Compliance Glossary
AICPA
AICPA standards for the American Institute of Certified Public Accountants (AICPA) who created the Service Organizational Controls standard. It is the largest organization of accountants in the United States.Â
Learn moreAccess Control
Access control is an essential aspect of security management and is used to protect resources, prevent unauthorized access, and ensure compliance.
Learn moreAnnex A Controls
Annex A is part of the ISO 27001 standard document. It outlines all ISO 27001 controls and groups them into categories.
Learn moreApproved Publishing Partner (APP)
An Approved Publishing Partners (APP), formerly known as a Licensed Publishing Partner (LPP), is an organization approved by the CAICO to develop the CMMC certification curriculum for Approved Training Providers (ATPs).
Learn moreApproved Training Provider (ATP)
An Approved Training Provider (ATP), formerly known as a Licensed Training Provider (LTP), is an organization authorized by CAICO to develop and deliver official CMMC training courses.
Learn moreAuditor
An auditor is an accounting firm hired by a company to assess whether it meets a compliance standard such as SOC 2 or ISO 27001. Compliance standards require companies to implement a long list of security controls.
Learn moreBridge Letter
A SOC 2 bridge letter is a document that provides information about the controls and systems of a service organization for a period of time that is not covered by a previously issued SOC 2 report.
Learn moreBusiness Associate (HIPAA)
A HIPAA business associate is a person or organization that provides certain services or functions that involve access to protected health information (PHI) on behalf of a covered entity.
Learn moreBusiness Associate Agreement (HIPAA)
A HIPAA business associate is a person or organization that provides certain services or functions that involve access to protected health information (PHI) on behalf of a covered entity.
Learn moreCAGE Code
A Commercial and Government Entity (CAGE) code is a five-character alpha-numeric identifier assigned to entities located in the United States and its territories in order to support a variety of procurement and acquisition processes throughout the US government.
Learn moreCCPA
The California Consumer Privacy Act (CCPA) declares that companies must inform consumers about how their data is being used and empowers consumers to decide how or if their data is shared.Â
Learn moreCMMC Assessment Process (CAP)
The CMMC Assessment Process (CAP) is the procedural document C3PAOs follow when conducting an official CMMC assessment. Published by the Cyber AB and reviewed by the CMMC PMO, it defines the phases, evidence expectations, scoring rules, and reporting requirements. If you want to know what a C3PAO is actually doing during your assessment, the CAP is the answer.
Learn moreCMMC Enclave (CUI Enclave)
A CMMC enclave is a scoped segment of your IT environment dedicated to handling CUI. Instead of applying 110 NIST 800-171 practices across the whole company, you build a bounded network with specific workstations, storage, and users, and CMMC assessment applies only there. This is the usual strategy for managing CMMC cost and complexity.
Learn moreCMMC Program Management Office (PMO)
The CMMC Program Management Office (PMO), under the authority of the DoD Chief Information Officer (CIO), oversees the implementation and effectiveness of the CMMC program.
Learn moreCardholder Data
The Payment Card Industry Security Standards Council (PCI SSC) established what cardholder data must be protected under PCI DSS.
Learn moreCertified CMMC Assessor (CCA)
A Certified CMMC Assessor (CCA) is an individual credentialed to lead and conduct official CMMC Level 2 assessments on behalf of a CMMC Third-Party Assessment Organization (C3PAO).
Learn moreCertified CMMC Instructor (CCI)
A Certified CMMC Instructor (CCI) is an individual accredited by The Cyber AB to develop CMMC Approved Training Materials (CATM) curriculum with Approved Publishing Partners (APPs) or deliver official CMMC training courses through a Licensed Training Provider (LTP).Â
Learn moreCertified CMMC Professional (CCP)
A Certified CMMC Professional (CCP) is an individual who is authorized to assess, examine, verify, and review an organization for CMMC compliance but they cannot make any final determinations.
Learn moreCertified Third-Party Assessment Organization (C3PAO)
A Certified Third-Party Assessment Organization (C3PAO) is an independent organization accredited by the Cyber AB (formerly the CMMC Accreditation Body) to conduct official CMMC assessments on defense contractors seeking certification. C3PAOs evaluate whether an Organization Seeking Certification (OSC) has properly implemented the security practices required at their target CMMC level.
Learn moreCloud Compliance
Cloud compliance refers to the set of rules and regulations that govern the use of cloud computing services.
Learn moreCloud Service Provider (CSP)
A Cloud Service Provider (CSP), as defined in the CMMC Final Rule (32 CFR Part 170.4), is a third-party entity that provides cloud services based on cloud computing.
