Knowledge Base & Reference

Enterprise IT Audit, TPRM & GRC Compliance Glossary

A comprehensive, authoritative reference guide containing 40+ key terms across ITGC, SOC 2, ISO 27001, Quebec Law 25, TPRM, and Virtual CISO advisory.

ITGC (IT General Controls)

Foundational security controls applied to operating systems, databases, and network infrastructure, covering logical access, change management, and computer operations.

ITAC (IT Application Controls)

Automated controls programmed natively into software applications to ensure completeness, validity, and accuracy of transactions.

PIA (Privacy Impact Assessment)

A systematic evaluation process required by Quebec Law 25 and GDPR Article 35 to identify privacy risks associated with new information systems or cross-border data flows.

DPIA (Data Protection Impact Assessment)

The European GDPR counterpart to a PIA, legally required before commencing high-risk processing of personal data.

Quebec Law 25 (Bill 64)

Comprehensive privacy legislation in Quebec, Canada, introducing mandatory PIAs, designated Privacy Officers, and fines up to $25M or 4% of global revenue.

SOC 2 (System and Organization Controls 2)

An auditing procedure developed by the AICPA that ensures service providers securely manage data based on five Trust Services Criteria.

Trust Services Criteria (TSC)

The five criteria evaluated in a SOC 2 audit: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

ISO/IEC 27001:2022

The world’s most recognized standard for Information Security Management Systems (ISMS), comprising 93 security controls across 4 themes.

Statement of Applicability (SoA)

A mandatory document in ISO 27001 declaring which of the 93 Annex A controls apply to your organization and justifying exclusions.

TPRM (Third-Party Risk Management)

A discipline that evaluates, monitors, and mitigates security risks introduced by external suppliers, vendors, and partners.

SIG (Standardized Information Gathering)

A widely adopted questionnaire framework maintained by Shared Assessments to evaluate third-party cybersecurity posture.

CAIQ (Consensus Assessments Initiative Questionnaire)

A cloud security questionnaire framework developed by the Cloud Security Alliance (CSA).

Virtual CISO (vCISO)

An outsourced security executive providing board-level cybersecurity leadership and regulatory compliance direction on a fractional basis.

ISO/IEC 42001

The world’s first certifiable standard for Artificial Intelligence Management Systems (AIMS), governing AI risk, ethics, and transparency.