Governance Glossary

Browse 119 governance terms defined in plain English, from the cultural dictionary of computing.

119 Governance Terms

Advisory Board
A group of advisors who provide strategic guidance, introductions, or expertise to a company without having the formal authority of a board of directors. In...
AI Act
The European Union's legal framework for regulating AI systems based on risk and use case. It influences how models are trained, evaluated, or served, and it...
AI Alignment Problem
The challenge of ensuring advanced AI systems reliably pursue human goals, values, and constraints. It influences how models are trained, evaluated, or served,...
AI Audit
A structured review of an AI system's behavior, data use, controls, and outcomes to assess risk, compliance, quality, or accountability. AI audits may examine...
AI Compliance
The practice of ensuring AI systems meet applicable legal, policy, contractual, and internal governance requirements. AI compliance work often covers data...
AI Ethics Board
A formal internal or external group tasked with reviewing AI-related risks, policies, and ethical concerns around deployment.
AI Model Card
A documentation artifact describing a model's purpose, data, metrics, limitations, and intended use. It influences how models are trained, evaluated, or...
AI Privacy
The protection of personal, sensitive, or confidential information when AI systems collect, process, store, or generate data. AI privacy concerns include...
Apache Foundation
A common shorthand for the Apache Software Foundation, the nonprofit that hosts and governs many major open source projects through a community-driven model...
BDFL
Benevolent Dictator For Life — a title given to the founder/leader of an open-source project who retains final decision-making authority. Guido van Rossum held...
Benevolent Dictator
A project leader with final authority over all decisions, trusted by the community to exercise that power wisely. The non-'for-life' variant of BDFL. Works...
Benevolent Dictator For Life
A governance model where one founder or central leader retains final decision authority over a project while generally acting in the project’s long-term...
Board Meeting
A formal meeting where the board reviews company performance, strategy, major decisions, and risks with management. In startups, board meetings often shape...
Board Observer
Someone allowed to attend board meetings and receive materials without holding a formal board seat or voting authority. Observer rights are common in venture...
Board of Directors
The formal governing body responsible for overseeing company leadership, major decisions, and fiduciary obligations to shareholders. Startups often move from...
Board Seat
A formal position on a company's board of directors, usually carrying governance rights, meeting participation, and influence over major decisions. Board seats...
Code Nanny
A joking term for a tool, reviewer, or policy that constantly tells developers what they should and should not do in the code. In engineering slang, code nanny...
Code of Conduct
A document establishing expected behavior standards for participants in an open-source project or community. The Contributor Covenant (2014) became the most...
Code of Conduct Standard
A standard or widely accepted template for defining expected behavior and enforcement norms in open-source or technical communities. In project culture, a code...
Code Patrol
A joking term for people or automation that watch for policy violations, risky changes, or quality problems in code. In engineering slang, code patrol can...
Code Tribunal
A formal or semi-formal group that judges important technical changes, standards, or disputes. In engineering slang, code tribunal can sound reassuringly...
Committer
A contributor with direct rights to commit code or merge changes into a project repository, often reflecting a trusted role in open source governance. In some...
Community Standards
The shared expectations for behavior, contribution, communication, and moderation within a project or ecosystem, often documented through codes of conduct and...
Compliance
Adherence to laws, regulations, standards, and internal policies governing data handling, security, and operations. Common frameworks include SOC 2, GDPR,...
Compliance Automation
Compliance Automation is the use of code, policy engines, and evidence collection workflows to automate compliance checks and reporting. Security teams use it...
Compliance Framework
A structured set of controls, requirements, and guidance used to assess or demonstrate compliance with regulatory, industry, or contractual security...
Consensus Decision
A decision reached through broad agreement rather than unilateral authority or simple majority vote. Consensus decisions can build trust and buy-in, though...
Contributor Covenant
A widely adopted open source code-of-conduct template that projects use to set expectations for respectful behavior and define reporting or enforcement paths....
