Compliance Glossary

Browse 61 compliance terms defined in plain English, from the cultural dictionary of computing.

61 Compliance Terms

AI Audit
A structured review of an AI system's behavior, data use, controls, and outcomes to assess risk, compliance, quality, or accountability. AI audits may examine...
AI Compliance
The practice of ensuring AI systems meet applicable legal, policy, contractual, and internal governance requirements. AI compliance work often covers data...
Audit Log
An append-only, tamper-evident record of security-relevant events — such as logins, permission changes, and data access — that provides an immutable trail for...
Audit Trail
Audit Trail is a chronological record of administrative and system actions that supports accountability, investigation, and compliance review. Security teams...
Chain of Custody
Chain of Custody is the documented handling history that shows who collected, transferred, stored, and analyzed digital evidence. Security teams use it to...
CMMC
Cybersecurity Maturity Model Certification, the U.S. Department of Defense framework used to assess and require cybersecurity practices for contractors...
Compliance Automation
Compliance Automation is the use of code, policy engines, and evidence collection workflows to automate compliance checks and reporting. Security teams use it...
Compliance Framework
A structured set of controls, requirements, and guidance used to assess or demonstrate compliance with regulatory, industry, or contractual security...
Continuous Monitoring
An ongoing process of collecting and reviewing security-relevant signals so issues can be detected, assessed, and acted on as environments change. Continuous...
Credential Rotation
The practice of periodically replacing secrets (API keys, database passwords, certificates) with new ones and invalidating the old. Limits the blast radius of...
Cyber Insurance
Cyber Insurance is insurance coverage and underwriting practices related to cyber incidents, recovery costs, and organizational controls. Security teams use it...
Data Anonymization
The process of altering data so individuals can no longer be identified from it, directly or through practical linkage attacks. Strong anonymization is hard...
Data Classification
Data Classification is the labeling of information by sensitivity and handling requirements so controls can be applied consistently. Security teams use it to...
Data Privacy
The discipline of controlling how personal or sensitive data is collected, used, shared, retained, and deleted in line with expectations, law, and policy. It...
Data Protection
The combined technical, administrative, and legal measures used to keep sensitive data confidential, accurate, available, and appropriately handled. It spans...
Data Residency
The requirement or policy that certain data be stored and sometimes processed within a particular geographic region or legal jurisdiction. Data residency...
Data Retention Policy
Data Retention Policy is a rule set that defines how long data is kept, when it is archived, and when it must be deleted. Security teams use it to enforce...
Data Sovereignty
The principle that data is subject to the laws and authority of the country where it is collected, stored, or processed, including possible government access...
Federal Compliance
Adherence to security, privacy, and operational requirements imposed by federal laws, regulations, or agency frameworks. In practice this often means aligning...
GLBA
Short for the Gramm-Leach-Bliley Act, a US law that imposes privacy and information-security obligations on financial institutions handling consumer financial...
Governance Risk Compliance
The discipline of aligning security governance, risk assessment, control ownership, and compliance obligations into a coordinated management program....
GPL Compliance
The practice of meeting the obligations of GPL-licensed software, such as providing corresponding source code, preserving notices, and honoring redistribution...
GRC
Short for governance, risk, and compliance, the organizational framework used to manage policies, control requirements, audits, and risk decisions in a...
HIPAA
The Health Insurance Portability and Accountability Act — a US federal law that sets standards for protecting sensitive patient health information (PHI). In...
Industry Standard
A widely accepted technical or operational practice, control set, or specification used across an industry as a baseline for security or interoperability....
ISO
The International Organization for Standardization — an independent body that publishes technical standards. In tech, 'ISO' commonly refers to ISO disk image...
ISO 27001
The international standard that defines requirements for establishing, maintaining, and improving an information security management system. Organizations...
ISO 27002
A companion international standard that provides guidance on information security controls supporting an ISO 27001-style management system. Where ISO 27001...
IT Audit
A review of information technology processes, systems, and controls to evaluate whether they are secure, reliable, and aligned with policy or regulatory...
License Audit
A review of project dependencies, source files, and distributions to verify which licenses apply and whether obligations are being met. In open-source culture,...
License Checker
