GRC Glossary

Security, compliance, and risk management terms — explained simply.

A

Audit
A formal examination of an organization's security controls, processes, and documentation by an independent assessor. Audits verify that controls meet the requirements of a specific framework.

B

BCP
Business Continuity Plan. A documented strategy for maintaining business operations during and after a disruption, based on the findings of a business impact analysis.
BIA
Business Impact Analysis. The process of identifying critical business processes, assessing the impact of disruption, and establishing recovery priorities.

C

CMMC
Cybersecurity Maturity Model Certification. A framework required for defense contractors to protect controlled unclassified information (CUI) in the defense industrial base.
Control
A safeguard or countermeasure designed to reduce risk. Controls can be technical (firewalls, encryption), administrative (policies, training), or physical (locks, badges). Compliance frameworks define required controls.

D

DMARC
Domain-based Message Authentication, Reporting & Conformance. An email authentication protocol that protects against email spoofing and phishing by verifying sender identity through SPF and DKIM alignment.

E

EDR
Endpoint Detection and Response. Security technology deployed on endpoints (laptops, servers) that continuously monitors for threats, detects suspicious activity, and enables rapid response to incidents.
Evidence
Documented proof that a security control is in place and operating effectively. Examples: access review exports, scan reports, policy documents, training completion records. Evidence is what auditors evaluate.

F

Framework
A structured set of guidelines, best practices, and controls that organizations follow to manage security and compliance. Examples: SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS.

G

GDPR
General Data Protection Regulation. European Union regulation on data protection and privacy that gives individuals control over their personal data and imposes strict requirements on organizations handling that data.
GRC
Governance, Risk, and Compliance. The integrated framework for managing organizational governance, enterprise risk management, and regulatory compliance.
Learn more

H

HIPAA
Health Insurance Portability and Accountability Act. U.S. federal law that requires organizations handling protected health information (PHI) to implement physical, network, and process security measures.

I

IAM
Identity and Access Management. The framework of policies and technologies ensuring that the right people have appropriate access to technology resources. Includes authentication, authorization, and user lifecycle management.
ISO 27001
An international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive company information through risk management processes.

M

MFA
Multi-Factor Authentication. A security method requiring users to provide two or more verification factors to access a system. Combines something you know (password), something you have (phone), and/or something you are (biometrics).
MITRE ATT&CK
A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. Used by security teams to understand attacker behavior and improve detection coverage.
MSP
Managed Service Provider. An organization that delivers IT services and support to businesses on a subscription basis, typically including network management, patching, backup, and help desk.
MSSP
Managed Security Service Provider. An organization that provides outsourced security monitoring and management services, including threat detection, incident response, and compliance management.
Learn more
MTTD
Mean Time to Detect. The average time between when a threat enters an environment and when it's detected. Lower MTTD indicates more effective detection capabilities.
MTTR
Mean Time to Respond (or Remediate). The average time between detecting a security incident or vulnerability and resolving it. A key operational security metric.

N

NIST CSF
National Institute of Standards and Technology Cybersecurity Framework. A voluntary framework of standards, guidelines, and best practices to manage cybersecurity risk, organized into six functions: Govern, Identify, Protect, Detect, Respond, Recover.
Learn more

P

PAM
Privileged Access Management. Security practices and tools for controlling, monitoring, and auditing access by accounts with elevated privileges (admin, root, service accounts).
PCI DSS
Payment Card Industry Data Security Standard. A set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
Posture
Security posture refers to an organization's overall cybersecurity strength — the combined effectiveness of its policies, controls, tools, and practices in managing risk and defending against threats.

R

Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact and likelihood. Results feed into the risk register and drive remediation priorities.
Risk Register
A structured document listing all identified risks to an organization, including their severity, likelihood, impact, ownership, status, and mitigation plans. The central artifact of any risk management program.
Learn more
RLS
Row Level Security. A database security feature that restricts which rows a user can access in a table based on their identity or role. Critical for multi-tenant SaaS applications.
RPO
Recovery Point Objective. The maximum acceptable amount of data loss measured in time. Defines how frequently backups must occur to stay within tolerance.
RTO
Recovery Time Objective. The maximum acceptable time between a disruption and the restoration of a business process. A key metric in business continuity planning.

S

SIEM
Security Information and Event Management. A platform that aggregates log data from across an organization's infrastructure, correlates events, and generates alerts for potential security incidents.
SOAR
Security Orchestration, Automation, and Response. Technology that enables organizations to automate incident response workflows, reducing mean time to respond (MTTR) to security events.
SOC 2
Service Organization Control 2. An auditing framework developed by the AICPA that evaluates an organization's controls over security, availability, processing integrity, confidentiality, and privacy of customer data.
Learn more

T

TPRM
Third-Party Risk Management. The practice of assessing, monitoring, and mitigating risks associated with vendors, suppliers, and other external parties that have access to your data or systems.

V

vCISO
Virtual Chief Information Security Officer. A security leader who provides CISO-level guidance to multiple organizations on a fractional or contract basis, rather than as a full-time employee.
Learn more

X

XDR
Extended Detection and Response. A unified security platform that collects and correlates data across multiple security layers — endpoints, network, email, cloud, identity — to provide comprehensive threat detection and automated response.

Z

Zero Trust
A security model based on the principle of 'never trust, always verify.' Every access request is authenticated and authorized regardless of where it originates — inside or outside the network perimeter.
Radius360

We use cookies

We use strictly necessary cookies to make Radius360 work. With your consent, we'd also like to use analytics cookies to understand how visitors use our site so we can improve it. You can change your choice anytime. See our Privacy Policy.