Glossary

30 terms you'll hear in every interview.

The vocabulary that distinguishes a candidate who has done the prep from one who has not. Sub-10% of GRC interviews are spent here; knowing these terms is non-negotiable.

Filter by category
All
Foundations
Controls
Risk
Reporting
Privacy
Compliance
Vendor
Operations
Audit
BCP/DR

30 terms across 10 categories.

CIA triad
Foundations

Confidentiality, integrity, availability — the three properties information security protects.

Control
Controls

A safeguard that reduces the likelihood or impact of a risk.

Residual risk
Risk

The risk that remains after controls are applied.

Inherent risk
Risk

The risk before any controls are applied — the gross exposure.

KRI
Reporting

Key Risk Indicator — a leading metric that signals a change in risk posture.

DPIA
Privacy

Data Protection Impact Assessment — required under GDPR for high-risk processing.

AOC
Compliance

Attestation of Compliance — the document that proves a vendor's PCI compliance.

BAAs
Privacy

Business Associate Agreements — HIPAA-required contracts with vendors handling PHI.

CMMC
Compliance

Cybersecurity Maturity Model Certification — DoD's framework for contractor cyber posture.

CUI
Compliance

Controlled Unclassified Information — federal data that requires safeguarding.

POA&M
Compliance

Plan of Action and Milestones — the federal tracker for outstanding security items.

SIG
Vendor

Standardized Information Gathering questionnaire — a common vendor risk questionnaire.

CAIQ
Vendor

Cloud Alliance Information Questionnaire — a cloud-vendor security questionnaire.

BAU
Operations

Business As Usual — the steady-state operations of a control.

ISMS
Compliance

Information Security Management System — the management framework under ISO 27001.

Annex A
Compliance

The 93 controls of ISO 27001 (2022 revision) — the control reference catalog.

TSC
Audit

Trust Services Criteria — the five SOC 2 categories (Security, Availability, Confidentiality, PI, Privacy).

CC criteria
Audit

Common Criteria — the SOC 2 Security category, embedded in every SOC 2 report.

SBOM
Operations

Software Bill of Materials — a list of components in a software product.

RTO
BCP/DR

Recovery Time Objective — max acceptable time to restore service.

RPO
BCP/DR

Recovery Point Objective — max acceptable data loss measured in time.

Tabletop
Operations

A facilitated discussion of a hypothetical incident to rehearse roles and decision-making.

SLA
Operations

Service-Level Agreement — a contractual commitment on performance or availability.

TPRM
Vendor

Third-Party Risk Management — the program for vetting and monitoring vendors.

EOL
Operations

End of Life — when a vendor stops supporting a product or version.

Pen test
Operations

A controlled attempt to find security weaknesses in a system or environment.

Red team
Operations

A friendly team that emulates real attackers to test the org's detection and response.

Bug bounty
Operations

A public program that rewards external researchers for finding security issues.

Threat model
Risk

A structured exercise to enumerate threats to a system and prioritize them.

Attack surface
Risk

The set of ways an attacker can get in or extract data.

Related: /templates — blank artifacts to use alongside these terms (risk register, control worksheet, vendor questionnaire, audit outline).