A tool used to inspect dependencies or source artifacts and report their licenses, compatibility, or compliance risks. In engineering practice, license...
License Compatibility
The question of whether software under different licenses can be combined, linked, redistributed, or embedded together without violating any of their terms. It...
License Compliance
The practice of ensuring that all open-source dependencies in a project comply with their license terms. Copyleft licenses (GPL, AGPL) require derivative works...
License Header
A notice placed at the top of a source file indicating copyright ownership and the terms under which the file is licensed. License headers are used to preserve...
License Scanning
The automated detection and analysis of software licenses in source code, dependencies, and packaged artifacts to support compliance and procurement decisions....
Log Management
Log Management is the collection, retention, parsing, storage, and analysis of logs for operations and security use. Security teams use it to enforce trust,...
Log Retention
The policy and practice of keeping logs for a defined period to support investigations, compliance, operational review, or legal obligations. Too little...
Mobile Device Management
Mobile Device Management is centralized policy and lifecycle control for mobile devices, applications, compliance posture, and remote actions. Security teams...
Patch Compliance
The state of systems meeting defined patching requirements, such as being up to date within a policy window for critical, high, or standard updates. Patch...
PCI
In security and compliance contexts, shorthand for the payment card industry environment and its associated security requirements for handling cardholder data....
PCI DSS
The Payment Card Industry Data Security Standard, a compliance framework for protecting cardholder data. It shows up in application security, identity,...
PCIDSS
Short for Payment Card Industry Data Security Standard, the control framework that organizations handling payment card data must follow to protect cardholder...
PII
Short for personally identifiable information, data that can identify, contact, or distinguish a specific individual directly or when combined with other...
Policy as Code
The practice of expressing security or compliance rules in machine-readable policies that can be tested and enforced automatically. It shows up in application...
Policy Compliance
The state of systems, users, or processes adhering to an organization's defined security policies and standards. Policy compliance is broader than passing an...
Policy Violation
An action or condition that conflicts with an organization's defined rules, standards, or security requirements. Policy violations may be accidental,...
Privacy Policy
A published statement describing what personal data an organization collects, how it uses that data, who it shares it with, and what choices or rights users...
Protected Health Information
Health-related information linked to an identifiable individual and protected under regulations such as HIPAA in the United States. Protected health...
Questionnaire
A structured set of questions used to gather information about a vendor's, product's, or internal system's security controls, practices, and compliance status....
Region
A geographic area containing multiple availability zones where cloud resources can be deployed. Choosing regions affects latency (closer to users = faster),...
Regulation
A binding rule or set of rules issued by a government or regulator that organizations must follow in specific contexts such as privacy, critical...
Regulatory Compliance
Adherence to laws, regulations, and mandatory standards that govern how an organization handles security, privacy, reporting, and operations. Regulatory...
Regulatory Risk
The risk that laws, regulation, enforcement actions, or licensing requirements will materially hurt the business model or growth path. Regulatory risk is...
Repository License
The software license declared for a repository, usually through a license file and related metadata. In open-source practice, the repository license determines...
Revenue Recognition
The accounting process of determining when revenue is officially recorded as earned rather than just when cash is received. In subscription and services...
SBOM
Software Bill of Materials — a complete inventory of all components, libraries, and dependencies in a software application, including their versions and...
SOC 2
A compliance framework developed by AICPA that evaluates an organization's controls for Security, Availability, Processing Integrity, Confidentiality, and...
Source Code License
The license governing how source code may be used, modified, and redistributed. In legal and engineering practice, the source code license determines what...
SOX Compliance
Conformance with Sarbanes-Oxley control and reporting requirements for public companies and their financial systems. It shows up in application security,...
WCAG
Web Content Accessibility Guidelines — the international standard for web accessibility published by W3C. Organized around four principles: Perceivable,...
WORM Storage
Write-once, read-many storage that prevents later modification or deletion of retained data. It shows up in application security, identity, infrastructure, or...

Related Topics