GRC Glossary

Essential terms in risk management, security, and compliance

Quick reference for security, compliance, and vendor management teams.

Governance and Risk Management

TPRM
Third-Party Risk Management — the process of identifying, assessing, and mitigating risks originating from vendors, partners, and service providers.
GRC
Governance, Risk and Compliance — an integrated discipline of corporate governance, risk management, and regulatory compliance.
Risk Appetite
The level of risk an organization is willing to accept in pursuit of its strategic objectives. It is the reference point for all decisions to accept or mitigate risk.
Control
Measures (technical, administrative, or physical) implemented to modify risk. They can be preventive, detective, corrective, or directive.
Due Diligence
The process of detailed investigation and audit conducted before entering into partnerships, mergers, or acquisitions, focused on identifying hidden risks.
KRI (Key Risk Indicator)
A metric used to provide early warning signals about increasing risk in specific areas, enabling proactive action.
Risk Matrix
A visual tool that plots the Probability of an event occurring against its Impact (severity) if it does, facilitating prioritization.
Risk Register
A central repository (inventory) where all identified risks are mapped, documented, quantified, and assigned to an owner (Risk Owner).
Risk Tolerance
The maximum acceptable variance from the defined risk appetite.

Compliance, Privacy and Legal

LGPD
Lei Geral de Proteção de Dados (Law 13.709/2018) — Brazil's data protection regulation, analogous to the European GDPR.
GDPR
General Data Protection Regulation (EU 2016/679) — European data protection regulation applicable to any organization that processes data of EU residents.
DPA (Data Processing Agreement)
A mandatory contract formalizing the relationship between the data controller and processor, detailing responsibilities for data protection (essential for LGPD/GDPR).
Privacy by Design
An approach requiring data protection to be embedded from the conception phase of a project, product, or system — not added as an afterthought.
DPIA (Data Protection Impact Assessment)
A mandatory document for assessing privacy risks in processes involving large-scale personal data processing or sensitive technologies.
Data Controller
The natural or legal person who makes the decisions regarding the processing of personal data, defining its purposes and means — a term used by both LGPD and GDPR.
Data Processor
The natural or legal person who processes personal data on behalf of the controller, following its instructions — corresponds to the GDPR 'processor' and the LGPD 'operador'.
DPO (Data Protection Officer)
The professional designated to advise the organization on LGPD/GDPR compliance, act as the communication channel with data subjects and authorities, and monitor the privacy program.
Anonymization
A technical process that permanently removes the possibility of linking a piece of data to an identifiable individual, placing it outside the scope of LGPD/GDPR protection — unlike pseudonymization, which is reversible.
Pseudonymization
A technique that replaces direct identifiers with codes or pseudonyms, so that re-identification requires additional information kept separately — it reduces risk without eliminating the personal nature of the data.
Legitimate Interest
A legal basis under LGPD and GDPR that allows personal data processing without consent when justified by the legitimate interests of the controller or a third party, provided the data subject's rights and freedoms do not override it.
Cross-Border Data Transfer
The transfer of personal data outside the country of origin, subject to specific safeguards (standard contractual clauses, adequacy decisions) required by LGPD and GDPR to ensure an equivalent level of protection.

Information Security and Operations

Audit Trail
A chronological, immutable record of activities that enables full traceability of actions in systems — essential for audits and forensic investigations.
CVSS
Common Vulnerability Scoring System — a standardized 0–10 vulnerability scoring system classifying severity as Low, Medium, High, or Critical.
DMARC
Domain-based Message Authentication, Reporting and Conformance — an email authentication protocol that protects domains against unauthorized use (phishing, spoofing).
IAM
Identity and Access Management — policies and technologies ensuring the right people have access only to the resources they need.
MFA
Multi-Factor Authentication — authentication using more than one factor: password + something you have (token, app) or something you are (biometrics).
MITRE ATT&CK
A global knowledge base mapping the tactics and techniques of real-world attackers. Essential for Threat Modeling and testing the effectiveness of detection controls.
MTTR
Mean Time to Respond/Recover — average time to detect and respond to a security incident.
Pentest
Penetration testing — an authorized simulation of a cyberattack to identify vulnerabilities before malicious actors do.
SIEM
Security Information and Event Management — a centralizing platform that collects, correlates, and analyzes security logs in real time, enabling threat detection.
SOAR
Security Orchestration, Automation and Response — a platform that automates incident response by orchestrating workflows across different IT and security tools.
Vulnerability Management
A continuous, cyclical process of identifying, classifying, prioritizing, mitigating, and reporting vulnerabilities across the technology environment.
Zero Trust
A security paradigm that removes implicit trust from the network. It assumes the network is already compromised; every access request requires continuous verification of identity and context.
EDR / XDR
Endpoint Detection and Response / Extended Detection and Response — solutions that monitor endpoints (EDR) or multiple layers — endpoint, network, email, cloud (XDR) — to detect and respond to threats in a correlated way.
IOC (Indicator of Compromise)
Forensic evidence (a file hash, malicious IP, domain, or signature) suggesting a system has been compromised, used for detection and incident response.
TTP (Tactics, Techniques and Procedures)
A description of a threat actor's behavior, from strategic goal (tactic) to specific execution steps (procedures) — the basis of the MITRE ATT&CK framework.
Ransomware
Malware that encrypts or blocks access to data and systems, demanding a ransom payment for restoration — one of the main fourth-party risks, as it can affect critical vendors and disrupt the supply chain.
DLP (Data Loss Prevention)
A set of technologies and policies that monitor, detect, and block the unauthorized transmission of sensitive data outside the organization.
PAM (Privileged Access Management)
Controls and tools dedicated to protecting, monitoring, and auditing accounts with elevated privileges (administrators, service accounts) — one of the preferred targets of attacks.
SSO (Single Sign-On)
A mechanism that allows a user to access multiple systems with a single set of credentials, centralizing and simplifying access control.
WAF (Web Application Firewall)
A protection layer that filters, monitors, and blocks malicious HTTP traffic between a web application and the internet, mitigating attacks such as SQL injection and XSS.