Learn moreCompliance Risk Management
Compliance risk management is an organization’s process for regularly identifying, analyzing, and mitigating risks. In the context of SOC 2 and ISO 27001, risk management refers to security and compliance risk management, meaning you’ll want to understand risks to sector and geography specific regulation and compliance standards.
Learn moreCompliance Software
Compliance software is a software tool an organization can use to scan and monitor its vendors, systems, and controls to ensure they are compliant with certain security standards or regulations. Compliance software can be part of an organization's compliance risk management strategy to continuously track, monitor, and remediate any compliance risks that would jeopardize an organization's ability to stay compliant with relevant security standards and regulations.
Learn moreContinuous Integration (CI) and Continuous Delivery (CD)
Continuous Integration (CI) and Continuous Delivery (CD) are practices in software engineering for improving the development process through automation and streamlined workflows.
Learn moreContinuous Monitoring
Continuous monitoring is an ongoing process of assessing and managing your security posture by tracking system changes, analyzing vulnerabilities, and evaluating compliance with security requirements.Â
Learn moreControl
A control is a specific rule or safeguard used to improve a company’s security and compliance. Common types of safeguards include management, physical, legal, operational, and technical controls.
Learn moreControl Family
A control family is a group of related security controls categorized by function and purpose.
Learn moreControlled Technical Information (CTI)
Controlled Technical Information is a CUI category for technical data with military or space application. Engineering drawings, specifications, performance parameters, test data, source code for weapons systems. CTI is identified by Distribution Statements B through F (per DoD Instruction 5230.24). If your contract involves CTI, you are handling CUI, which means CMMC Level 2 and DFARS 252.204-7012 apply.
Learn moreControlled Unclassified Information (CUI)
Controlled Unclassified Information is non-classified information that a law, regulation, or government-wide policy says must be safeguarded. Created by Executive Order 13556 in 2010 and standardized under 32 CFR Part 2002. CUI replaced the pre-2010 patchwork of agency-specific markings like 'For Official Use Only' and 'Sensitive But Unclassified.' For defense contractors, CUI is what triggers CMMC Level 2 and NIST SP 800-171.
Learn moreCovered Defense Information (CDI)
Covered Defense Information is the DFARS 252.204-7012 term for unclassified information that requires safeguarding. In practice, CDI means Controlled Unclassified Information (CUI) used in DoD contracts. It is what triggers NIST SP 800-171 implementation and CMMC Level 2 scope. If your contract says 252.204-7012 and identifies CDI, you are handling CUI.
Learn moreCybersecurity
Cybersecurity is the body of technologies, processes, and practices designed to protect data, information, programs, systems, networks, and devices from digital attacks from unauthorized users on the internet.Â
Learn moreCybersecurity Assessor and Instructor Certification Organization (CAICO)
The Cybersecurity Assessor and Instructor Certification Organization (CAICO) is the organization responsible for training, testing, authorizing, certifying, and recertifying assessors, instructors, and professionals within the CMMC Ecosystem.
Learn moreCybersecurity Maturity Model Certification (CMMC)
The Cybersecurity Maturity Model Certification (CMMC) is a cybersecurity framework developed by the U.S. Department of Defense to verify that defense contractors and subcontractors meet required security standards for protecting sensitive government information. CMMC replaces self-attestation with additional verification layers, requiring contractors to achieve a CMMC status in SPRS at the appropriate level before being awarded DoD contracts involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Learn moreDFARS (Defense Federal Acquisition Regulation Supplement)
DFARS supplements the Federal Acquisition Regulation (FAR) with rules specific to Department of Defense contracts. For contractors, the cybersecurity clauses matter most: 252.204-7012 (protect CUI using NIST SP 800-171), 252.204-7019 and 7020 (report and score NIST 800-171 implementation to SPRS), and 252.204-7021 (achieve CMMC certification before award).
Learn moreDIBCAC (Defense Industrial Base Cybersecurity Assessment Center)
DIBCAC is part of the Defense Contract Management Agency (DCMA). It runs the Medium and High NIST SP 800-171 assessments defined in DFARS 252.204-7020. DIBCAC can show up for a few reasons: your contract picked you, you are a prime supporting a major program, or you passed DIBCAC's trigger criteria. Assessment results land in SPRS and contracting officers can see them.
Learn moreData Breach
A data breach is a security incident in which sensitive, confidential, or protected information is accessed, stolen, or disclosed by an unauthorized individual or entity.
