Access Control
Rules and mechanisms that determine who can access systems, data, wallets, and functions.
Knowledge base
Conversational definitions for governance, risk, compliance, cybersecurity, government, FinTech, digital assets, and quantum readiness.
63 terms
Rules and mechanisms that determine who can access systems, data, wallets, and functions.
Clear ownership for decisions, actions, risks, controls, and outcomes.
Laws, monitoring, and controls intended to prevent financial systems from being used to conceal illicit funds.
A management decision that authorizes an information system to operate with an accepted level of risk.
A chronological record that makes significant actions, changes, approvals, and transactions traceable.
The process of proving an identity through credentials, biometrics, cryptographic signatures, or other factors.
The minimum set of safeguards an organization requires for a defined system or risk level.
A documented approach for maintaining or restoring priority operations through a disruption.
A California privacy law that gives residents rights concerning collection, use, disclosure, and deletion of personal information.
A controlled process for requesting, assessing, approving, testing, and releasing changes.
The US Department of Defense cybersecurity program for protecting sensitive information across the defense industrial base.
Conformance with applicable laws, regulations, standards, contracts, and internal policies.
The secure generation, storage, distribution, rotation, recovery, and retirement of cryptographic keys.
Unauthorized access, acquisition, disclosure, alteration, or loss of protected information.
An organization whose rules and decisions are substantially coordinated through smart contracts and token-holder governance.
Financial services delivered through blockchain protocols and smart contracts rather than traditional intermediaries.
An EU regulation establishing ICT risk and operational-resilience requirements for financial entities and key technology providers.
A structured investigation of risk, controls, claims, and obligations before entering or continuing a relationship.
The transformation of information so it is unreadable without authorized cryptographic access.
An organization-wide approach to identifying, assessing, treating, and monitoring uncertainty against objectives.
European Union legislation that applies obligations to AI actors and systems according to role and risk classification.
The structured gathering of reliable proof that a control is designed and operating as intended.
The US government program that standardizes security assessment, authorization, and monitoring for cloud services.
US federal law requiring agencies to develop, document, and implement information security programs.
A structured set of principles, requirements, or controls used to organize a governance or assurance program.
European Union law governing the processing of personal data and the rights of individuals.
The structures, decision rights, policies, and oversight used to direct and hold an organization accountable.
The integration of governance, risk management, and compliance so decisions, uncertainty, and obligations are managed coherently.
A US law and associated rules establishing privacy and security requirements for protected health information.
Processes and technology for managing digital identities and their access throughout a lifecycle.
The coordinated preparation, detection, containment, recovery, and learning activities used to manage security incidents.
Policies and activities designed to provide reasonable assurance that objectives and obligations will be met.
The international standard specifying requirements for an information security management system.
Identity verification and due-diligence processes used to understand customers and financial-crime risk.
A measurable signal used to monitor changes in exposure to a defined risk.
The principle that people and systems receive only the access required for their authorized tasks.
The European Union regulatory framework for crypto-asset issuers and service providers.
A cryptographic arrangement requiring more than one approved key to authorize an action.
A voluntary framework for understanding, prioritizing, and communicating cybersecurity outcomes.
A catalog of security and privacy controls for information systems and organizations.
Risk of loss or disruption resulting from inadequate or failed processes, people, systems, or external events.
A security standard for organizations that store, process, or transmit payment-card data.
An authorized exercise that attempts to exploit weaknesses to demonstrate practical security impact.
Information that identifies, relates to, or can reasonably be linked to an individual.
The lifecycle of drafting, approving, communicating, reviewing, and retiring organizational policies.
Cryptographic methods designed to remain secure against attacks using sufficiently capable quantum computers.
The level of risk that remains after controls and other treatments are applied.
The types and amount of risk an organization is willing to accept in pursuit of its objectives.
A structured lifecycle for categorizing systems, selecting and assessing controls, authorizing operation, and monitoring risk.
A maintained record of identified risks, assessments, owners, treatments, and status.
An access model that assigns permissions according to defined job or system roles.
Checking customers, counterparties, and transactions against applicable sanctions restrictions.
Dividing incompatible responsibilities so one person cannot complete a sensitive process without oversight.
A review of blockchain code and its logic for vulnerabilities, unintended behavior, and control weaknesses.
An independent report on controls relevant to security, availability, processing integrity, confidentiality, or privacy.
The lifecycle for identifying, assessing, treating, and monitoring risk introduced by external parties.
A structured process for identifying potential threats, attack paths, and appropriate mitigations.
Requirements for certain financial transfers to carry specified originator and beneficiary information.
Governance and monitoring of risks arising from suppliers and service providers.
A business performing defined virtual-asset activities and subject to relevant financial-crime obligations.
The continuous discovery, prioritization, remediation, and verification of security weaknesses.
A cryptographic method that proves a statement is true without revealing the underlying secret information.
A security model that continuously verifies users, devices, context, and access rather than trusting network location.