Knowledge base

The language of modern GRC.

Conversational definitions for governance, risk, compliance, cybersecurity, government, FinTech, digital assets, and quantum readiness.

63 terms

A

Access Control

Rules and mechanisms that determine who can access systems, data, wallets, and functions.

Accountability

Clear ownership for decisions, actions, risks, controls, and outcomes.

Anti-Money Laundering (AML)

Laws, monitoring, and controls intended to prevent financial systems from being used to conceal illicit funds.

Authorization to Operate (ATO)

A management decision that authorizes an information system to operate with an accepted level of risk.

Audit Trail

A chronological record that makes significant actions, changes, approvals, and transactions traceable.

Authentication

The process of proving an identity through credentials, biometrics, cryptographic signatures, or other factors.

B

Baseline Controls

The minimum set of safeguards an organization requires for a defined system or risk level.

Business Continuity Plan (BCP)

A documented approach for maintaining or restoring priority operations through a disruption.

C

California Consumer Privacy Act (CCPA)

A California privacy law that gives residents rights concerning collection, use, disclosure, and deletion of personal information.

Change Management

A controlled process for requesting, assessing, approving, testing, and releasing changes.

CMMC 2.0

The US Department of Defense cybersecurity program for protecting sensitive information across the defense industrial base.

Compliance

Conformance with applicable laws, regulations, standards, contracts, and internal policies.

Cryptographic Key Management

The secure generation, storage, distribution, rotation, recovery, and retirement of cryptographic keys.

D

Data Breach

Unauthorized access, acquisition, disclosure, alteration, or loss of protected information.

Decentralized Autonomous Organization (DAO)

An organization whose rules and decisions are substantially coordinated through smart contracts and token-holder governance.

Decentralized Finance (DeFi)

Financial services delivered through blockchain protocols and smart contracts rather than traditional intermediaries.

Digital Operational Resilience Act (DORA)

An EU regulation establishing ICT risk and operational-resilience requirements for financial entities and key technology providers.

Due Diligence

A structured investigation of risk, controls, claims, and obligations before entering or continuing a relationship.

E

Encryption

The transformation of information so it is unreadable without authorized cryptographic access.

Enterprise Risk Management (ERM)

An organization-wide approach to identifying, assessing, treating, and monitoring uncertainty against objectives.

EU AI Act

European Union legislation that applies obligations to AI actors and systems according to role and risk classification.

Evidence Collection

The structured gathering of reliable proof that a control is designed and operating as intended.

F

FedRAMP

The US government program that standardizes security assessment, authorization, and monitoring for cloud services.

FISMA

US federal law requiring agencies to develop, document, and implement information security programs.

Framework

A structured set of principles, requirements, or controls used to organize a governance or assurance program.

G

General Data Protection Regulation (GDPR)

European Union law governing the processing of personal data and the rights of individuals.

Governance

The structures, decision rights, policies, and oversight used to direct and hold an organization accountable.

GRC

The integration of governance, risk management, and compliance so decisions, uncertainty, and obligations are managed coherently.

H

HIPAA

A US law and associated rules establishing privacy and security requirements for protected health information.

I

Identity and Access Management (IAM)

Processes and technology for managing digital identities and their access throughout a lifecycle.

Incident Response

The coordinated preparation, detection, containment, recovery, and learning activities used to manage security incidents.

Internal Controls

Policies and activities designed to provide reasonable assurance that objectives and obligations will be met.

ISO 27001

The international standard specifying requirements for an information security management system.

K

Know Your Customer (KYC)

Identity verification and due-diligence processes used to understand customers and financial-crime risk.

Key Risk Indicator (KRI)

A measurable signal used to monitor changes in exposure to a defined risk.

L

Least Privilege

The principle that people and systems receive only the access required for their authorized tasks.

M

Markets in Crypto-Assets (MiCA)

The European Union regulatory framework for crypto-asset issuers and service providers.

Multisignature (Multisig)

A cryptographic arrangement requiring more than one approved key to authorize an action.

N

NIST Cybersecurity Framework

A voluntary framework for understanding, prioritizing, and communicating cybersecurity outcomes.

NIST SP 800-53

A catalog of security and privacy controls for information systems and organizations.

O

Operational Risk

Risk of loss or disruption resulting from inadequate or failed processes, people, systems, or external events.

P

PCI DSS

A security standard for organizations that store, process, or transmit payment-card data.

Penetration Testing

An authorized exercise that attempts to exploit weaknesses to demonstrate practical security impact.

Personally Identifiable Information (PII)

Information that identifies, relates to, or can reasonably be linked to an individual.

Policy Management

The lifecycle of drafting, approving, communicating, reviewing, and retiring organizational policies.

Q

Quantum-Resistant Cryptography

Cryptographic methods designed to remain secure against attacks using sufficiently capable quantum computers.

R

Residual Risk

The level of risk that remains after controls and other treatments are applied.

Risk Appetite

The types and amount of risk an organization is willing to accept in pursuit of its objectives.

Risk Management Framework (RMF)

A structured lifecycle for categorizing systems, selecting and assessing controls, authorizing operation, and monitoring risk.

Risk Register

A maintained record of identified risks, assessments, owners, treatments, and status.

Role-Based Access Control (RBAC)

An access model that assigns permissions according to defined job or system roles.

S

Sanctions Screening

Checking customers, counterparties, and transactions against applicable sanctions restrictions.

Segregation of Duties

Dividing incompatible responsibilities so one person cannot complete a sensitive process without oversight.

Smart Contract Audit

A review of blockchain code and its logic for vulnerabilities, unintended behavior, and control weaknesses.

SOC 2

An independent report on controls relevant to security, availability, processing integrity, confidentiality, or privacy.

T

Third-Party Risk Management (TPRM)

The lifecycle for identifying, assessing, treating, and monitoring risk introduced by external parties.

Threat Modeling

A structured process for identifying potential threats, attack paths, and appropriate mitigations.

Travel Rule

Requirements for certain financial transfers to carry specified originator and beneficiary information.

V

Vendor Risk Management

Governance and monitoring of risks arising from suppliers and service providers.

Virtual Asset Service Provider (VASP)

A business performing defined virtual-asset activities and subject to relevant financial-crime obligations.

Vulnerability Management

The continuous discovery, prioritization, remediation, and verification of security weaknesses.

Z

Zero-Knowledge Proof

A cryptographic method that proves a statement is true without revealing the underlying secret information.

Zero Trust Architecture

A security model that continuously verifies users, devices, context, and access rather than trusting network location.