jump to content

Glossary

Search for definitions for platform product terms, along with the common security, privacy and compliance vocabulary used throughout the documentation.

Show as Markdown

Use this glossary as a quick reference while working on the platform. For an explanation of how major records connect, read Core Concepts.

Glossary term Definition
Access entry

A record can include roles, administrator status, MFA status, account status, optional flags, and reviewer decision.

Access review

A periodic review of who can access a system and whether that access remains appropriate.On the platform, reviews are organized as campaigns using one or more access sources. Access Reviews overview .

Access review campaign

A point-to-point access review that combines one or more sources, their instant entries, reviewer decisions, flags, and completion statistics.

Access review flag

An optional reviewer tag on an access entry, such as the orphan account, sleeping, excessive privileges, or SoD conflict.Flags highlight findings for evidence; they do not replace a decision. Flags.

Access source

A connected provider or CSV import from which an access review campaign collects identity and permission data.

Agent run

A record of the agent activity in the product performed on the basis of GRC authorized data. A executed agent is different from a collection of device agent positionsZebraBytepe a device.

Applicability statement

Decision and reasoning describing whether a particular control is applied in a declaration of suitability.

Approval quorum

The set or minimum number of approvers whose decisions are necessary for a specific version of the document to proceed.

Asset

A system, application, database, device, service or other resource that an organization needs to protect.

Audit

A formal assessment of whether an organization meets the defined requirements.An audit includes its scope, supporting evidence, findings and corrective work.

Audit log

A chronological record of actions and changes in an organization, used to investigate who carried out an operation and when it took place. Audit log.

Auditor

An internal or external auditor evaluating a compliance program and the evidence supporting it.

Authentication

The process of verifying the identity of a user, device or service. Passwords, SSO, tokensAPIand OAuth are authentication mechanisms.

Authorization

Rules that determine which resources and actions an authenticated identity is allowed to access.

BAA

Business Associate Agreement. A contract required by HIPAA when a business partner manages protected health information on behalf of a covered entity.

Campaign

See Access review campaign.

Compliance framework

An organized set of requirements or controls from a standard, regulation or insurance program, such as SOC2, ISO27001, or GDPR.

Compliance Portal

A public-oriented site where an organization shares certifications, commitments, references, selected files and links without exposing its private platform work space.

Commitment

A statement an organization chooses to publish through its compliance portal, organized within a commitment group.

Commitment group

A collection used to organize related commitments published through the Compliance Portal.

Control

A control indicates what the organization needs to, while a measure describes how it does.

Control owner

The person responsible for the implementation, operation or review of a control and its support measures.

Data classification

A category of data assigned based on sensitivity and handling requirements, such as public, internal, confidential or restricted.

Data record

A description of the information processed by an organization, including classification, sensitivity and impact on the business.

Data subject

An identified or identifiable person whose personal data is processed.

Device

A registered endpoint with ZebraByteDevice Agent. Its record can include property, platform details, record status, and potential posture.

Document

A controlled policy, procedure, report or other compliance registry that supports versions, approvals, signatures, publication, archiving and exports.

Document version

Content, approval decisions, and signature requests are associated with a specific version.

DPA

Data Processing Agreement. A contract that defines how a controller processes personal data on behalf of a controller.

DPIA

Data Protection Impact Assessment. An assessment of the privacy risks associated with the processing that could create a high risk for individuals.

Electronic signature

An electronic signature associated with a specific version and signature of a document.

Evidence

An artefact that demonstrates a control or measure works. Examples include reports, configuration exports, screenshots, approvals, logs and signed documents.

Finding

A lack, exception, observation or non-compliance identified during an assessment or audit.

Framework

See Compliance framework.

Identity provider (IdP)

A service that authenticates users and provides application identity information through protocols such as SAML or OpenID Connect.

Impact

the severity of the consequences if a risk event occurs; the impact is usually assessed together with the probability.