Learn moreData Integrity
Data integrity refers to the accuracy, consistency, and reliability of data throughout its lifecycle, from creation to deletion.
Learn moreData Loss Prevention (DLP)
Data loss prevention (DLP) is a set of policies and technologies designed to prevent sensitive or confidential information from being lost, stolen, or exposed.
Learn moreData Mining
Data mining is the process of discovering patterns, trends, and insights from large datasets.
Learn moreData Universal Numbering System (DUNS) number
The Data Universal Numbering System (DUNS) number was the authoritative unique entity identifier used by the federal government until April 3, 2022.
Learn moreDefense Industrial Base (DIB)
The Defense Industrial Base is the set of organizations that produce, maintain, and support the materials, components, and services the DoD buys. Over 300,000 companies are in the DIB, from Lockheed Martin to two-person machine shops. The DIB is one of 16 critical infrastructure sectors recognized under Presidential Policy Directive 21. DoD is the sector-specific agency. The cybersecurity program for the DIB is coordinated through the DIB-CS Program.
Learn moreDefense Innovation Unit (DIU)
The Defense Innovation Unit (DIU) is an organization within the United States Department of Defense (DoD) that works to strengthen national security by increasing the military's adoption of innovative commercial technology.
Learn moreDepartment of Defense Information Network (DoDIN)
The Department of Defense Information Network (DoDIN) is a global set of information capabilities, processes, and personnel for collecting, processing, storing, disseminating, and managing information on demand to warfighters, policymakers, and support personnel.
Learn moreDevSecOps
DevSecOps integrates security practices within the DevOps process.
Learn moreDoD (Department of Defense)
The Department of Defense is the federal agency responsible for U.S. military operations. For contractors, the DoD is the counterparty on contracts, the author of DFARS, the owner of CMMC, and the operator of SPRS. Cybersecurity oversight sits across several DoD components: the DoD CIO sets policy, DIBCAC (under DCMA) conducts assessments, the CMMC PMO manages the certification program, and DC3 handles incident response coordination.
Learn moreDoD Assessment Methodology
The DoD Assessment Methodology is the scoring rulebook for NIST SP 800-171 self-assessments under DFARS 252.204-7019. Documented in Version 1.2.1 (June 24, 2020), it produces a score from -203 (nothing implemented) to 110 (everything implemented). The score goes into SPRS. Contracting officers look at it. Misrepresenting it is how companies end up in False Claims Act cases.
Learn moreDue Diligence Questionnaire (DDQ)
A Due Diligence Questionnaire is a comprehensive questionnaire used to assess a company's business operations, financial performance, legal and regulatory compliance, and other key areas.
Learn moreExternal Service Provider (ESP)
An External Service Provider (ESP) is a third-party entity that processes, stores, or transmits FCI, CUI, or SPD in its provision or management of IT and/or cybersecurity services to an organization seeking to undergo a CMMC assessment.Â
Learn moreFAR (Federal Acquisition Regulation)
The Federal Acquisition Regulation is the rulebook for how every federal executive branch agency buys goods and services with appropriated funds. Codified in Title 48 CFR. Jointly maintained by DoD, GSA, and NASA. DFARS adds DoD-specific rules on top of the FAR. If you're a defense contractor, you read both.
Learn moreFIPS (Federal Information Processing Standards)
FIPS are mandatory NIST-issued standards that federal agencies and their contractors must follow. For defense and cloud compliance, the standards you will actually encounter are FIPS 140-2 and FIPS 140-3 (cryptographic module validation) and FIPS 199 (security categorization). FIPS 140-3 took effect September 2019. NIST stopped accepting new FIPS 140-2 validations in April 2022.
Learn moreFedRAMP 20x
FedRAMP 20x is the latest major iteration of the FedRAMP program designed to accelerate FedRAMP authorization processes by streamlining cloud security approvals and reducing the time it takes for cloud service providers (CSPs) to achieve authorization.
Learn moreFedRAMP 20x Community Working Groups
FedRAMP 20x Community Working Groups are collaborative forums where industry stakeholders work together to improve the FedRAMP authorization process.
Learn moreFedRAMP Baselines
FedRAMP baselines are predefined security control requirements that cloud service providers must meet to achieve FedRAMP authorization.
Learn moreFedRAMP Marketplace
The FedRAMP Marketplace at marketplace.fedramp.gov is the official directory of cloud services that have been authorized, are actively pursuing authorization, or have been designated as FedRAMP Ready. Federal agencies use the Marketplace to find authorized cloud services and leverage existing authorizations without duplicating assessments. If you run a cloud service that wants federal business, Marketplace listing is how you become visible to buyers.