Contributor License Agreement
A legal agreement contributors sign to grant a project rights to use, relicense, or defend their code contributions.
Core Contributor
A contributor who plays a central sustained role in maintaining or advancing a project, often with elevated trust, review authority, or release...
Core Team
The small group of maintainers or leaders who guide a project’s strategy, make major decisions, and often hold elevated review or release authority. In open...
Cyber Insurance
Cyber Insurance is insurance coverage and underwriting practices related to cyber incidents, recovery costs, and organizational controls. Security teams use it...
Cyber Resilience
Cyber Resilience is the ability of an organization to prepare for, withstand, recover from, and adapt after cyber incidents. Security teams use it to enforce...
DAO
Decentralized autonomous organization — an entity governed by smart contracts and token-holder votes rather than a traditional management structure. Members...
Dark Data
Data that an organization collects, stores, or generates but does not actively use, understand, or manage well. In data culture dark data is often seen as both...
Data Classification
Data Classification is the labeling of information by sensitivity and handling requirements so controls can be applied consistently. Security teams use it to...
Data Contract
A formal agreement between data producers and consumers that defines the schema, semantics, quality expectations, SLAs, and ownership of a data asset. Like API...
Data Governance
The policies, roles, processes, and controls used to manage data quality, access, lineage, retention, and compliance. In data-heavy organizations governance is...
Data Governance Security
The security controls embedded in data governance, including classification, access policy, retention, lineage, and accountability for sensitive data handling....
Data Lineage
The tracking of data's journey from source through transformations to final consumption — which systems produced it, what transformations were applied, and who...
Data Retention Policy
Data Retention Policy is a rule set that defines how long data is kept, when it is archived, and when it must be deleted. Security teams use it to enforce...
Digital Sovereignty
The idea that a country, region, or organization should retain meaningful control over its digital infrastructure, data, platforms, and strategic technology...
Dual-Class Shares
A share structure where different classes carry different voting rights, often letting founders retain outsized control relative to economic ownership. It is...
Eclipse Foundation
A nonprofit foundation that hosts and governs many open source projects, originally centered on the Eclipse IDE ecosystem but now spanning cloud, IoT, tooling,...
Enterprise Architecture
The high-level structure and governance of systems, processes, and technology across a large organization. In workplace culture enterprise architecture can be...
Forking Etiquette
The social norms around when and how to fork a project, including communication with maintainers, naming, attribution, and whether a fork is a hostile split or...
Founder Vesting
A vesting arrangement applied to founders' equity so ownership is earned over time rather than fully guaranteed from day one. It protects the company if a...
Governance Model
The structure by which a project decides who has authority, how decisions are made, how roles are granted, and how disputes are resolved. In open source,...
Governance Risk Compliance
The discipline of aligning security governance, risk assessment, control ownership, and compliance obligations into a coordinated management program....
GRC
Short for governance, risk, and compliance, the organizational framework used to manage policies, control requirements, audits, and risk decisions in a...
hard fork (blockchain)
A backward-incompatible change to a blockchain's protocol that permanently splits the network into two separate chains. Nodes that don't upgrade follow the old...
Identity and Access Management
Identity and Access Management is the set of processes and systems used to govern identities, roles, authentication, and authorization. Security teams use it...
Identity Governance
The policies, processes, and controls used to manage who should have access to what, who approves it, how it is reviewed, and how it is removed. Identity...
Independent Board Member
A board member who is not part of management and is not primarily there to represent a major investor, intended to provide independent judgment and oversight....
Information Assurance
A broad discipline focused on ensuring information remains trustworthy, available, protected, and properly managed throughout its lifecycle. It is often...
Information Rights
Contractual rights allowing investors or certain shareholders to receive financial statements, reports, and other company information on an ongoing basis....
Information Security
Information Security is the discipline of protecting confidentiality, integrity, and availability across information systems and data. Security teams use it to...
