Glossary

Cyber governance glossary

A practical executive reference for Virtual CISO, ISO 27001, GDPR, DORA, SOC 2, AI governance, vendor risk, and related security concepts.

47terms
13topic areas
EN / TRbilingual

47 terms shown

Filter by topic
A
Security Controls

Access Control

A security control family that governs who can access systems, data, and functions.

Full definition and related resources

A security control family that governs who can access systems, data, and functions.

Related pages: vCISO, Resources and Blog.

Security ControlsAccess Control
AI Governance

AI Governance

A management approach for using artificial intelligence with clear accountability, data rules, oversight, and risk controls.

Full definition and related resources

AI governance is the management approach for deciding how AI tools are used, which data they may process, who owns the risk, and what human oversight is required. It is not only model testing. It includes policy, use-case inventory, data classification, vendor assessment, monitoring, and decision records.

Why it matters: Generative AI adoption can move faster than security and privacy review. Without governance, teams may expose sensitive data, rely on unclear vendor terms, or use outputs without accountability. A practical AI governance model sets acceptable use boundaries while preserving useful adoption and executive visibility.

AI GovernanceAI Governance
B
Resilience

Business Continuity

The capability to continue important business operations during disruption.

Full definition and related resources

The capability to continue important business operations during disruption.

Related pages: vCISO, Resources and Blog.

ResilienceBusiness Continuity
C
Governance

Control Owner

The person accountable for operating, maintaining, and evidencing a control.

Full definition and related resources

The person accountable for operating, maintaining, and evidencing a control.

Related pages: vCISO, Resources and Blog.

GovernanceControl Owner
Assurance

Corrective Action

A documented action that addresses the root cause of a nonconformity or control weakness.

Full definition and related resources

A documented action that addresses the root cause of a nonconformity or control weakness.

Related pages: vCISO, Resources and Blog.

AssuranceCorrective Action
Privacy

Cross-Border Data Transfer

A transfer of personal data from one jurisdiction to another, often requiring legal and security safeguards.

Full definition and related resources

A transfer of personal data from one jurisdiction to another, often requiring legal and security safeguards.

Related pages: vCISO, Resources and Blog.

PrivacyCross-Border Data Transfer
Governance

Cyber Governance

The operating model that connects security risk, ownership, controls, reporting, and executive decisions.

Full definition and related resources

The operating model that connects security risk, ownership, controls, reporting, and executive decisions.

Related pages: vCISO, Resources and Blog.

GovernanceCyber Governance
D
Data Governance

Data Classification

A process for labeling data by sensitivity, business value, and handling requirements.

Full definition and related resources

A process for labeling data by sensitivity, business value, and handling requirements.

Related pages: vCISO, Resources and Blog.

Data GovernanceData Classification
Privacy

Data Controller

The organization or person that determines the purposes and means of personal data processing.

Full definition and related resources

The organization or person that determines the purposes and means of personal data processing.

Related pages: vCISO, Resources and Blog.

PrivacyData Controller
Privacy

Data Processor

A party that processes personal data on behalf of a controller.

Full definition and related resources

A party that processes personal data on behalf of a controller.

Related pages: vCISO, Resources and Blog.

PrivacyData Processor
Privacy

Data Subject

The individual whose personal data is processed.

Full definition and related resources

The individual whose personal data is processed.

Related pages: vCISO, Resources and Blog.

PrivacyData Subject
DORA

Digital Operational Resilience

The ability of an organization to prevent, withstand, recover from, and learn from digital disruptions.

Full definition and related resources

The ability of an organization to prevent, withstand, recover from, and learn from digital disruptions.

Related pages: vCISO, Resources and Blog.

DORADigital Operational Resilience
Resilience

Disaster Recovery

The process and capability to restore technology services after a major failure or disaster.

Full definition and related resources

The process and capability to restore technology services after a major failure or disaster.

Related pages: vCISO, Resources and Blog.

ResilienceDisaster Recovery
DORA

DORA

The EU Digital Operational Resilience Act for financial entities and ICT service providers in the financial ecosystem.

Full definition and related resources

DORA defines digital operational resilience expectations for financial entities and important ICT service providers in the European Union. It is not limited to technical security controls. It also brings attention to incident handling, third-party dependencies, resilience testing, evidence management, and management reporting.

