GLOSSARY
Cybersecurity Compliance, Defined.
The frameworks, regulations, and roles that run a security program, in plain English. Written by the practitioners who operate them.
DEFENSE & CMMC
C3PAO (CMMC Third-Party Assessment Organization)
A C3PAO (CMMC Third-Party Assessment Organization) is a company accredited under the CMMC ecosystem to conduct CMMC Level 2 certification assessments of defense contractors. C3PAO assessments were the centerpiece of CMMC Phase 2, which the Department of Defense suspended in July 2026 pending a Reform Task Force review, leaving self-assessments, SPRS scores, and affirmations as the operative requirements for now.
CMMC (Cybersecurity Maturity Model Certification)
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that verifies defense contractors protect Federal Contract Information and Controlled Unclassified Information. It defines three levels of security requirements, from basic safeguarding self-assessments to third-party and government-led assessments, and it conditions eligibility for DoD contract awards on meeting the level specified in each solicitation.
CMMC Affirming Official
A CMMC Affirming Official is the senior company official who is responsible for ensuring the organization's compliance with CMMC requirements and who affirms, in the Supplier Performance Risk System, that the organization has implemented and will maintain its required security posture. Affirmations are made after each assessment and annually thereafter, and a false affirmation can create liability under the False Claims Act.
CUI (Controlled Unclassified Information)
CUI (Controlled Unclassified Information) is information the federal government creates or possesses, or that an organization creates or handles on the government's behalf, that requires safeguarding or dissemination controls under law, regulation, or government-wide policy but is not classified. Categories are defined in the National Archives CUI Registry, and defense contractors that handle CUI must protect it under NIST SP 800-171.
DFARS 252.204-7012 (Safeguarding Covered Defense Information)
DFARS 252.204-7012 is the Defense Federal Acquisition Regulation Supplement clause titled Safeguarding Covered Defense Information and Cyber Incident Reporting. It requires defense contractors to implement NIST SP 800-171 on systems that handle covered defense information, report cyber incidents to the Department of Defense within 72 hours of discovery, preserve related media, and flow the clause down to subcontractors.
FCI (Federal Contract Information)
FCI (Federal Contract Information) is information provided by or generated for the federal government under a contract that is not intended for public release. It excludes information the government provides to the public and simple transactional data such as payment processing information. Contractors that handle FCI must meet the 15 basic safeguarding requirements of FAR 52.204-21, which correspond to CMMC Level 1.
NIST SP 800-171 (Protecting Controlled Unclassified Information)
NIST SP 800-171 is the National Institute of Standards and Technology publication that specifies security requirements for protecting Controlled Unclassified Information in nonfederal systems and organizations. Revision 2 contains 110 requirements across 14 families and remains the assessment baseline for Department of Defense contractors under a May 2024 class deviation; Revision 3 has been published but not adopted for DoD assessments.
POA&M (Plan of Action and Milestones)
A POA&M (Plan of Action and Milestones) is a documented plan identifying security requirements an organization has not yet fully implemented, the tasks needed to close each gap, the resources required, and target completion dates. Under CMMC, POA&Ms are permitted only for a limited subset of requirements and must be closed out within 180 days of the assessment.
SPRS (Supplier Performance Risk System)
SPRS (Supplier Performance Risk System) is the Department of Defense database where contractors post their NIST SP 800-171 self-assessment scores and where CMMC assessment results and annual affirmations are recorded. Contracting officers check SPRS before award, so a current score and affirmation function as a precondition for winning and keeping DoD contracts that involve covered defense information.
FRAMEWORKS & CERTIFICATIONS
CIS Controls
CIS Controls are a prioritized set of prescriptive cybersecurity safeguards published by the Center for Internet Security. Version 8.1 organizes 18 controls into specific safeguards grouped by Implementation Groups, IG1 through IG3, so organizations can start with an essential cyber hygiene baseline and scale up. They answer the question of what to do first, complementing outcome-based frameworks like the NIST CSF.