Internal Audit
An audit conducted by an organization's own internal audit function to evaluate whether controls, processes, and risk management practices are designed and...
Investment Committee
The group within an investment firm that reviews and approves potential deals before capital is committed. Getting through the investment committee is often...
IT Asset Management
The process of tracking and managing hardware, software, cloud resources, and related ownership or lifecycle data across an organization. In security, IT asset...
IT Governance
The structures and decision processes used to ensure technology investments, risks, policies, and operations are aligned with organizational goals and...
Java Community Process
The formal process used to propose and standardize changes in the Java ecosystem through Java Specification Requests and related governance mechanisms. In...
Just-in-Time Access
Just-in-Time Access is privileged access granted only when needed and usually for a limited duration with approval or audit controls. Security teams use it to...
Key Ceremony
Key Ceremony is a formal process for generating and handling high-value cryptographic keys under strict procedural controls. Security teams use it to enforce...
Key Custodian
A person or role formally responsible for safeguarding cryptographic keys or key material and enforcing the procedures around their handling. Key custodians...
Key Escrow
Key Escrow is an arrangement in which decryption keys are held by a trusted third party under defined recovery conditions. Security teams use it to enforce...
Linux Foundation
A nonprofit consortium that supports Linux and many related open source projects through governance, events, legal infrastructure, and ecosystem coordination....
Multi-Cloud Security
The protection of workloads, identities, networks, and data spread across more than one cloud provider. Multi-cloud security is difficult because each platform...
Open Container Initiative
The standards body that maintains widely used specifications for container images and runtimes.
Open Governance
A governance approach where decisions, roles, roadmaps, and processes are visible and participatory rather than concentrated behind closed doors. In open...
Open Source Community
The people and social structures around an open source project or ecosystem, including maintainers, contributors, users, sponsors, and moderators. It is often...
Open Source Governance
The rules and decision-making structures that determine how an open source project sets direction, grants authority, resolves disputes, and manages...
Open Source Initiative
The nonprofit organization that stewards the Open Source Definition and approves licenses as open source under that framework. The OSI plays a central role in...
Open Source Maintainer
A person responsible for reviewing contributions, making release decisions, handling issues, and guiding the direction of an open source project. Maintainers...
Operational Security
Operational Security is the practice of protecting sensitive activities, plans, and capabilities from observation or inference. Security teams use it to...
OSPO
Short for Open Source Program Office, an internal team or function that coordinates a company’s open source strategy, compliance, contributions, policies, and...
Owner
The person, team, or role formally accountable for a system, dataset, control, or risk decision. In security governance, assigning a clear owner is essential...
PII Detection
PII Detection is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
Policy Compliance
The state of systems, users, or processes adhering to an organization's defined security policies and standards. Policy compliance is broader than passing an...
Policy Enforcement
The technical and procedural actions used to ensure defined security policies are actually applied rather than merely documented. Policy enforcement can...
Policy Violation
An action or condition that conflicts with an organization's defined rules, standards, or security requirements. Policy violations may be accidental,...
Privacy
The discipline of controlling how personal or sensitive information is collected, used, shared, stored, and deleted in accordance with expectations, rights,...
Program Security
The overall security of a defined program, initiative, or managed set of activities, including its governance, staffing, controls, objectives, and measurement....
Project Charter
A document describing a project's purpose, scope, principles, or governance expectations. In open-source and organizational culture, a project charter helps...
Project Governance
The framework that defines how a project is run, including roles, voting or decision methods, release authority, conflict resolution, and succession. In open...
Public Benefit Corporation
A legal corporate form that allows a company to pursue specified public benefits alongside shareholder value rather than treating profit maximization as the...
Public Company
A company whose shares are publicly traded and therefore subject to exchange rules, market scrutiny, and extensive disclosure obligations. Becoming a public...
