Glossary

Cyber governance glossary

Plain definitions for common security, privacy, AI risk, and compliance terms used in executive conversations.

Security Controls

Access Control

A security control family that governs who can access systems, data, and functions.

A security control family that governs who can access systems, data, and functions.

Related pages: vCISO, Resources and Blog.

Security ControlsAccess Control
AI Governance

AI Governance

A management approach for using artificial intelligence with clear accountability, data rules, oversight, and risk controls.

AI governance is the management approach for deciding how AI tools are used, which data they may process, who owns the risk, and what human oversight is required. It is not only model testing. It includes policy, use-case inventory, data classification, vendor assessment, monitoring, and decision records.

Why it matters: Generative AI adoption can move faster than security and privacy review. Without governance, teams may expose sensitive data, rely on unclear vendor terms, or use outputs without accountability. A practical AI governance model sets acceptable use boundaries while preserving useful adoption and executive visibility.

AI GovernanceAI Governance
Resilience

Business Continuity

The capability to continue important business operations during disruption.

The capability to continue important business operations during disruption.

Related pages: vCISO, Resources and Blog.

ResilienceBusiness Continuity
Governance

Control Owner

The person accountable for operating, maintaining, and evidencing a control.

The person accountable for operating, maintaining, and evidencing a control.

Related pages: vCISO, Resources and Blog.

GovernanceControl Owner
Assurance

Corrective Action

A documented action that addresses the root cause of a nonconformity or control weakness.

A documented action that addresses the root cause of a nonconformity or control weakness.

Related pages: vCISO, Resources and Blog.

AssuranceCorrective Action
Privacy

Cross-Border Data Transfer

A transfer of personal data from one jurisdiction to another, often requiring legal and security safeguards.

A transfer of personal data from one jurisdiction to another, often requiring legal and security safeguards.

Related pages: vCISO, Resources and Blog.

PrivacyCross-Border Data Transfer
Governance

Cyber Governance

The operating model that connects security risk, ownership, controls, reporting, and executive decisions.

The operating model that connects security risk, ownership, controls, reporting, and executive decisions.

Related pages: vCISO, Resources and Blog.

GovernanceCyber Governance
Data Governance

Data Classification

A process for labeling data by sensitivity, business value, and handling requirements.

A process for labeling data by sensitivity, business value, and handling requirements.

Related pages: vCISO, Resources and Blog.

Data GovernanceData Classification
Privacy

Data Controller

The organization or person that determines the purposes and means of personal data processing.

The organization or person that determines the purposes and means of personal data processing.

Related pages: vCISO, Resources and Blog.

PrivacyData Controller
Privacy

Data Processor

A party that processes personal data on behalf of a controller.

A party that processes personal data on behalf of a controller.

Related pages: vCISO, Resources and Blog.

PrivacyData Processor
Privacy

Data Subject

The individual whose personal data is processed.

The individual whose personal data is processed.

Related pages: vCISO, Resources and Blog.

PrivacyData Subject
DORA

Digital Operational Resilience

The ability of an organization to prevent, withstand, recover from, and learn from digital disruptions.

The ability of an organization to prevent, withstand, recover from, and learn from digital disruptions.

Related pages: vCISO, Resources and Blog.

DORADigital Operational Resilience
Resilience

Disaster Recovery

The process and capability to restore technology services after a major failure or disaster.

The process and capability to restore technology services after a major failure or disaster.

Related pages: vCISO, Resources and Blog.

ResilienceDisaster Recovery
DORA

DORA

The EU Digital Operational Resilience Act for financial entities and ICT service providers in the financial ecosystem.

DORA defines digital operational resilience expectations for financial entities and important ICT service providers in the European Union. It is not limited to technical security controls. It also brings attention to incident handling, third-party dependencies, resilience testing, evidence management, and management reporting.

Why it matters: A technology company serving EU finance customers may see DORA requirements appear in security questionnaires, contract clauses, and vendor reviews. Readiness work helps clarify which services are critical, which evidence is available, who owns supplier risk, and how resilience topics are reported to leadership. This is a practical governance explanation, not legal advice.

DORADORA
Privacy

DPIA

A data protection impact assessment used to evaluate privacy risks in higher-risk processing activities.

A data protection impact assessment used to evaluate privacy risks in higher-risk processing activities.

Related pages: vCISO, Resources and Blog.

PrivacyDPIA
Security Controls

Encryption

A technical control that protects data confidentiality by transforming readable data into protected form.

A technical control that protects data confidentiality by transforming readable data into protected form.

Related pages: vCISO, Resources and Blog.

Security ControlsEncryption
vCISO

Fractional CISO

A part-time CISO model used by companies that need senior security leadership before a permanent executive hire.

A part-time CISO model used by companies that need senior security leadership before a permanent executive hire.

Related pages: vCISO, Resources and Blog.

vCISOFractional CISO
Privacy

GDPR

The European Union data protection regulation governing personal data processing.