CRI Profile
The CRI Profile is the Cyber Risk Institute's cybersecurity assessment framework for the financial sector, built by harmonizing the NIST Cybersecurity Framework with financial regulations and supervisory expectations. After the FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, the Profile became the de facto sector standard. Version 2.1, released in April 2025, adds a maturity model to the diagnostic statements.
FedRAMP
FedRAMP is the U.S. federal government's program for authorizing cloud services used by federal agencies, built on NIST SP 800-53 controls at Low, Moderate, and High baselines. A cloud provider must hold a FedRAMP authorization before agencies can use its service. The program is currently being overhauled under FedRAMP 20x, an automation-first redesign being rolled out through phased pilots.
GovRAMP
GovRAMP, formerly StateRAMP, is a nonprofit program that verifies the cloud security of providers selling to state and local governments and educational institutions. Rebranded from StateRAMP in February 2025, it uses security requirements based on NIST SP 800-53 with independent assessments, modeled on FedRAMP, and a growing number of state and local procurement offices recognize or require its verified statuses.
HITRUST CSF
HITRUST CSF is a certifiable security and privacy framework that harmonizes requirements from sources including HIPAA, NIST, ISO 27001, and PCI DSS into a single control library. HITRUST offers three assessment tiers: e1 for essential cybersecurity hygiene, i1 for leading security practices, and r2 for a tailored, risk-based certification. It is most commonly requested in healthcare vendor risk programs.
ISO 27001
ISO 27001 is the international standard for information security management systems, published jointly by ISO and IEC as ISO/IEC 27001. It defines requirements for establishing, operating, and continually improving a risk-based ISMS, and organizations can be certified against it by accredited certification bodies. The current edition is ISO/IEC 27001:2022; the transition period from the 2013 edition closed on October 31, 2025.
NIST CSF 2.0
NIST CSF 2.0 is the current version of the NIST Cybersecurity Framework, a voluntary risk management framework organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Released in 2024, it extends the framework beyond critical infrastructure to organizations of every size and sector, and elevates governance and supply chain risk management to first-class concerns.
NIST RMF (Risk Management Framework)
The NIST RMF (Risk Management Framework) is the structured process defined in NIST SP 800-37 for integrating security and privacy risk management into the system life cycle. Its seven steps are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Federal agencies are required to use it, and contractors operating systems for the government frequently must follow it to obtain an Authorization to Operate.
NIST SP 800-53 (Security and Privacy Controls)
NIST SP 800-53 is the National Institute of Standards and Technology catalog of security and privacy controls for information systems and organizations. Revision 5 organizes more than one thousand controls and enhancements into 20 families, and it underpins federal agency compliance, FedRAMP authorizations, and the Risk Management Framework. NIST SP 800-171's CUI requirements were derived from its moderate baseline.
PCI DSS
PCI DSS is the Payment Card Industry Data Security Standard, a contractual security standard maintained by the PCI Security Standards Council for any organization that stores, processes, or transmits payment card data. It defines twelve requirement areas covering network security, access control, monitoring, and testing, with validation through self-assessment questionnaires or an independent assessment depending on transaction volume.
SOC 2
SOC 2 is an attestation framework from the AICPA in which an independent CPA firm examines a service organization's controls against the Trust Services Criteria and issues a report. A Type I report covers control design at a point in time; a Type II report covers operating effectiveness over a period. It is the default security proof requested from B2B software and service vendors in North America.
Trust Services Criteria
Trust Services Criteria are the AICPA's evaluation criteria used in SOC 2 examinations, organized into five categories: security, availability, processing integrity, confidentiality, and privacy. Security, known as the common criteria, is mandatory in every SOC 2 report, while the other four categories are added based on the commitments a company makes to customers. The current version is the 2017 criteria with revised points of focus issued in 2023.
HEALTHCARE COMPLIANCE
Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is a contract required under HIPAA between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It obligates the vendor to apply Security Rule safeguards, report breaches and security incidents, and flow the same terms down to subcontractors, and it establishes direct HIPAA liability for the business associate.
ePHI (electronic Protected Health Information)
ePHI (electronic protected health information) is any individually identifiable health information that a HIPAA covered entity or business associate creates, receives, maintains, or transmits in electronic form. It spans data in EHR systems, databases, email, cloud storage, backups, and medical devices, and it is the specific class of information the HIPAA Security Rule's safeguards exist to protect.