Why it matters: A technology company serving EU finance customers may see DORA requirements appear in security questionnaires, contract clauses, and vendor reviews. Readiness work helps clarify which services are critical, which evidence is available, who owns supplier risk, and how resilience topics are reported to leadership. This is a practical governance explanation, not legal advice.

DORADORA
Privacy

DPIA

A data protection impact assessment used to evaluate privacy risks in higher-risk processing activities.

Full definition and related resources

A data protection impact assessment used to evaluate privacy risks in higher-risk processing activities.

Related pages: vCISO, Resources and Blog.

PrivacyDPIA
E
Security Controls

Encryption

A technical control that protects data confidentiality by transforming readable data into protected form.

Full definition and related resources

A technical control that protects data confidentiality by transforming readable data into protected form.

Related pages: vCISO, Resources and Blog.

Security ControlsEncryption
F
vCISO

Fractional CISO

A part-time CISO model used by companies that need senior security leadership before a permanent executive hire.

Full definition and related resources

A part-time CISO model used by companies that need senior security leadership before a permanent executive hire.

Related pages: vCISO, Resources and Blog.

vCISOFractional CISO
G
Privacy

GDPR

The European Union data protection regulation governing personal data processing.

Full definition and related resources

GDPR is the European Union data protection regulation governing personal data processing. It covers lawful bases, transparency, data subject rights, minimization, breach notification, processor obligations, and transfer mechanisms.

Why it matters: Companies outside the EU may still face GDPR expectations when they serve EU customers, employees, or users. Those expectations often appear in contracts, vendor reviews, and security questionnaires. GDPR readiness overlaps with KVKK in some areas, but scope, documentation, transfer analysis, and governance routines should be tracked clearly and separately.

PrivacyGDPR
I
DORA

ICT Risk Management

The discipline of identifying, treating, and monitoring risks from information and communication technology systems.

Full definition and related resources

The discipline of identifying, treating, and monitoring risks from information and communication technology systems.

Related pages: vCISO, Resources and Blog.

DORAICT Risk Management
Resilience

Incident Response Plan

A documented process for detecting, escalating, containing, and recovering from security incidents.

Full definition and related resources

A documented process for detecting, escalating, containing, and recovering from security incidents.

Related pages: vCISO, Resources and Blog.

ResilienceIncident Response Plan
Assurance

Internal Audit

An independent review used to test whether policies, controls, and evidence work as intended.

Full definition and related resources

An independent review used to test whether policies, controls, and evidence work as intended.

Related pages: vCISO, Resources and Blog.

AssuranceInternal Audit
ISO

ISMS

An information security management system covering risk, controls, policies, evidence, and improvement.

Full definition and related resources

An ISMS is an information security management system. It brings together risk assessment, policy, control operation, measurement, internal audit, management review, and corrective actions as a repeatable governance cycle.

Why it matters: In ISO 27001 readiness, the value comes from making security decisions in a managed system rather than producing documents only for an audit. An ISMS creates shared ownership across security, legal, HR, product, and leadership teams. It also helps evidence appear during normal work, not only during audit preparation.

ISOISMS
ISO

ISO 27001

An international standard for information security management systems and risk-based control governance.

Full definition and related resources

ISO 27001 describes a risk-based information security management system. It is more than a document set; it covers scope, risk assessment, control ownership, evidence, internal audit, management review, and continual improvement.

Why it matters: B2B buyers, enterprise customers, and investors often ask about ISO 27001 readiness as a signal of security maturity. The standard does not require every company to implement every control in the same way. It expects reasoned decisions based on risk, supported by evidence that shows the operating system is working before an audit or customer review.

ISOISO 27001
ISO

ISO 27002

A guidance standard that explains information security controls used with ISO 27001.

Full definition and related resources

A guidance standard that explains information security controls used with ISO 27001.

Related pages: vCISO, Resources and Blog.

ISOISO 27002
ISO

ISO 27005

An ISO standard focused on information security risk management.

Full definition and related resources

An ISO standard focused on information security risk management.

Related pages: vCISO, Resources and Blog.

ISOISO 27005
Privacy

ISO 27701

A privacy information management extension to ISO 27001 and ISO 27002.

Full definition and related resources

A privacy information management extension to ISO 27001 and ISO 27002.