GDPR is the European Union data protection regulation governing personal data processing. It covers lawful bases, transparency, data subject rights, minimization, breach notification, processor obligations, and transfer mechanisms.

Why it matters: Companies outside the EU may still face GDPR expectations when they serve EU customers, employees, or users. Those expectations often appear in contracts, vendor reviews, and security questionnaires. GDPR readiness overlaps with KVKK in some areas, but scope, documentation, transfer analysis, and governance routines should be tracked clearly and separately.

PrivacyGDPR
DORA

ICT Risk Management

The discipline of identifying, treating, and monitoring risks from information and communication technology systems.

The discipline of identifying, treating, and monitoring risks from information and communication technology systems.

Related pages: vCISO, Resources and Blog.

DORAICT Risk Management
Resilience

Incident Response Plan

A documented process for detecting, escalating, containing, and recovering from security incidents.

A documented process for detecting, escalating, containing, and recovering from security incidents.

Related pages: vCISO, Resources and Blog.

ResilienceIncident Response Plan
Assurance

Internal Audit

An independent review used to test whether policies, controls, and evidence work as intended.

An independent review used to test whether policies, controls, and evidence work as intended.

Related pages: vCISO, Resources and Blog.

AssuranceInternal Audit
ISO

ISMS

An information security management system covering risk, controls, policies, evidence, and improvement.

An ISMS is an information security management system. It brings together risk assessment, policy, control operation, measurement, internal audit, management review, and corrective actions as a repeatable governance cycle.

Why it matters: In ISO 27001 readiness, the value comes from making security decisions in a managed system rather than producing documents only for an audit. An ISMS creates shared ownership across security, legal, HR, product, and leadership teams. It also helps evidence appear during normal work, not only during audit preparation.

ISOISMS
ISO

ISO 27001

An international standard for information security management systems and risk-based control governance.

ISO 27001 describes a risk-based information security management system. It is more than a document set; it covers scope, risk assessment, control ownership, evidence, internal audit, management review, and continual improvement.

Why it matters: B2B buyers, enterprise customers, and investors often ask about ISO 27001 readiness as a signal of security maturity. The standard does not require every company to implement every control in the same way. It expects reasoned decisions based on risk, supported by evidence that shows the operating system is working before an audit or customer review.

ISOISO 27001
ISO

ISO 27002

A guidance standard that explains information security controls used with ISO 27001.

A guidance standard that explains information security controls used with ISO 27001.

Related pages: vCISO, Resources and Blog.

ISOISO 27002
ISO

ISO 27005

An ISO standard focused on information security risk management.

An ISO standard focused on information security risk management.

Related pages: vCISO, Resources and Blog.

ISOISO 27005
AI Governance

ISO 42001

A management system standard for artificial intelligence governance.

A management system standard for artificial intelligence governance.

Related pages: vCISO, Resources and Blog.

AI GovernanceISO 42001
Privacy

KVKK

Turkey’s primary personal data protection law and privacy compliance framework.

KVKK is Turkey’s primary personal data protection law and privacy compliance framework. For companies, it is not only a privacy notice exercise. Processing purposes, controller and processor roles, retention, third-party transfers, and security measures need to work together.

Why it matters: KVKK readiness connects directly with security governance. Access control, logging, data classification, vendor assessment, and incident response all affect personal data risk. Companies working with Turkish customers or operations need a practical way to connect privacy obligations with daily control ownership. This summary is an operational explanation, not legal advice.

PrivacyKVKK
Security Controls

Least Privilege

The principle that users and systems should have only the access needed to perform their role.

The principle that users and systems should have only the access needed to perform their role.

Related pages: vCISO, Resources and Blog.

Security ControlsLeast Privilege
Security Controls

Logging and Monitoring

Collection and review of events to detect issues, support investigations, and prove control operation.

Collection and review of events to detect issues, support investigations, and prove control operation.

Related pages: vCISO, Resources and Blog.

Security ControlsLogging and Monitoring
Security Controls

MFA

Multi-factor authentication requiring more than one factor to verify user identity.

Multi-factor authentication requiring more than one factor to verify user identity.

Related pages: vCISO, Resources and Blog.

Security ControlsMFA
Privacy

PIMS

A privacy information management system for organizing privacy roles, controls, evidence, and accountability.

A privacy information management system for organizing privacy roles, controls, evidence, and accountability.

Related pages: vCISO, Resources and Blog.

PrivacyPIMS
Governance

Policy Exception

A documented, approved deviation from a policy, usually with risk acceptance and an expiry date.

A documented, approved deviation from a policy, usually with risk acceptance and an expiry date.

Related pages: vCISO, Resources and Blog.

GovernancePolicy Exception
Privacy

Privacy by Design

A practice of embedding privacy safeguards into systems and processes from the beginning.