HIPAA Security Rule
The HIPAA Security Rule is the federal regulation, codified at 45 CFR Part 164 Subpart C, that requires covered entities and business associates to implement administrative, physical, and technical safeguards protecting electronic protected health information (ePHI). It mandates a documented risk analysis, workforce training, access controls, and audit mechanisms, and is enforced by the HHS Office for Civil Rights.
HPH Cybersecurity Performance Goals (CPGs)
The HPH Cybersecurity Performance Goals (CPGs) are voluntary cybersecurity practices published by the US Department of Health and Human Services for the healthcare and public health sector. Split into Essential and Enhanced tiers, they cover practices such as multifactor authentication, email security, incident planning, and vendor risk management, and serve as a widely referenced baseline for healthcare cyber hygiene.
OCR (HHS Office for Civil Rights)
OCR (the HHS Office for Civil Rights) is the federal agency that enforces the HIPAA Privacy, Security, and Breach Notification Rules. It investigates complaints and reported breaches, conducts compliance reviews, and resolves violations through settlements, corrective action plans, and civil money penalties against covered entities and business associates that fail to protect health information.
Security Risk Analysis (HIPAA SRA)
A Security Risk Analysis (SRA) is the accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information that the HIPAA Security Rule requires of every covered entity and business associate. It is the foundational document of a HIPAA security program and a central focus of OCR enforcement.
FINANCIAL SERVICES
DORA (EU Digital Operational Resilience Act)
DORA (the EU Digital Operational Resilience Act) is the European Union regulation that requires financial entities to manage ICT risk, report major incidents, test digital resilience, and govern third-party technology providers under mandatory contractual terms. It has applied since January 17, 2025, and reaches US and other non-EU vendors through contract requirements flowed down by their EU financial clients.
FFIEC
The FFIEC (Federal Financial Institutions Examination Council) is the interagency body that prescribes uniform examination standards for US depository institutions on behalf of the Federal Reserve, FDIC, OCC, NCUA, and CFPB. Its IT Examination Handbook series defines the technology and cybersecurity expectations that federal examiners apply to banks and credit unions.
GLBA Safeguards Rule
The GLBA Safeguards Rule is the Federal Trade Commission regulation under the Gramm-Leach-Bliley Act that requires nonbank financial institutions to maintain a written information security program protecting customer information. It mandates a designated Qualified Individual, risk assessments, encryption, multifactor authentication, vendor oversight, and notification to the FTC of security events involving the information of 500 or more consumers.
NYDFS Part 500 (23 NYCRR 500)
NYDFS Part 500 (23 NYCRR 500) is the New York Department of Financial Services cybersecurity regulation covering banks, insurers, and other financial services companies licensed in New York. It requires a risk-based cybersecurity program, a designated CISO, broad multifactor authentication, asset inventories, 72-hour incident reporting, and an annual compliance certification, with amended requirements fully phased in as of November 1, 2025.
Qualified Individual (GLBA)
A Qualified Individual is the person the GLBA Safeguards Rule requires each covered financial institution to designate to oversee, implement, and enforce its information security program. The role may be filled by an employee, an affiliate, or an outsourced service provider, but the institution retains full responsibility for Safeguards Rule compliance regardless of who holds the title.
OT & UTILITIES
BES Cyber System
A BES Cyber System is one or more BES Cyber Assets grouped under NERC CIP-002 that, if rendered unavailable, degraded, or misused, would adversely impact reliable operation of the bulk electric system within 15 minutes. Each system is categorized as high, medium, or low impact, and that categorization determines which NERC CIP requirements apply to it.
IEC 62443
IEC 62443 is a series of international standards for securing industrial automation and control systems, developed through ISA and published by the IEC. It defines security requirements for asset owners, service providers, and product suppliers, organized around zones, conduits, and four security levels. It is the most widely referenced OT security standard across manufacturing, energy, utilities, and other industrial sectors.