Business Continuity and Resilience

BCP (Business Continuity Plan)
A strategic plan defining how the company will maintain its critical operational functions during and immediately after a disaster or major disruption.
DRP (Disaster Recovery Plan)
A technical and operational plan focused on restoring IT systems and infrastructure after a catastrophic disruption.
ISO 22301
International standard for Business Continuity Management, specifying requirements to plan, implement, and maintain operational resilience.
RPO (Recovery Point Objective)
The maximum point in time of data loss tolerable after an incident. It determines the required backup frequency.
RTO (Recovery Time Objective)
The maximum time a system can be offline before the business impact becomes unacceptable.
BIA (Business Impact Analysis)
A process that identifies critical processes and quantifies the financial, operational, and reputational impact of their disruption over time — the basis for defining RTO and RPO.
MTPD (Maximum Tolerable Period of Disruption)
The maximum length of time a critical process can be disrupted before the consequences become unacceptable to the organization — a direct input to the BIA.
Crisis Management
The governance structure, roles, and decision-making processes activated during a high-impact incident, coordinating communication, response, and continuity above the operational level of the BCP/DRP.
Tabletop Exercise
A structured, discussion-based simulation of a crisis or incident scenario, conducted with stakeholders to test plans, roles, and decision-making without disrupting real operations.

Certifications and Reference Frameworks

ISO 27001
International standard for Information Security Management Systems (ISMS), focused on establishing a continuous improvement cycle for information security.
NIST CSF 2.0
Cybersecurity Framework structured around: Govern, Identify, Protect, Detect, Respond, Recover. The gold standard for building security programs.
SOC 2
An audit report validating the effectiveness of a service organization's (especially SaaS) internal controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Type I validates design; Type II validates operation over time.
PCI DSS (Payment Card Industry Data Security Standard)
A mandatory security standard for any organization that stores, processes, or transmits payment card data.
HIPAA (Health Insurance Portability and Accountability Act)
A U.S. law that establishes security and privacy requirements for health data (PHI), with strong impact on vendor assessments in that sector.
CIS Controls
A prioritized set of cyber defense practices maintained by the Center for Internet Security, organized into implementation groups (IG1-IG3) by organizational maturity level.
COBIT (Control Objectives for Information and Related Technologies)
An IT governance framework that connects business objectives to IT objectives and to specific processes and controls.

Third-Party Risk Management

Inherent Risk
The level of risk that exists before any control or mitigation is applied — the raw exposure of an activity, process, or vendor.
Residual Risk
The risk that remains after controls and mitigations have been applied. This is the risk that should be compared against the organization's risk appetite.
Fourth-Party Risk
Risk arising from the subcontractors and vendors of an organization's own direct vendors (third parties), forming a chain of dependencies beyond the organization's direct visibility.
SIG Questionnaire
Standardized Information Gathering — a standardized questionnaire (maintained by Shared Assessments) used to assess vendor security, privacy, and risk practices consistently across organizations.
Vendor Risk Tiering
Classification of vendors into criticality tiers based on data access, operational dependency, and potential impact, allowing due diligence depth to be allocated proportionally to risk.
Control Owner
The individual or team designated as responsible for the implementation, operation, and ongoing effectiveness of a specific control.
Risk Owner
The individual with the authority and accountability to manage a specific risk, including the decision to accept, mitigate, transfer, or avoid it.
Continuous Monitoring
The practice of tracking vendor risk and security posture on an ongoing basis (via scanners, threat feeds, alerts) rather than relying solely on point-in-time, periodic assessments.
Questionnaire Fatigue
The burnout vendors face from having to respond to multiple similar but non-standardized security questionnaires for different clients, reducing the quality and timeliness of responses.
Subprocessor
A third party engaged by a processor to carry out part of the personal data processing on behalf of the controller — must be disclosed and contractually bound to the same data protection obligations.

AI and Governance

ISO 42001
The first international standard for an AI Management System (AIMS), establishing requirements for developing, providing, and using AI systems responsibly.
AI Act
The EU regulation (EU 2024/1689) that classifies AI systems by risk level (unacceptable, high, limited, minimal) and imposes proportional obligations, including for non-EU vendors serving the European market.
Model Risk Management
The discipline of identifying, assessing, and mitigating risks arising from the use of models (statistical or AI) in business decisions, including bias, inaccuracy, and use outside their intended scope.
Shadow AI
The use of artificial intelligence tools by employees or vendors without the organization's approval, visibility, or governance — analogous to Shadow IT, with added risk of data leakage through prompts.
Explainability
The ability of an AI system to provide understandable reasons for its outputs and decisions — a growing requirement in AI regulations and essential for auditing and trust in models used in risk decisions.