Related pages: vCISO, Resources and Blog.

PrivacyISO 27701
AI Governance

ISO 42001

A management system standard for artificial intelligence governance.

Full definition and related resources

A management system standard for artificial intelligence governance.

Related pages: vCISO, Resources and Blog.

AI GovernanceISO 42001
K
Privacy

KVKK

Turkey’s primary personal data protection law and privacy compliance framework.

Full definition and related resources

KVKK is Turkey’s primary personal data protection law and privacy compliance framework. For companies, it is not only a privacy notice exercise. Processing purposes, controller and processor roles, retention, third-party transfers, and security measures need to work together.

Why it matters: KVKK readiness connects directly with security governance. Access control, logging, data classification, vendor assessment, and incident response all affect personal data risk. Companies working with Turkish customers or operations need a practical way to connect privacy obligations with daily control ownership. This summary is an operational explanation, not legal advice.

PrivacyKVKK
L
Security Controls

Least Privilege

The principle that users and systems should have only the access needed to perform their role.

Full definition and related resources

The principle that users and systems should have only the access needed to perform their role.

Related pages: vCISO, Resources and Blog.

Security ControlsLeast Privilege
Security Controls

Logging and Monitoring

Collection and review of events to detect issues, support investigations, and prove control operation.

Full definition and related resources

Collection and review of events to detect issues, support investigations, and prove control operation.

Related pages: vCISO, Resources and Blog.

Security ControlsLogging and Monitoring
M
Security Controls

MFA

Multi-factor authentication requiring more than one factor to verify user identity.

Full definition and related resources

Multi-factor authentication requiring more than one factor to verify user identity.

Related pages: vCISO, Resources and Blog.

Security ControlsMFA
P
Privacy

PIMS

A privacy information management system for organizing privacy roles, controls, evidence, and accountability.

Full definition and related resources

A privacy information management system for organizing privacy roles, controls, evidence, and accountability.

Related pages: vCISO, Resources and Blog.

PrivacyPIMS
Governance

Policy Exception

A documented, approved deviation from a policy, usually with risk acceptance and an expiry date.

Full definition and related resources

A documented, approved deviation from a policy, usually with risk acceptance and an expiry date.

Related pages: vCISO, Resources and Blog.

GovernancePolicy Exception
Privacy

Privacy by Design

A practice of embedding privacy safeguards into systems and processes from the beginning.

Full definition and related resources

A practice of embedding privacy safeguards into systems and processes from the beginning.

Related pages: vCISO, Resources and Blog.

PrivacyPrivacy by Design
R
Risk

Residual Risk

The risk that remains after controls and treatment actions are applied.

Full definition and related resources

The risk that remains after controls and treatment actions are applied.

Related pages: vCISO, Resources and Blog.

RiskResidual Risk
Risk

Risk Appetite

The amount and type of risk an organization is willing to accept in pursuit of objectives.

Full definition and related resources

The amount and type of risk an organization is willing to accept in pursuit of objectives.

Related pages: vCISO, Resources and Blog.

RiskRisk Appetite
Risk

Risk Register

A structured record of risks, owners, treatment decisions, controls, and status.

Full definition and related resources

A risk register is a structured record of security and privacy risks, owners, likelihood, impact, treatment decisions, controls, and status. A useful register is not just a list of findings. It records decision history and makes ownership visible.

Why it matters: Executive reporting and audit readiness both require clarity on who owns a risk and what decision has been made. A risk register turns technical findings into business priorities and supports decisions about budget, remediation, acceptance, and sequencing.

RiskRisk Register
Privacy

RoPA

Records of Processing Activities documenting personal data processing purposes, categories, recipients, and retention.

Full definition and related resources

RoPA means Records of Processing Activities. It documents personal data processing purposes, categories, systems, recipients, retention, and other key processing details. It gives privacy and security teams operational visibility into data flows.

Why it matters: Without a processing record, it is difficult to design accurate notices, retention rules, vendor reviews, or security controls. RoPA supports data classification, access control, transfer analysis, and incident response scoping. It is most useful when maintained as a living inventory rather than a one-time spreadsheet.

PrivacyRoPA
S
Customer Trust

Security Evidence Pack

A reusable set of policies, reports, diagrams, and control evidence used to answer trust requests.