Regulation
A binding rule or set of rules issued by a government or regulator that organizations must follow in specific contexts such as privacy, critical...
Repository Insights
Metrics or dashboards that show repository activity, contribution patterns, issues, pull requests, and other operational signals. In team settings, repository...
Responsible AI
Responsible AI is an AI or ML concept used to represent, train, evaluate, or deploy learned systems. It is commonly used for building production models and...
Review
A structured examination of a system, process, design, or incident to evaluate quality, correctness, compliance, or risk. In security work, reviews range from...
RFC Process
A structured process for proposing and discussing significant changes to a project. Authors write a detailed proposal (motivation, detailed design,...
Risk Acceptance
A formal decision to tolerate a known security risk without fully remediating it, usually because the cost, feasibility, or business tradeoff makes immediate...
Risk Appetite
The amount and type of risk an organization is willing to tolerate in pursuit of its objectives. In security governance, risk appetite shapes how aggressive...
Risk Category
A grouping used to classify risks by type, such as operational, privacy, compliance, third-party, insider, or availability risk. Risk categories help...
Risk Communication
The practice of explaining security risk clearly to the people who need to understand, own, or act on it, such as engineers, leaders, auditors, or customers....
Risk Framework
A structured model for identifying, evaluating, treating, and tracking risk across an organization. Risk frameworks provide common terminology, roles, scoring...
Risk Management
The ongoing process of identifying, analyzing, prioritizing, treating, and monitoring risks so security decisions align with business realities and threat...
Risk Monitoring
The ongoing tracking of risk conditions, control effectiveness, threat changes, and remediation progress over time. Risk monitoring matters because a decision...
Risk Owner
The person or role accountable for deciding how a specific risk will be handled and for accepting the consequences of that decision. A risk owner is not always...
Risk Statement
A concise written description of a risk that explains the condition, the potential event, and the likely impact if it occurs. Strong risk statements are...
Risk Strategy
An organization's overall approach to identifying, prioritizing, and handling risk in line with its objectives, constraints, and tolerance levels. A risk...
Risk Threshold
A defined level of risk above which action, escalation, or executive approval is required and below which a risk may be tolerated or handled routinely. Risk...
Role Separation
The deliberate division of responsibilities and permissions across different roles so no single person or system can complete a sensitive workflow alone. Role...
Safety Classifier
Safety Classifier is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI...
Safety Filter
Safety Filter is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
Shadow Board
An informal or parallel advisory group that provides perspective and challenge to leadership without replacing the formal board of directors. Companies...
soft fork (blockchain)
A backward-compatible change to a blockchain's protocol where old nodes can still validate new blocks, even if they don't understand the new rules. Unlike a...
SOX Compliance
Conformance with Sarbanes-Oxley control and reporting requirements for public companies and their financial systems. It shows up in application security,...
Stage Gate
A decision checkpoint that work must pass before moving from one phase to the next, often used in product development, procurement, or governance-heavy...
Sunlight Test
An informal check of whether a decision, design, or behavior would still seem acceptable if exposed to public or wider internal scrutiny. The metaphor comes...
Super Alignment
Super Alignment is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
System Card
A document that describes an AI system's purpose, capabilities, limitations, risks, and evaluation results so stakeholders can understand how it should be...
Technical Steering Committee
A formal governing body in a project or foundation that makes or approves technical direction decisions, often abbreviated TSC. It is commonly used in larger...
The Apache Way
The community and governance philosophy associated with the Apache Software Foundation, emphasizing consensus, community over code, meritocratic contribution,...
Training Data Licensing
The legal and contractual framework governing whether data can be used to train or fine-tune AI models.
Value Alignment
Value Alignment is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
WG
Short for working group, a temporary or standing team focused on a specific technical area, proposal, or governance problem. The abbreviation is common in...
Working Group
A group formed to work on a specific technical, organizational, or policy area within a larger project, foundation, or standards process. Working groups allow...

Related Topics