Learn moreFedRAMP Project Management Office (PMO)
The FedRAMP Project Management Office (PMO) oversees the FedRAMP program, ensuring consistent implementation of security requirements and supporting cloud service providers and federal agencies through the authorization process.
Learn moreFederal Contract Information (FCI)
Federal Contract Information is non-public information the government provides to a contractor, or that a contractor generates for the government under a contract. It is not CUI. It does not carry a CUI category marking. But it triggers FAR 52.204-21 safeguarding requirements, which CMMC Level 1 adopts as its 15 practices. If your contract involves only FCI (and no CUI), you need CMMC Level 1, not Level 2.
Learn moreFederal Information Processing Standards (FIPS) 140-2
The Federal Information Processing Standards (FIPS) 140-2 is a U.S. government security standard that specifies requirements for cryptographic modules used to protect sensitive data.
Learn moreFederal Information Processing Standards (FIPS) 140-3
The Federal Information Processing Standards (FIPS) 140-3 is the updated version of the U.S. government’s cryptographic module validation standard, replacing FIPS 140-2.
Learn moreFederal Information Security Management Act (FISMA)
The Federal Information Security Management Act is United States legislation that was enacted as part of the Electronic Government Act of 2002.
Learn moreFederal Risk and Authorization Management Program (FedRAMP)
FedRAMP is the government-wide program that standardizes security assessment and authorization for cloud services used by federal agencies. Introduced in 2011, codified into law in December 2022 (FedRAMP Authorization Act, Title 5 Subtitle B of the FY23 NDAA). Cloud service providers achieve FedRAMP authorization once, and any federal agency can reuse that authorization. The program is managed by GSA with JAB (Joint Authorization Board) oversight for the highest-visibility authorizations.
Learn moreFirewall
A firewall is a network security device that monitors and controls incoming and outgoing network traffic.
Learn moreGCC High (Government Community Cloud High)
Microsoft GCC High is the Microsoft 365 and Azure Government environment built for U.S. government and defense workloads that handle CUI, ITAR-controlled data, and other sensitive material. It meets FedRAMP High and DoD SRG Impact Level 4 equivalency, sits on physically segregated infrastructure in the continental U.S., and limits access to U.S.-citizen staff. If your contracts involve CUI under DFARS 252.204-7012 and you want to stay in the Microsoft ecosystem, GCC High is the usual answer.
Learn moreGDPR
In May 2018, the European Union implemented the General Data Protection Regulation (GDPR) to create one legal framework for collecting and processing personal information from individuals who live inside the European Economic Area.Â
Learn moreGovernance, Risk, and Compliance (GRC)
Governance, Risk, and Compliance (GRC) is a management framework that organizations use to ensure they are operating in a legal, ethical, and effective manner.
Learn moreHIPAA
Congress passed the Health Insurance Portability and Accountability Act (HIPAA) in 1996 in order to create national standards to protect sensitive patient health data.
Learn moreHIPAA Breach Notification Rule
The HIPAA Breach Notification Rule requires covered entities and their business associates to notify individuals, HHS, and, in some cases, the media when there is a breach of unsecured protected health information (PHI).
Learn moreHIPAA Covered Entity
A covered entity is a healthcare provider, health plan, or healthcare clearinghouse that is subject to the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.
Learn moreHIPAA Employee Training
Healthcare organizations are legally required to have certain administrative safeguards, like employee training, in place to protect patient data against breaches and comply with HIPAA.
Learn moreHIPAA Enforcement Rule
The HIPAA Enforcement Rule governs violation investigations and penalties.
Learn moreHIPAA Omnibus Rule
The HIPAA Breach Notification Rule requires covered entities and their business associates to notify individuals, HHS, and, in some cases, the media when there is a breach of unsecured protected health information (PHI).
Learn moreHIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards for protecting the privacy and security of protected health information.
Learn moreHIPAA Rules
The Health Insurance Portability and Accountability Act (HIPAA) includes a set of rules to help healthcare organizations and their business associates protect the security and confidentiality of sensitive patient data. To become compliant, healthcare organizations must follow five HIPAA rules to safeguard this protected health information (PHI).
Learn moreHIPAA Safeguards
The HIPAA Security Rule outlines three types of safeguards — administrative, physical, and technical — to properly protect PHI.
Learn moreHIPAA Security Rule
The HIPAA Security Rule is a set of regulations issued by the U.S. Department of Health and Human Services (HHS) that establish national standards for protecting electronic personal health information (ePHI).