Full definition and related resources

A reusable set of policies, reports, diagrams, and control evidence used to answer trust requests.

Related pages: vCISO, Resources and Blog.

Customer TrustSecurity Evidence Pack
Customer Trust

Security Questionnaire

A customer or buyer assessment of a vendor’s security controls and evidence.

Full definition and related resources

A security questionnaire is a customer or buyer assessment of a vendor’s controls and evidence. It commonly covers access management, encryption, logging, incident response, business continuity, vendor management, privacy, and audit readiness.

Why it matters: In enterprise sales, weak or inconsistent questionnaire answers can slow the buying process. A maintained evidence pack, approved answer base, and clear control ownership model help teams respond faster and more accurately. The goal is not to say yes to every question, but to explain the current control position clearly.

Customer TrustSecurity Questionnaire
Assurance

SOC 2

An attestation reporting framework for service organizations based on Trust Services Criteria.

Full definition and related resources

SOC 2 is an attestation reporting approach used by service organizations to explain controls related to security, availability, confidentiality, processing integrity, and privacy. It is not the same as an ISO-style certificate. Scope, report period, control design, and selected criteria matter.

Why it matters: SaaS and technology companies often use SOC 2 reports when enterprise customers request assurance evidence. Readiness work helps teams define control owners, evidence sources, exception handling, and reusable answer bases for security questionnaires. The goal is not to overpromise compliance, but to make control operation easier to explain and verify.

AssuranceSOC 2
ISO

Statement of Applicability

An ISO 27001 document explaining which controls apply, which do not, and why.

Full definition and related resources

The Statement of Applicability is an ISO 27001 document explaining which controls apply, which do not, and why. It connects scope, risk assessment, control ownership, and implementation status into one decision record.

Why it matters: During audit readiness, the SoA explains why controls were selected or excluded and how their implementation is tracked. If it is not maintained, the document can drift away from operational reality. It should therefore be managed with the risk register, evidence map, and control owner matrix.

ISOStatement of Applicability
T
Vendor Risk

Third-Party Risk Management

A broader risk discipline for outsourced services, suppliers, technology providers, and partners.

Full definition and related resources

A broader risk discipline for outsourced services, suppliers, technology providers, and partners.

Related pages: vCISO, Resources and Blog.

Vendor RiskThird-Party Risk Management
Assurance

Trust Services Criteria

The criteria used in SOC 2 reports covering areas such as security, availability, processing integrity, confidentiality, and privacy.

Full definition and related resources

The criteria used in SOC 2 reports covering areas such as security, availability, processing integrity, confidentiality, and privacy.

Related pages: vCISO, Resources and Blog.

AssuranceTrust Services Criteria
V
vCISO

vCISO

A virtual or fractional executive security leader who guides cyber governance without requiring a full-time CISO.

Full definition and related resources

A virtual or fractional executive security leader who guides cyber governance without requiring a full-time CISO.

Related pages: vCISO, Resources and Blog.

vCISOvCISO
Vendor Risk

Vendor Risk Management

The process of assessing and monitoring security, privacy, resilience, and compliance risks from vendors.

Full definition and related resources

Vendor risk management is the process of assessing and monitoring security, privacy, resilience, and compliance risks from external providers. It should include criticality, due diligence, contract expectations, evidence review, ongoing monitoring, and incident communication.

Why it matters: Cloud platforms, SaaS tools, consultants, and AI providers are part of normal business operations. Risk therefore extends beyond the company boundary. A clear program helps show which vendors are critical, which controls are evidenced, and who accepts residual risk when gaps remain.

Vendor RiskVendor Risk Management
vCISO

Virtual CISO

Executive-level cybersecurity leadership delivered without requiring a full-time in-house CISO role.

Full definition and related resources

A Virtual CISO (vCISO) provides senior cybersecurity leadership without requiring an organization to hire a full-time CISO. The role typically covers security strategy, risk ownership, governance, executive reporting, customer assurance, compliance readiness, and prioritization.

A virtual CISO is different from a managed security provider: the emphasis is on leadership and decision-making, not operating a SOC or reselling security tools.

Related pages: Virtual CISO services, vCISO guide and Do I need a vCISO?.

Related terms

Virtual CISOvCISOSecurity Leadership