Terminology Index
Glossary
1801 terms
Showing 385-416 of 1801 terms
Compliance Program Scope
Defining what a compliance program covers, which frameworks, systems, data, and business units are in or out, set when building the program so effort is focused on what actually matters and audits have clear boundaries.
Scope is the foundational build-time decision that bounds a compliance program: which standards apply, which products and environments they cover, and what data is in play. Getting scope right prevents both over-investment (certifying systems no customer cares about) and gaps (omitting a system the framework requires). It is driven by customer demands, regulations, and risk, and it shapes mapping, evidence, and audit boundaries downstream.
Introduced in: Compliance Program Design and Operations
Examples
- Deciding that SOC 2 covers the production SaaS platform but not internal tools.
- Defining which data types bring HIPAA into scope.
- Excluding a legacy system from the audit boundary deliberately.
No related terms linked yet.
