Centraleyes’s Glossary

A-Z guide to commonly used cybersecurity terms and phrases
 
Glossary visual

Resources | Glossary

data retention iso
What Is an ISO 27001 Data Retention Policy? An ISO 27001 data retention policy defines how long an organization keeps...
siloed data
Key Takeaways What Is Siloed Data? Data silos are isolated collections of information that sit inside separate departments, tools, spreadsheets,...
governance risk compliance certification
Key Takeaways What Is Risk Compliance Certification? Risk compliance certification is a professional credential that helps show a person’s knowledge...
documentation of risk
Key Takeaways What Is Risk Documentation? Risk management documentation is the organized record of how an organization identifies, analyzes, owns,...
ChatGPT Image May 26, 2026, 09_02_52 AM
Key Takeaways What Is Compliance Posture? Compliance posture is the overall condition of an organization’s compliance program at a specific...
double materiality assessment
Key Takeaways What Is a Double Materiality Assessment? A double materiality assessment helps a company decide which sustainability topics are...
GRC requirements
Key Takeaways What Are GRC Requirements? GRC requirements are the rules, obligations, and expectations that tell an organization how to...
ChatGPT Image May 20, 2026, 10_24_42 AM
Key Takeaways What Is IT Risk Management? IT risk management, often called ITRM, is the process of identifying, assessing, treating,...
iso 27001 operations
​​​​Key Takeaways What Is ISO 27001 Operations Security? Operations security in ISO 27001 refers to the controls that ensure an...
pci compliant hosting
Key Takeaways What Is PCI Compliant Hosting? PCI-compliant hosting refers to a hosting environment that is managed in a way...
audit risk model
Key Takeaways What Is the Audit Risk Model? The audit risk model is a framework auditors use to understand the...
surveillance visit
Key Takeaways What is a Surveillance Visit? A surveillance visit is a periodic audit performed after an organization receives certification...
rpo
Key Takeaways What is a Recovery Point Objective? A recovery point objective, often shortened to RPO, is the maximum amount...
fips
Key Takeaways What is FIPS? Federal Information Processing Standards (FIPS) were developed by the National Institute of Standards and Technology...
hipaa covered entity
Key Takeaways: ​​What are HIPAA Covered Entities? HIPAA covered entities are organizations that must follow federal rules for protecting patient...
iso 9001
What is an ISO 9001 Audit? An ISO 9001 audit is a structured, independent review used to assess whether an...
grc_convergence
Key Takeaways What is GRC Convergence? GRC convergence describes an approach to organizing governance, risk, and compliance activities so they...
dod distribution
Key Takeaways What are DoD Distribution Statements? DoD Distribution Statements are standardized markings used by the U.S. Department of Defense...
continuous monitoring
Key Takeaways What is Continuous Monitoring? Continuous monitoring is the practice of maintaining ongoing visibility into systems, controls, and risk...
cmmc accreditation
Key Takeaways What Is the CMMC Accreditation Body? The CMMC Accreditation Body (CMMC-AB), now officially operating under The Cyber AB,...
fedramp-baseline
Key Takeaways What Are FedRAMP Baselines? FedRAMP baselines are standardized sets of security controls that define the minimum cybersecurity requirements...
sox controls
Key Takeaways What are SOX Controls? SOX controls are the internal mechanisms organizations use to ensure that financial reporting is...
cui-enclave
Key Takeaways What is a CUI Enclave? A CUI enclave is a defined, isolated environment used to store, process, and...
processing-integrity
Key Takeaways What is Processing Integrity? Processing integrity is one of the SOC 2 Trust Services Criteria and focuses on...
doc control procedure
Key Takeaways What Is a Document Control Procedure? A document control procedure is the system an organization uses to manage...
iso data destruction
Key Takeaways What is ISO 27001 Data Destruction? In ISO 27001, data destruction refers to permanently erasing information so it...
hipaa enforcement rule
Key Takeaways What Is the HIPAA Enforcement Rule? The HIPAA Enforcement Rule is the section of the Health Insurance Portability...
vciso
Key Takeaways What is a vCISO (Virtual Chief Information Security Officer)? A virtual Chief Information Security Officer (vCISO) is an...
pci NONCOMPLIANCE
Key Takeaways What are PCI Non-Compliance Fees? PCI non-compliance fees are penalties that merchants may face if they fail to...
nist incident response lifecycle
Key Takeaways What is the NIST Incident Response Life Cycle? The NIST Incident Response Life Cycle is a structured process...
Skip to content