A comprehensive, authoritative reference guide containing 40+ key terms across ITGC, SOC 2, ISO 27001, Quebec Law 25, TPRM, and Virtual CISO advisory.
Foundational security controls applied to operating systems, databases, and network infrastructure, covering logical access, change management, and computer operations.
Automated controls programmed natively into software applications to ensure completeness, validity, and accuracy of transactions.
A systematic evaluation process required by Quebec Law 25 and GDPR Article 35 to identify privacy risks associated with new information systems or cross-border data flows.
The European GDPR counterpart to a PIA, legally required before commencing high-risk processing of personal data.
Comprehensive privacy legislation in Quebec, Canada, introducing mandatory PIAs, designated Privacy Officers, and fines up to $25M or 4% of global revenue.
An auditing procedure developed by the AICPA that ensures service providers securely manage data based on five Trust Services Criteria.
The five criteria evaluated in a SOC 2 audit: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The world’s most recognized standard for Information Security Management Systems (ISMS), comprising 93 security controls across 4 themes.
A mandatory document in ISO 27001 declaring which of the 93 Annex A controls apply to your organization and justifying exclusions.
A discipline that evaluates, monitors, and mitigates security risks introduced by external suppliers, vendors, and partners.
A widely adopted questionnaire framework maintained by Shared Assessments to evaluate third-party cybersecurity posture.
A cloud security questionnaire framework developed by the Cloud Security Alliance (CSA).
An outsourced security executive providing board-level cybersecurity leadership and regulatory compliance direction on a fractional basis.
The world’s first certifiable standard for Artificial Intelligence Management Systems (AIMS), governing AI risk, ethics, and transparency.