Learn moreHITECH
The Health Information Technology for Economic and Clinical Health Act (HITECH Act) was enacted under Title XIII of the American Recovery and Reinvestment Act (ARRA) of 2009.
Learn moreISO 27001
The ISO 27001 is a security and compliance standard created jointly by the International Organization for Standardization and the International Electrotechnical Commission.
Learn moreISO 27001 Stage 1 Audit
An ISO 27001 certification audit happens in multiple stages. For organizations pursuing certification for the first time, the audit process begins with a Stage 1 audit, also referred to as an ISMS design review.Â
Learn moreISO 27001 Stage 2 Audit
An ISO 27001 Stage 2 audit is the second part of a two-stage audit process for ISO/IEC 27001 certification
Learn moreISOO (Information Security Oversight Office)
The Information Security Oversight Office sits inside NARA and runs the federal CUI program. Executive Order 13556 (November 2010) created the program. ISOO owns the CUI Registry at archives.gov/cui, publishes 32 CFR Part 2002 (the rule that governs CUI handling), and coordinates with agencies on how CUI is marked, safeguarded, decontrolled, and disposed of.
Learn moreITAR (International Traffic in Arms Regulations)
ITAR controls the export and import of defense articles, services, and technical data on the U.S. Munitions List (USML). Codified in 22 CFR Parts 120-130. Administered by the Directorate of Defense Trade Controls (DDTC) in the State Department. If you manufacture defense articles, provide defense services, or hold ITAR technical data, you need to register with DDTC and apply export controls (including controls on foreign-person access to technical data).
Learn moreImpact Levels
Impact levels are used within certain security frameworks, such as those provided by the United States Department of Defense (DoD), to categorize the potential impact of unauthorized disclosure, alteration, or destruction of information.
Learn moreInformation Security Management System (ISMS)
The ISO 27001 standard evaluates an organization’s information security management system, or ISMS.Â
Learn moreInformation Security Policy
An information security policy is a set of rules and guidelines that define how an organization manages and protects its information assets, including data, systems, and networks.
Learn moreInfrastructure as a Service (IaaS)
The Department of Defense Information Network (DoDIN) is a global set of information capabilities, processes, and personnel for collecting, processing, storing, disseminating, and managing information on demand to warfighters, policymakers, and support personnel.
Learn moreInternal Audit
An internal security audit is an evaluation of an organization's internal security controls, policies, and procedures to assess their effectiveness and identify areas for improvement.
Learn moreInternational Organization for Standardization (ISO)
ISO stands for the International Organization for Standardization, which is a non-governmental organization that develops and publishes international standards for a wide range of industries and sectors.
Learn moreIntrusion Detection System (IDS)
An intrusion detection system (IDS) is a network security technology designed to detect and respond to suspicious or malicious activity on a computer network.
Learn moreIntrusion Prevention System (IPS)
An intrusion detection system (IDS) is a network security technology designed to detect and respond to suspicious or malicious activity on a computer network.
Learn moreJoint Interoperability Test Command (JITC)
The Joint Interoperability Test Command (JITC) is part of the United States Department of Defense.
Learn moreKeylogging
Keylogging is a technique used to capture and record keystrokes made on a keyboard.
Learn moreMalware
Malware, short for malicious software, refers to any software or program that is specifically designed to cause harm, damage, or disruption to computer systems, networks, or mobile devices.
Learn moreManagement Assertion (SOC 2)
A SOC 2 management assertion is a statement made by the management of a service organization that describes the organization's commitment to security, availability, processing integrity, confidentiality, and privacy of customer data.
Learn moreMulti-Factor Authentication (MFA)
Multi-factor authentication (MFA) is a multi-step account login process that requires users to enter two or more pieces of information.
Learn moreNARA (National Archives and Records Administration)
NARA is best known for preserving federal records. For defense contractors, NARA matters because Executive Order 13556 named it the CUI Executive Agent. NARA delegates that authority to its Information Security Oversight Office (ISOO), which runs the CUI program day to day. The CUI Registry, CUI marking standards, and 32 CFR Part 2002 all come from NARA through ISOO.
Learn moreNIST CSF
The NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) is a set of voluntary guidelines, standards, and best practices for managing cybersecurity risks in critical infrastructure organizations.