Internal Network Security Monitoring (INSM, CIP-015)
Internal Network Security Monitoring (INSM) is the NERC CIP-015-1 requirement to collect, analyze, and retain network traffic data inside Electronic Security Perimeters so anomalous east-west activity can be detected. It applies to high impact BES Cyber Systems and medium impact systems with External Routable Connectivity, with compliance deadlines in September 2028 and September 2030 depending on asset category.
NERC CIP
NERC CIP is the mandatory Critical Infrastructure Protection standards family that the North American Electric Reliability Corporation enforces for owners and operators of the bulk electric system. The standards cover asset categorization, security management, personnel, electronic and physical security perimeters, incident reporting, recovery, configuration change management, supply chain risk, and internal network security monitoring, with violations subject to financial penalties.
OT Security (Operational Technology Security)
OT Security is the practice of protecting operational technology, the hardware and software that monitors and controls physical processes in environments such as utilities, manufacturing, and energy. It covers industrial control systems, SCADA, PLCs, and safety systems, and it prioritizes availability and safety over confidentiality, which distinguishes it from traditional IT security.
AI GOVERNANCE
EU AI Act
The EU AI Act is the European Union's comprehensive, risk-based regulation of artificial intelligence. It bans certain AI practices, imposes strict obligations on high-risk systems, and sets transparency and general-purpose AI model requirements. It applies extraterritorially, so companies outside the EU that place AI systems on the EU market or whose AI outputs are used in the EU are in scope.
ISO/IEC 42001
ISO/IEC 42001 is the international standard for artificial intelligence management systems, defining requirements for how an organization governs the responsible development and use of AI. Structured like ISO 27001, it is certifiable and covers AI policy, risk and impact assessment, lifecycle controls, and continual improvement. It is emerging as the leading third-party proof point for enterprise AI governance.
NIST AI RMF
The NIST AI RMF is a voluntary framework from the U.S. National Institute of Standards and Technology for identifying, measuring, and managing risks from artificial intelligence systems. It organizes AI governance into four functions, Govern, Map, Measure, and Manage, and has become the de facto baseline for AI risk management programs in the United States.
Shadow AI
Shadow AI is the use of artificial intelligence tools, models, or services by employees without the knowledge, approval, or oversight of IT and security teams. It creates data leakage, intellectual property, compliance, and accuracy risks because sensitive information flows into external systems the organization has not vetted, contracted with, or configured for enterprise controls.
SECURITY OPERATIONS & ROLES
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act, a 2022 U.S. federal law directing CISA to require covered critical infrastructure entities to report substantial cyber incidents within 72 hours and ransom payments within 24 hours. The implementing final rule has not yet been published; CISA has targeted September 2026, and obligations begin once the rule takes effect.
Cybersecurity Operating Partner
A cybersecurity operating partner is a firm that runs a client's security program continuously by pairing a dedicated forward-deployed security team with a GRC platform operated in the client's own tenant. Unlike a consultancy that delivers a project and leaves, or a software vendor that ships a tool, an operating partner combines people, platform, and ongoing execution.
Executive Security Advisor (ESA)
An Executive Security Advisor (ESA) is a named senior security leader who directs a client's security program as part of Z Cyber's operating model. The ESA leads a dedicated forward-deployed security team, runs the program cadence, and prepares prioritized recommendations, while the client makes the decisions, grants the approvals, and owns the risk.
vCISO (Virtual CISO)
A vCISO (virtual Chief Information Security Officer) is an outsourced senior security leader who provides CISO-level strategy, governance, and board reporting on a fractional or subscription basis. Mid-market and growth-stage companies use vCISO services to get executive security leadership without the cost of a full-time hire, typically for compliance programs, risk management, and customer security requirements.
Need more than a definition?
Z Cyber runs security and compliance programs for regulated mid-market companies: a dedicated team, led by a named advisor, on the Glance platform.
Meet Your Security Team →