Compliance glossary
Plain-English definitions of the compliance, audit and information-security terms behind ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF and AI governance — written so you (and your auditor) know exactly what each one means.
Looking for a framework overview instead? See our framework guides.
Why this vocabulary matters
Compliance has a language of its own. The same word can carry a precise, specific meaning in ISO 27001, SOC 2, HIPAA, or the GDPR. A risk assessment, a control, and an audit each mean something exact that auditors and enterprise buyers expect you to use correctly. This glossary defines those terms in plain English. The goal is simple: you can read a standard, answer a security questionnaire, or talk to an auditor without guessing what a word means.
Clear definitions also matter for AI search. When someone asks an assistant what a Statement of Applicability is, or what a BAA covers, the engine looks for a short, accurate, self-contained answer to cite. Each entry here is written to be exactly that. It leads with a direct definition, then adds the context that makes the term useful.
How the glossary is organized
The terms are grouped into categories, from core concepts that recur everywhere to vocabulary specific to a single framework. Each definition links to the related terms around it, so you can follow a thread — for example, from a risk assessment to a risk register to a risk treatment plan. Where a term maps to a framework we cover, the page also points to the relevant guide and the editable policy templates.
We keep the glossary focused on component concepts, such as an ISMS, a Statement of Applicability, a BAA, or a DPIA. For an overview of a whole framework, start with the framework guides instead.
How to use it
Use the glossary in three ways. Look up a term you have hit in a standard, a contract, or a questionnaire. Browse a category to learn the vocabulary of a framework before you start. Or follow the related-term links to see how the parts of a compliance program fit together. Every definition is free to read, with no sign-up.
When a term sends you toward building the actual document, the toolkits provide editable, framework-aligned templates you can tailor. The glossary explains the concept; the toolkit gives you the starting draft. Neither replaces operating the controls, which is what compliance ultimately requires.
Core concepts
Foundational terms that recur across every framework — risk, controls, scope, and the assessments that tie them together.
Security operations
The day-to-day practices that keep data safe: access control, monitoring, incident response, and recovery.
Audit & certification
How independent assurance works — the audits, reports, and evidence that turn a program into a certificate or attestation.
ISO 27001 & 42001
Terms specific to the ISO management-system standards for information security (27001) and AI (42001).
SOC 2
The vocabulary of a SOC 2 examination — the Trust Services Criteria, report types, and the CPA attestation.
HIPAA
Key terms from the HIPAA Privacy and Security Rules for protecting health information.
GDPR & Privacy
Data-protection terms under the GDPR and related privacy laws — roles, records, and data-subject rights.
AI governance & NIST CSF
Terms for governing AI systems and managing cybersecurity risk under the NIST frameworks.
