Terminology Index
344 terms tagged "grc"
Showing 1-32 of 344 terms
72-Hour Notification
A 72-hour notification is a regulatory deadline that requires an organization to report certain security or privacy incidents within 72 hours of becoming aware of them.
Action-Oriented Reporting
A style of risk reporting that frames findings around the decisions and actions the audience can take, rather than just listing data. It tells leaders what changed, why it matters, and what to do next.
Analysis Documentation
Recording how a risk analysis was performed, including the assumptions, data sources, methods, and reasoning behind each estimate, so the conclusions can be understood, defended, and revisited later.
Annual Review Cycle
A scheduled, recurring review of security policies, typically yearly, to confirm each one is still accurate, relevant, and aligned with current risks and regulations, updating or retiring those that are out of date.
Approval Process
The defined steps and sign-offs a security policy must pass before it becomes official, identifying who reviews, who approves, and how disagreements are resolved, so policies carry genuine authority.
Architecture Finding Communication
Conveying the results of a security architecture review so stakeholders understand each design weakness, why it matters, and what to change, adjusting depth and framing for technical teams versus leadership.
Architecture Findings
The weaknesses identified during a security architecture review, such as missing trust boundaries, weak authentication between components, or single points of failure, that stem from how a system is designed rather than from a single bug.
Architecture Review Methodology
The defined process for reviewing a system's security architecture from start to finish: setting scope, gathering design information, applying threat modeling, identifying findings, and communicating recommendations.
Architecture Review Scope
The boundaries of a security architecture review: which systems, components, data flows, and concerns are in or out, set at the start so the review stays focused and its findings are meaningful.
Assessment Types
The different forms a security or control assessment can take, such as control assessments, vulnerability assessments, maturity assessments, and audits, each with its own purpose, rigor, and intended audience.
Assessment vs Audit
The distinction between an assessment, which evaluates and advises on security to drive improvement, and an audit, which independently verifies against defined criteria to provide formal assurance. They differ in independence, rigor, and purpose.
Asset-Based Identification
A risk identification approach that starts from the organization's important assets, such as systems, data, and services, and asks what threatens each one. It anchors risk discovery in what actually matters to protect.
Audience Analysis
Considering who will read and must follow a security policy, so the wording, detail, and tone fit them. A policy written for engineers differs from one for all staff, and matching the audience is what makes it usable.
Audit Automation
Using tools and scripts to perform audit work that was traditionally manual, such as pulling evidence, testing controls across all records instead of a sample, and tracking findings. It lets auditors cover more ground with less repetitive effort.
Audit Career Paths
The routes a professional can take within auditing, from staff auditor through senior, manager, and leadership roles, or into specializations like IT or cybersecurity audit. It maps how experience and certifications open new roles.
Audit Career Transitions
The shifts auditors make between roles, specialties, or industries, such as moving from external to internal audit, into IT or security audit, or out of audit into risk or compliance. Each transition draws on transferable audit skills.
Audit Categories
The major kinds of audit, such as financial, operational, compliance, and IT or cybersecurity audits, each with a different objective and scope. Knowing the category sets expectations for what an audit will and will not cover.
Audit Certifications
Professional credentials that validate audit expertise, such as CISA for IT audit, CIA for internal audit, or CPA for financial audit. They signal competence to employers and are often required for advancement.
Audit Coordination
From a GRC perspective, managing the logistics and relationships of an audit on the organization's side: scheduling, gathering evidence, routing auditor requests to the right owners, and keeping the engagement running smoothly.
Audit Discipline
The body of professional rigor that defines good auditing: systematic methodology, evidence-based conclusions, objectivity, and adherence to standards. It is what makes audit results credible and repeatable.
Audit Engagement Management
Running an external audit engagement well from the company's side: selecting the firm, scoping the work, coordinating evidence and timelines, and managing distribution of the resulting report, so the audit is efficient and the outcome is usable.
Audit Ethics
The ethical obligations that govern auditors, including objectivity, integrity, confidentiality, and avoiding conflicts of interest. Because others rely on audit conclusions, ethical lapses undermine the entire value of the work.
Audit Firm Selection
Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.
Audit Independence
The auditor's freedom from influence or conflicts that could bias their conclusions, in both fact and appearance. Without independence, an audit's assurance is worthless because its objectivity cannot be trusted.
Audit Innovation
Improving how audits are done through new techniques and technology, such as data analytics, continuous auditing, and automation, to increase coverage, speed, and insight beyond traditional sample-based methods.
Audit Integration
Connecting audit with the rest of the organization's governance, risk, and assurance activities so efforts are coordinated rather than siloed, reducing duplicate testing and giving a unified view of control health.
Audit Leadership Path
The progression toward leading an audit function, advancing from auditor to manager, director, and ultimately chief audit executive. It adds skills in strategy, stakeholder management, and running an audit program.
Audit Lessons Learned
Reflecting after an audit on what went well and what could improve, both in the audit process and in the organization's response, so future audits run more smoothly and recurring issues get addressed.
Audit Maturity Indicators
Signs that an audit function has moved beyond basic compliance checking toward a strategic, well-run capability, such as risk-based planning, data analytics, integration with other functions, and demonstrable business value.
Audit Profession
The field of auditing as a recognized professional discipline, with its own standards, ethics, certifications, and career structure. Membership implies adhering to shared expectations of competence and integrity.
Audit Program Management
Running the overall portfolio of audits over time: building a risk-based audit plan, allocating resources, scheduling engagements, tracking findings to closure, and reporting on the function's performance.
Audit Quality
How well an audit achieves its purpose: conclusions that are accurate, well-evidenced, and relevant, reached through sound methodology and objectivity. Poor quality erodes the trust that makes audit useful.