Security & Compliance Glossary
Clear, jargon-free definitions of the cybersecurity and compliance terms you'll encounter when securing and certifying your organisation.
GDPR
General Data Protection Regulation
The General Data Protection Regulation (GDPR) is an EU regulation governing the processing of personal data within its territorial scope. It gives people rights over their data and requires controllers and processors to meet applicable duties, including lawful processing and appropriate safeguards. Organisations outside the EU may also fall within its scope in defined circumstances.
HIPAA
Health Insurance Portability and Accountability Act
HIPAA (the Health Insurance Portability and Accountability Act) is a US law whose privacy, security, and breach-notification rules protect health information held by covered entities and their business associates. The rules address permitted uses of protected health information, safeguards for electronic health information, and notification duties for breaches of unsecured protected health information.
ISO 27001
ISO/IEC 27001 Information Security Management
ISO/IEC 27001 is the leading international standard for information security management systems (ISMS). It provides a risk-based framework of policies, procedures, and controls that organisations use to protect the confidentiality, integrity, and availability of information. Certification, issued after an independent audit, shows customers and regulators that security is managed systematically.
Managed IT services
Managed IT services means outsourcing the day-to-day running of an organisation’s IT — monitoring, user support, patching, account and device management, backup and infrastructure operations — to a provider under an ongoing agreement with defined service levels, rather than paying for help each time something breaks.
PCI DSS
Payment Card Industry Data Security Standard
PCI DSS (Payment Card Industry Data Security Standard) is an industry security standard for organisations that store, process, or transmit cardholder data, and for systems that can affect its security. Maintained by the PCI Security Standards Council, it sets technical and operational requirements for protecting payment account data. Validation obligations depend on the applicable payment-brand and acquirer rules.
SIEM
Security Information and Event Management
SIEM (Security Information and Event Management) is software that centralises security logs and events from multiple systems. It can help analysts correlate activity, investigate alerts and produce monitoring evidence when configured for relevant sources. A SIEM provides visibility, not an incident response team, and installing one alone does not establish compliance.
SOC
Security Operations Center
A Security Operations Center (SOC) is an organisational function that monitors, investigates, and coordinates responses to cybersecurity events. It combines analysts, defined processes, and tools such as SIEM to identify and assess suspicious activity. Coverage hours and response responsibilities depend on the operating model; a SOC is not the same thing as a SOC 2 audit report.
SOC 2
System and Organization Controls 2
SOC 2 (System and Organization Controls 2) is an independent attestation report on controls at a service organisation relevant to selected Trust Services Criteria. The criteria cover security, availability, processing integrity, confidentiality, and privacy. A licensed CPA firm issues the report for its intended users; it is not a certification or a security operations center.
VAPT
Vulnerability Assessment and Penetration Testing
VAPT (Vulnerability Assessment and Penetration Testing) combines techniques for identifying potential security weaknesses with authorised testing of whether they can be exploited. Assessments can scan or review systems, networks and applications; penetration tests try attack paths within agreed boundaries. Together, their findings help teams prioritise remediation, but neither guarantees that all weaknesses will be found.
Use the glossary to make a practical decision
Security and compliance terminology often combines an operating capability, a technical tool and an assurance outcome in the same conversation. This glossary separates those concepts. Start with a definition, then read the practical explanation, comparison and misconceptions. The aim is to help business and technical teams agree what work is needed, who owns it and which evidence supports a decision. A definition alone should not be interpreted as legal advice, a certification claim or a complete implementation checklist.
For operational security, begin with VAPT, SOC and SIEM. VAPT helps identify and validate weaknesses within an authorised scope. A SOC investigates security activity and coordinates response. SIEM supports collection and analysis of events. These can complement each other without being substitutes. Agree the systems, access, responsibilities and response decisions relevant to your environment before selecting a service.
For assurance and compliance, distinguish management-system certification, independent attestation and legal or payment-security obligations. ISO 27001 concerns an ISMS; SOC 2 is a CPA controls report. GDPR and HIPAA applicability need assessment of the organisation's role and processing activities. PCI DSS scope depends on the payment environment and relevant responsibilities. A common label used in procurement is not enough to determine which requirements apply.
Each entry includes reference sources and a contextual service link where one is relevant. Use official authorities for the governing requirements and qualified specialists for interpretation. Read related terms when acronyms are easily confused, particularly SOC and SOC 2. If you are discussing work with a provider, ask for a scoped deliverable and clear exclusions. Revisit the definition and the operating boundary when products, customers or suppliers change, rather than treating a programme as complete because a document has been issued.
