Glossary
Search for definitions for platform product terms, along with the common security, privacy and compliance vocabulary used throughout the documentation.
Use this glossary as a quick reference while working on the platform. For an explanation of how major records connect, read Core Concepts.
| Glossary term | Definition |
|---|---|
| Access entry | A record can include roles, administrator status, MFA status, account status, optional flags, and reviewer decision. |
| Access review | A periodic review of who can access a system and whether that access remains appropriate.On the platform, reviews are organized as campaigns using one or more access sources. Access Reviews overview . |
| Access review campaign | A point-to-point access review that combines one or more sources, their instant entries, reviewer decisions, flags, and completion statistics. |
| Access review flag | An optional reviewer tag on an access entry, such as the orphan account, sleeping, excessive privileges, or SoD conflict.Flags highlight findings for evidence; they do not replace a decision. Flags. |
| Access source | A connected provider or CSV import from which an access review campaign collects identity and permission data. |
| Agent run | A record of the agent activity in the product performed on the basis of GRC authorized data. A executed agent is different from a collection of device agent positionsZebraBytepe a device. |
| Applicability statement | Decision and reasoning describing whether a particular control is applied in a declaration of suitability. |
| Approval quorum | The set or minimum number of approvers whose decisions are necessary for a specific version of the document to proceed. |
| Asset | A system, application, database, device, service or other resource that an organization needs to protect. |
| Audit | A formal assessment of whether an organization meets the defined requirements.An audit includes its scope, supporting evidence, findings and corrective work. |
| Audit log | A chronological record of actions and changes in an organization, used to investigate who carried out an operation and when it took place. Audit log. |
| Auditor | An internal or external auditor evaluating a compliance program and the evidence supporting it. |
| Authentication | The process of verifying the identity of a user, device or service. Passwords, SSO, tokensAPIand OAuth are authentication mechanisms. |
| Authorization | Rules that determine which resources and actions an authenticated identity is allowed to access. |
| BAA | Business Associate Agreement. A contract required by HIPAA when a business partner manages protected health information on behalf of a covered entity. |
| Campaign | |
| Compliance framework | An organized set of requirements or controls from a standard, regulation or insurance program, such as SOC2, ISO27001, or GDPR. |
| Compliance Portal | A public-oriented site where an organization shares certifications, commitments, references, selected files and links without exposing its private platform work space. |
| Commitment | A statement an organization chooses to publish through its compliance portal, organized within a commitment group. |
| Commitment group | A collection used to organize related commitments published through the Compliance Portal. |
| Consent record | A record of a visitor’s consent options for cookies, including accepted or rejected categories and the banner version under which the choice was made. |
| Control | A control indicates what the organization needs to, while a measure describes how it does. |
| Control owner | The person responsible for the implementation, operation or review of a control and its support measures. |
| Cookie banner | A configurable notification that displays the tracking categories and records the visitor’s consent options according to the applicable consent mode. |
| Cookie category | A group of trackers with a common purpose and consent behavior, such as necessary, analytical or marketing. |
| Data classification | A category of data assigned based on sensitivity and handling requirements, such as public, internal, confidential or restricted. |
| Data record | A description of the information processed by an organization, including classification, sensitivity and impact on the business. |
| Data subject | An identified or identifiable person whose personal data is processed. |
| Device | A registered endpoint with ZebraByteDevice Agent. Its record can include property, platform details, record status, and potential posture. |
| Document | A controlled policy, procedure, report or other compliance registry that supports versions, approvals, signatures, publication, archiving and exports. |
| Document version | Content, approval decisions, and signature requests are associated with a specific version. |
| DPA | Data Processing Agreement. A contract that defines how a controller processes personal data on behalf of a controller. |
| DPIA | Data Protection Impact Assessment. An assessment of the privacy risks associated with the processing that could create a high risk for individuals. |
| Electronic signature | An electronic signature associated with a specific version and signature of a document. |
| Evidence | An artefact that demonstrates a control or measure works. Examples include reports, configuration exports, screenshots, approvals, logs and signed documents. |
| Finding | A lack, exception, observation or non-compliance identified during an assessment or audit. |
| Framework | See Compliance framework. |
| Identity provider (IdP) | A service that authenticates users and provides application identity information through protocols such as SAML or OpenID Connect. |