Inherent risk

The level of risk before considering existing safeguards, measures or mitigations.

Integration

A connection between the platform and another application or service. Integrations can support access review, automation, notifications or data exchange.

Likelihood

An estimate of the probability that a risk event or scenario will occur.

Membership

The relationship that assigns a user a role ( OWNER, ADMIN, VIEWER, AUDITOR, or EMPLOYEE) and access within an organization. People. See Roles and permissions.

Measure

Protection, process, or recurring activity implemented to meet one or more controls.

MFA

Multi-factor authentication. Authentication that requires evidence from more than one factor, reducing reliance on a single password.

OAuth

An authorization framework that allows an application to obtain limited access to another service without receiving the user’s password.

Obligation

A legal, regulatory, contractual or other requirement that the organization must meet.

Organization

Members, frameworks, controls, risks, third parties, evidence, documents and audits belong to an organization.

Personal data

Information about an identified or identifiable person Privacy laws may use related terms with jurisdiction-specific definitions.

Policy

A documented statement on the organization’s rules, responsibilities and expected practices.

ZebraByte Device Agent

the platform endpoint agent for recording devices and reporting posture controls, such as encryption, screen lock, firewall and operating system status.

Processing activity

A record of how personal data is collected, used, shared, stored and deleted. This includes purposes, legal grounds, data subjects, recipients and details of retention.

Publication

The action of creating a revised or externally usable representation of a record or list.Publishing does not necessarily result in internal records being published on the Portal.

Remediation

Work carried out to correct a finding, reduce a risk, or address another identified deficiency.

Retention period

The duration of the information is retained before it is deleted, anonymized or otherwise deleted.

Residual risk

Risk remaining after existing measures and mitigation measures shall be taken into account.

Rights request

A request from a data subject to exercise a right of confidentiality, such as access, correction, deletion, restriction or portability.

Risk

The possibility that a threat or event affects the organization’s objectives, security, privacy or compliance attitude.

Risk assessment

A structured analysis of scope, systems, limits, processes, threats and scenarios used to identify and assess risks.

Risk owner

The person responsible for monitoring a risk and providing its treatment is appropriate.

Risk register

The set of risksined by an organization is monitored, reviewed, held and handled over time.

Risk scenario

A description of how one or more threats could act in an assessment and lead to a risk.

SAML

Security Assertion Markup Language. A standard for exchanging authentication and authorization information between an identity provider and a service provider.

SCIM

System for Cross-domain Identity Management. A standard used to provide, update and remove user accounts between an identity provider and an application.

Scope

Systems, processes, organizational units, locations or other limits included in a compliance, audit or risk assessment activity.

Service provider

In SSO, the application that relies on an identity provider to authenticate users. the platform acts as the SAML service provider.

SoA

Statement of Applicability. An ISO27001 document that records whether each control in Annex A applies, why it is included or excluded, and the status of its implementation.

SSO

Single Sign-On. An authentication approach that allows users to access the platform through a central identity provider. the platform supports SAML 2.0 SSO.

Subprocessor

A third party engaged by a processor to process personal data on behalf of a controller.

Task

A work unit assigned with a owner and status. tasks help teams implement measures, collect evidence, complete assessments, and fix findings.

Threat

In a risk assessment, threats are related to scenarios that explain how the risks may arise.

Third party

A provider, supplier, service provider or other external organization that supports the business or processes its data.

TIA

Transfer Impact Assessment. An assessment of the privacy and legal risks associated with the transfer of personal data between jurisdictions.

Tracker

A script, iframe, image, style sheet or other browser resource whose loading can be classified and controlled by the cookie banner.

Vendor

See Third party.

Vendor vetting

Collecting and reviewing information about a third party in support of a risk or due diligence decision.

Webhook

A HTTP notification sent when a supported event takes place on the platform. Webhooks allows another system to react without repeatedly requesting changes.

Ultima actualizare: