Glossary
30 terms you'll hear in every interview.
The vocabulary that distinguishes a candidate who has done the prep from one who has not. Sub-10% of GRC interviews are spent here; knowing these terms is non-negotiable.
30 terms across 10 categories.
Confidentiality, integrity, availability — the three properties information security protects.
A safeguard that reduces the likelihood or impact of a risk.
The risk that remains after controls are applied.
The risk before any controls are applied — the gross exposure.
Key Risk Indicator — a leading metric that signals a change in risk posture.
Data Protection Impact Assessment — required under GDPR for high-risk processing.
Attestation of Compliance — the document that proves a vendor's PCI compliance.
Business Associate Agreements — HIPAA-required contracts with vendors handling PHI.
Cybersecurity Maturity Model Certification — DoD's framework for contractor cyber posture.
Controlled Unclassified Information — federal data that requires safeguarding.
Plan of Action and Milestones — the federal tracker for outstanding security items.
Standardized Information Gathering questionnaire — a common vendor risk questionnaire.
Cloud Alliance Information Questionnaire — a cloud-vendor security questionnaire.
Business As Usual — the steady-state operations of a control.
Information Security Management System — the management framework under ISO 27001.
The 93 controls of ISO 27001 (2022 revision) — the control reference catalog.
Trust Services Criteria — the five SOC 2 categories (Security, Availability, Confidentiality, PI, Privacy).
Common Criteria — the SOC 2 Security category, embedded in every SOC 2 report.
Software Bill of Materials — a list of components in a software product.
Recovery Time Objective — max acceptable time to restore service.
Recovery Point Objective — max acceptable data loss measured in time.
A facilitated discussion of a hypothetical incident to rehearse roles and decision-making.
Service-Level Agreement — a contractual commitment on performance or availability.
Third-Party Risk Management — the program for vetting and monitoring vendors.
End of Life — when a vendor stops supporting a product or version.
A controlled attempt to find security weaknesses in a system or environment.
A friendly team that emulates real attackers to test the org's detection and response.
A public program that rewards external researchers for finding security issues.
A structured exercise to enumerate threats to a system and prioritize them.
The set of ways an attacker can get in or extract data.
Related: /templates — blank artifacts to use alongside these terms (risk register, control worksheet, vendor questionnaire, audit outline).