| Impact | the severity of the consequences if a risk event occurs; the impact is usually assessed together with the probability. |
| Inherent risk | The level of risk before considering existing safeguards, measures or mitigations. |
| Integration | A connection between the platform and another application or service. Integrations can support access review, automation, notifications or data exchange. |
| Legal basis | The legal basis on which it is based for the processing of personal data, such as consent, contract, legal obligation or legitimate interests. |
| Likelihood | An estimate of the probability that a risk event or scenario will occur. |
| Membership | The relationship that assigns a user a role ( |
| Measure | Protection, process, or recurring activity implemented to meet one or more controls. |
| MFA | Multi-factor authentication. Authentication that requires evidence from more than one factor, reducing reliance on a single password. |
| OAuth | An authorization framework that allows an application to obtain limited access to another service without receiving the user’s password. |
| Obligation | A legal, regulatory, contractual or other requirement that the organization must meet. |
| Organization | Members, frameworks, controls, risks, third parties, evidence, documents and audits belong to an organization. |
| Personal data | Information about an identified or identifiable person Privacy laws may use related terms with jurisdiction-specific definitions. |
| Policy | A documented statement on the organization’s rules, responsibilities and expected practices. |
| ZebraByte Device Agent | the platform endpoint agent for recording devices and reporting posture controls, such as encryption, screen lock, firewall and operating system status. |
| Processing activity | A record of how personal data is collected, used, shared, stored and deleted. This includes purposes, legal grounds, data subjects, recipients and details of retention. |
| Publication | The action of creating a revised or externally usable representation of a record or list.Publishing does not necessarily result in internal records being published on the Portal. |
| Remediation | Work carried out to correct a finding, reduce a risk, or address another identified deficiency. |
| Retention period | The duration of the information is retained before it is deleted, anonymized or otherwise deleted. |
| Residual risk | Risk remaining after existing measures and mitigation measures shall be taken into account. |
| Rights request | A request from a data subject to exercise a right of confidentiality, such as access, correction, deletion, restriction or portability. |
| Risk | The possibility that a threat or event affects the organization’s objectives, security, privacy or compliance attitude. |
| Risk assessment | A structured analysis of scope, systems, limits, processes, threats and scenarios used to identify and assess risks. |
| Risk owner | The person responsible for monitoring a risk and providing its treatment is appropriate. |
| Risk register | The set of risksined by an organization is monitored, reviewed, held and handled over time. |
| Risk scenario | A description of how one or more threats could act in an assessment and lead to a risk. |
| SAML | Security Assertion Markup Language. A standard for exchanging authentication and authorization information between an identity provider and a service provider. |
| SCIM | System for Cross-domain Identity Management. A standard used to provide, update and remove user accounts between an identity provider and an application. |
| Scope | Systems, processes, organizational units, locations or other limits included in a compliance, audit or risk assessment activity. |
| Service provider | In SSO, the application that relies on an identity provider to authenticate users. the platform acts as the SAML service provider. |
| SoA | Statement of Applicability. An ISO27001 document that records whether each control in Annex A applies, why it is included or excluded, and the status of its implementation. |
| SSO | Single Sign-On. An authentication approach that allows users to access the platform through a central identity provider. the platform supports SAML 2.0 SSO. |
| Subprocessor | A third party engaged by a processor to process personal data on behalf of a controller. |
| Task | A work unit assigned with a owner and status. tasks help teams implement measures, collect evidence, complete assessments, and fix findings. |
| Threat | In a risk assessment, threats are related to scenarios that explain how the risks may arise. |
| Third party | A provider, supplier, service provider or other external organization that supports the business or processes its data. |
| TIA | Transfer Impact Assessment. An assessment of the privacy and legal risks associated with the transfer of personal data between jurisdictions. |
| Tracker | A script, iframe, image, style sheet or other browser resource whose loading can be classified and controlled by the cookie banner. |
| Vendor | See Third party. |
| Vendor vetting | Collecting and reviewing information about a third party in support of a risk or due diligence decision. |
| Webhook | A HTTP notification sent when a supported event takes place on the platform. Webhooks allows another system to react without repeatedly requesting changes. |
| No glossary terms match your search. | |
Next steps
Posts Tagged ‘Next Steps’- Read Core Concepts understanding the relationships between these terms.
- Create your first organization and framework.
- Explore the MCP tools reference for records available through the MCP server.