A practice of embedding privacy safeguards into systems and processes from the beginning.

Related pages: vCISO, Resources and Blog.

PrivacyPrivacy by Design
Risk

Residual Risk

The risk that remains after controls and treatment actions are applied.

The risk that remains after controls and treatment actions are applied.

Related pages: vCISO, Resources and Blog.

RiskResidual Risk
Risk

Risk Appetite

The amount and type of risk an organization is willing to accept in pursuit of objectives.

The amount and type of risk an organization is willing to accept in pursuit of objectives.

Related pages: vCISO, Resources and Blog.

RiskRisk Appetite
Risk

Risk Register

A structured record of risks, owners, treatment decisions, controls, and status.

A risk register is a structured record of security and privacy risks, owners, likelihood, impact, treatment decisions, controls, and status. A useful register is not just a list of findings. It records decision history and makes ownership visible.

Why it matters: Executive reporting and audit readiness both require clarity on who owns a risk and what decision has been made. A risk register turns technical findings into business priorities and supports decisions about budget, remediation, acceptance, and sequencing.

RiskRisk Register
Privacy

RoPA

Records of Processing Activities documenting personal data processing purposes, categories, recipients, and retention.

RoPA means Records of Processing Activities. It documents personal data processing purposes, categories, systems, recipients, retention, and other key processing details. It gives privacy and security teams operational visibility into data flows.

Why it matters: Without a processing record, it is difficult to design accurate notices, retention rules, vendor reviews, or security controls. RoPA supports data classification, access control, transfer analysis, and incident response scoping. It is most useful when maintained as a living inventory rather than a one-time spreadsheet.

PrivacyRoPA
Customer Trust

Security Evidence Pack

A reusable set of policies, reports, diagrams, and control evidence used to answer trust requests.

A reusable set of policies, reports, diagrams, and control evidence used to answer trust requests.

Related pages: vCISO, Resources and Blog.

Customer TrustSecurity Evidence Pack
Customer Trust

Security Questionnaire

A customer or buyer assessment of a vendor’s security controls and evidence.

A security questionnaire is a customer or buyer assessment of a vendor’s controls and evidence. It commonly covers access management, encryption, logging, incident response, business continuity, vendor management, privacy, and audit readiness.

Why it matters: In enterprise sales, weak or inconsistent questionnaire answers can slow the buying process. A maintained evidence pack, approved answer base, and clear control ownership model help teams respond faster and more accurately. The goal is not to say yes to every question, but to explain the current control position clearly.

Customer TrustSecurity Questionnaire
Assurance

SOC 2

An attestation reporting framework for service organizations based on Trust Services Criteria.

SOC 2 is an attestation reporting approach used by service organizations to explain controls related to security, availability, confidentiality, processing integrity, and privacy. It is not the same as an ISO-style certificate. Scope, report period, control design, and selected criteria matter.

Why it matters: SaaS and technology companies often use SOC 2 reports when enterprise customers request assurance evidence. Readiness work helps teams define control owners, evidence sources, exception handling, and reusable answer bases for security questionnaires. The goal is not to overpromise compliance, but to make control operation easier to explain and verify.

AssuranceSOC 2
ISO

Statement of Applicability

An ISO 27001 document explaining which controls apply, which do not, and why.

The Statement of Applicability is an ISO 27001 document explaining which controls apply, which do not, and why. It connects scope, risk assessment, control ownership, and implementation status into one decision record.

Why it matters: During audit readiness, the SoA explains why controls were selected or excluded and how their implementation is tracked. If it is not maintained, the document can drift away from operational reality. It should therefore be managed with the risk register, evidence map, and control owner matrix.

ISOStatement of Applicability
Assurance

Trust Services Criteria

The criteria used in SOC 2 reports covering areas such as security, availability, processing integrity, confidentiality, and privacy.

The criteria used in SOC 2 reports covering areas such as security, availability, processing integrity, confidentiality, and privacy.

Related pages: vCISO, Resources and Blog.

AssuranceTrust Services Criteria
vCISO

vCISO

A virtual or fractional executive security leader who guides cyber governance without requiring a full-time CISO.

A virtual or fractional executive security leader who guides cyber governance without requiring a full-time CISO.

Related pages: vCISO, Resources and Blog.

vCISOvCISO
Vendor Risk

Vendor Risk Management

The process of assessing and monitoring security, privacy, resilience, and compliance risks from vendors.

Vendor risk management is the process of assessing and monitoring security, privacy, resilience, and compliance risks from external providers. It should include criticality, due diligence, contract expectations, evidence review, ongoing monitoring, and incident communication.

Why it matters: Cloud platforms, SaaS tools, consultants, and AI providers are part of normal business operations. Risk therefore extends beyond the company boundary. A clear program helps show which vendors are critical, which controls are evidenced, and who accepts residual risk when gaps remain.

Vendor RiskVendor Risk Management