least privilege is the access principle that users, services, and devices receive only the minimum permissions needed to perform an authorized task, for only as long as needed.