Learn moreNIST SP 800-171 (Protecting CUI in Nonfederal Systems)
NIST Special Publication 800-171 defines the security requirements that a nonfederal organization must implement when it processes, stores, or transmits Controlled Unclassified Information (CUI) on behalf of the federal government. Rev 2 has 110 requirements across 14 control families. Rev 3 (published May 14, 2024) restructures the document and expands the number of requirements. DFARS 252.204-7012 requires Rev 2. CMMC Level 2 uses Rev 2. Rev 3 will be adopted in future rulemaking.
Learn moreNIST Special Publication 800-53
NIST Special Publication 800-53 is a comprehensive and flexible catalog of security and privacy controls designed to help federal agencies and private sector organizations manage cybersecurity risks and comply with FISMA.
Learn moreNational Institute of Standards and Technology (NIST)
NIST is a non-regulatory agency inside the Department of Commerce. Founded in 1901. For cybersecurity, NIST is the standards body that authors the frameworks and special publications everyone references: SP 800-171 for CUI in nonfederal systems, SP 800-53 for federal system controls, the Cybersecurity Framework (CSF) for voluntary adoption, and SP 800-37 for the Risk Management Framework. When a compliance program points to a control standard, the standard almost always comes from NIST.
Learn moreOIRA (Office of Information and Regulatory Affairs)
OIRA is the division of OMB that reviews significant federal regulations before they are published. Every major cybersecurity rule that affects defense contractors (CMMC, DFARS amendments, the FAR CUI rule) goes through OIRA. Tracking OIRA's review status is one of the best leading indicators for when a compliance requirement will actually hit your contracts.
Learn moreOMB (Office of Management and Budget)
OMB is the Executive Office of the President's budget and regulatory coordinator. On the cybersecurity side, OMB issues binding directives to federal agencies that flow down to contractors. Circular A-130 sets the baseline for managing federal information. Memorandum M-22-09 pushed agencies toward zero trust. OMB also houses OIRA, which reviews every significant federal rule.
Learn moreOn-Premises
"On-premises" (or "On-prem") refers to the location and management of servers, resources, and IT infrastructure.
Learn moreOperational Technology (OT)
Operational technology is the hardware and software that controls physical processes: assembly lines, pumps, turbines, HVAC, weapons platforms. OT differs from IT because downtime can mean physical harm. For defense contractors, OT shows up when manufacturing systems, test stands, or facility controls touch CUI or connect to CUI-handling networks.
Learn moreOrganization Seeking Assessment (OSA)
An Organization Seeking Assessment (OSA) is an entity seeking to undergo a CMMC assessment.
Learn moreOrganization Seeking Certification (OSC)
An Organization Seeking Certification is a defense contractor pursuing CMMC Level 2 or Level 3 certification via a formal third-party (C3PAO) or government (DIBCAC) assessment. The term distinguishes these contractors from OSAs (Organizations Seeking Assessment), which is the broader category that also includes Level 1 self-assessments. When a C3PAO engagement kicks off, you are an OSC from that point until certification is issued or denied.
Learn morePCI Attestation of Compliance (AoC)
An Attestation of Compliance (AoC) is a document that confirms that an organization has undergone a Payment Card Industry Data Security Standard (PCI DSS) assessment and is compliant with the standard.
Learn morePCI DSS
Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards intended to ensure that all companies that process, store, transmit, or impact the security of cardholder data maintain a secure environment.
Learn morePCI DSS Approved Scanning Vendor (ASV)
A PCI DSS Approved Scanning Vendor (ASV) is a company that has been certified by the Payment Card Industry Security Standards Council (PCI SSC) to conduct external vulnerability scans of merchants and service providers that handle payment card data.
Learn morePCI Self-Assessment Questionnaire (SAQ)
A PCI SAQ (Payment Card Industry Self-Assessment Questionnaire) is a tool used by merchants and service providers to assess their compliance with the PCI DSS.
Learn morePatch Management
Patch management is the process of identifying, acquiring, testing, and applying software updates.
Learn morePen Test
A penetration test (or “pen test”) is a simulated attack on an organization’s system and services, often conducted by a white hat or ethical hacker. The SOC 2 and ISO 27001 audits both require a penetration test.Â
Learn morePhishing
Phishing is a type of social engineering attack in which an attacker sends fraudulent emails, text messages, or other electronic communication to individuals, attempting to trick them into revealing sensitive information
Learn morePlan of Action and Milestones (POA&M)
A Plan of Action and Milestones (POA&M) is a structured document used to identify, track, and remediate security weaknesses in an organization’s information systems.
Learn morePlatform as a Service (PaaS)
PaaS, or Platform-as-a-Service, is a cloud computing model that offers organizations a complete cloud platform—hardware, software, and infrastructure—for developing, running, and managing applications without building and maintaining those platforms on-premises.
Learn morePolicy
A policy is a governing document describing what an organization does to ensure security and compliance. It outlines responsibilities and general procedures meant to implement and maintain specific security and compliance controls.
Learn morePrivacy Policy
A privacy policy is an important tool for organizations to communicate with their customers or users about how their personal information is being collected, used, and protected, and to ensure compliance with applicable privacy laws and regulations.
Learn moreProtected Health Information (PHI)
PHI is protected under the Health Insurance Portability and Availability Act (HIPAA), and includes any health data created, transmitted, or stored by a HIPAA-covered entity and its business associates.
Learn moreQualified Security Assessor (QSA)
A Qualified Security Assessor (QSA) is an individual or organization that has been certified by the Payment Card Industry Security Standards Council (PCI SSC) to assess an organization's compliance with the Payment Card Industry Data Security Standard (PCI DSS).
Learn moreRansomware
Ransomware is a type of malicious software that encrypts a victim's files or system, rendering them inaccessible, and then demands a ransom payment in exchange for restoring access.Â
Learn moreRegistered Practitioner (RP)
A Registered Practitioner (RP) is an individual registered with The Cyber AB who is authorized to provide CMMC implementation consulting services to organizations seeking certification (OSCs).
Learn moreRegistered Practitioner Advanced (RPA)
Registered Practitioner Advanced (RPA) is a consultant in the CMMC ecosystem that has completed additional training and experience requirements after becoming a Registered Practitioner (RP).
Learn moreRegistered Practitioner Organization (RPO)
A Registered Practitioner Organization (RPO) is an advisory firm or Managed Service Provider (MSP) registered with The Cyber AB that offers CMMC implementation consulting services.
Learn moreRequest for Information (RFI)
An RFI, or Request for Information, is a standard business process for collecting written information about the capabilities of various suppliers.
Learn moreRequest for Proposal (RFP)
An RFP, or Request for Proposal, is a document that organizations use to solicit proposals from potential vendors or service providers for a specific product or service.
Learn moreRequest for Quotation (RFQ)
A Request for Quotation is a document and process used in procurement where an organization asks vendors or suppliers to provide a quote for the supply of specific products or services.
Learn moreRisk Assessment
A risk assessment is a process that helps organizations identify and evaluate their cybersecurity risks, vulnerabilities, and threats.
Learn moreRisk Management
Risk management is the process of identifying, assessing, and mitigating potential risks to an organization.Â
Learn moreRisk Management Framework (RMF)
The Risk Management Framework is NIST's seven-step process for integrating security, privacy, and supply chain risk management into the system lifecycle. Defined in NIST SP 800-37 Rev 2. It is how federal systems get authorized to operate (ATO). FedRAMP is RMF applied to cloud services. The DoD system authorization process is RMF. If you work with federal systems or FedRAMP-authorized cloud services, you're seeing RMF in action.
Learn moreSOC 1
The Service Organization Control 1 Report (SOC 1) is an auditor report assessing controls for financial reporting. The SOC 1 targets companies providing services that could affect clients’ financial statements or internal controls over financial reporting.Â
Learn moreSOC 2
The Service Organization Control 2 Report (SOC 2) is an auditor report assessing controls for security and compliance. Any company offering a B2B service, along with any B2C company handling sensitive information, should think about getting a SOC 2 report completed.Â
Learn moreSOC 2 Auditor
SOC 2 auditors evaluate how effective your security program is and determine whether your internal controls meet the requirements of your chosen Trust Services Criteria (TSC).Â
Learn moreSOC 2 Report
A SOC 2 report summarizes the results of the compliance audit and the auditor’s findings.
Learn moreSOC 2 Type 1
A SOC 2 Type 1 report examines how well a service organization's system and controls perform over a period of time.
Learn moreSOC 2 Type 2
A SOC 2 Type 2 report examines how well a service organization's system and controls perform over a period of time.
Learn moreSOC 3
The Service Organizational Control 3 Report (SOC 3) is a more concise and high level version of the SOC 2 meant to be released publicly as marketing material.
Learn moreSSAE 16
The Statement on Standards for Attestation Engagements No. 16 (SSAE 16) is a set of standards developed specifically for certified public accountants (CPAs) to evaluate an organization’s internal controls and how service companies report on these controls.
Learn moreSSAE 18
The Statement on Standards for Attestation Engagements No. 18 (SSAE 18) is a new set of standards that have replaced SSAE 16 to help increase the usefulness and quality of a SOC 1 report.
Learn moreSecurity Assessment Plan (SAP)
A Security Assessment Plan (SAP) is developed by a Third-Party Assessment Organization (3PAO) and outlines the specific procedures and methodologies that will be used during the security assessment for FedRAMP authorization.Â
Learn moreSecurity Assessment Report (SAR)
A Security Assessment Report (SAR) is a document prepared by a Third-Party Assessment Organization (3PAO) that details the findings from a security assessment of a cloud service provider.
Learn moreSecurity Questionnaires
A security questionnaire is a list of questions that assess your organization’s security and data privacy practices. Organizations often exchange questionnaires as part of the due diligence process.
Learn moreStandardized Information Gathering (SIG) Questionnaire
The SIG is a comprehensive set of questions used to assess the cybersecurity, IT, data security, and privacy risks and controls of third-party service providers and vendors.
Learn moreStatement of Applicability (ISO 27001)
An ISO 27001 Statement of Applicability (SoA) is a document that identifies the controls that an organization has implemented to address the information security risks it has identified through a risk assessment.
Learn moreSupplier Performance Risk System (SPRS)
SPRS is the DoD's authoritative database for supplier performance and risk information. For cybersecurity, SPRS is where NIST SP 800-171 self-assessment scores live. Contracting officers look at these scores when evaluating proposals. A low score can lose you the award. A knowingly inflated score can land you in False Claims Act litigation. Scores are submitted through the PIEE portal.
Learn moreSupply Chain Risk Management (SCRM)
Supply chain risk management is the work of identifying and mitigating risks introduced by your suppliers, their suppliers, and the components moving through the chain. For defense contractors, the specific form is C-SCRM (cyber supply chain risk management), defined in NIST SP 800-161 Rev 1. CMMC Level 2 includes SCRM practices. DFARS 252.204-7012 pushes cybersecurity requirements down the chain automatically.
Learn moreSystem Description (SOC 2)
A SOC 2 System Description is a narrative description of a service organization's systems, policies, and procedures related to the Trust Services Criteria of security, availability, processing integrity, confidentiality, and privacy.
Learn moreSystem Security Plan (SSP)
A System Security Plan is the document that describes how an organization implements security controls to protect federal information. For defense contractors, the SSP is the primary document a CMMC or DIBCAC assessor reads. It maps each of the 110 NIST SP 800-171 requirements to your specific implementation. If your SSP is unclear, vague, or out of date, the assessment will be rough. If it's accurate and well-organized, the assessment goes much faster.
Learn moreSystem for Award Management (SAM.gov)
The System for Award Management (SAM.gov) is an official website of the U.S. Government where entities can register to receive a Unique Entity ID and CAGE code to do business with the government.
Learn moreThe Cyber AB (formerly CMMC Accreditation Body)
The Cyber AB is the sole authorized accreditation body for CMMC. It accredits C3PAOs, certifies individual assessors, maintains the Cyber AB Marketplace, and performs quality reviews on assessment reports before certifications are issued. The organization was originally called the CMMC Accreditation Body (CMMC-AB) and rebranded to The Cyber AB in 2022. Authority and responsibilities did not change with the rebrand.
Learn moreThird-Party Assessment Organization (3PAO)
A Third-Party Assessment Organization (3PAO) is an independent auditor accredited by the FedRAMP Program Management Office to assess cloud service providers for FedRAMP compliance.
Learn moreThreat Assessment
A threat assessment is a process of identifying, analyzing, and evaluating potential threats to an organization.
Learn moreTrust Services Criteria SOC 2
AICPA’s Trust Services Criteria are the framework used by auditors to determine which security and compliance controls they will test for in a company.
Learn moreUnique Entity ID (UEI)
A unique entity ID (UEI) is a 12-character alphanumeric code assigned to an entity when it registers on SAM.gov.
Learn moreValley of Death
In the military and defense sector, the valley of death describes the gap between a promising concept or prototype and the transition into a formal program of record or operational use.
Learn moreVendor Assessment
Vendor assessment is the process of evaluating a third party’s information security posture and data privacy practices during the vendor procurement process.
Learn moreVendor Risk Management (VRM)
Vendor Risk Management (VRM) refers to the process of identifying, assessing, monitoring, and mitigating the risks associated with outsourcing services or goods to third-party vendors or suppliers.
Learn moreVulnerability Scan
A vulnerability scan is a type of automated security assessment that checks a computer system or network for known security weaknesses and vulnerabilities.
Learn moreZero Trust
Zero trust is a modern security strategy based on the principle never trust, always verify.
Learn more