---
title: "Security & Compliance Glossary"
description: "Clear definitions and practical guides for the concepts that matter."
canonical: https://www.orbiqhq.com/glossary
html: https://www.orbiqhq.com/glossary
publisher: Orbiq GmbH
language: en
---
# Security & Compliance Glossary

Clear definitions and practical guides for the concepts that matter.

- [Risk Management Frameworks: Complete Guide for 2026](/glossary/risk-management-frameworks.md) - Compare ISO 31000, NIST RMF, COSO ERM, COBIT 2019, ISO 27005, and FAIR — the major risk management frameworks for NIS2, DORA, and ISO 27001 compliance in 2026.
- [Compliance Automation: How to Automate Compliance in 2026](/glossary/compliance-automation.md) - A practical guide to compliance automation — what it is, what it automates, how it differs from GRC tools, which frameworks it supports (ISO 27001, SOC 2, NIS2, DORA), and how to evaluate compliance automation platforms.
- [Third-Party Risk Management (TPRM): Definition](/glossary/third-party-risk-management.md) - A practical guide to third-party risk management — what it is, why it matters, how to build a TPRM programme, key frameworks and regulations (NIS2, DORA, ISO 27001), and how to move from manual vendor assessments to scalable trust operations.
- [Information Security Policy: What to Include](/glossary/information-security-policy.md) - A practical guide to information security policies — what they are, why they matter, what to include, how to write one that meets ISO 27001, NIS2, and SOC 2 requirements, and how to keep it effective beyond the initial certification.
- [Vendor Risk Assessment: How to Evaluate Third Parties](/glossary/vendor-risk-assessment.md) - A practical guide to vendor risk assessments — what they are, when to conduct them, what to evaluate, how to score vendor risk, and how to meet ISO 27001, NIS2, and DORA third-party requirements.
- [ISMS: What Is an Information Security Management System?](/glossary/isms.md) - A practical guide to Information Security Management Systems (ISMS) — what they are, how they work, what ISO 27001 requires, how to implement one, and how an ISMS relates to NIS2, DORA, and SOC 2 compliance.
- [SOC 2 Compliance: Who Needs It and How to Get Certified](/glossary/soc-2-compliance.md) - A practical guide to SOC 2 compliance — what it is, how it differs from ISO 27001, what the Trust Services Criteria require, how the audit process works, and what European companies need to know about SOC 2 in a NIS2 and DORA world.
- [ISO 27001 Certification: Requirements and How to Get It](/glossary/iso-27001-certification.md) - A practical guide to ISO 27001 certification — what it covers, how the audit works, what Annex A controls require, how it relates to NIS2 and DORA, and what European companies need to know about achieving and maintaining certification.
- [Security Questionnaires: How to Handle and Automate Them](/glossary/security-questionnaire.md) - A practical guide to security questionnaires — what they are, why buyers send them, what they typically ask, how to respond efficiently, and how automation and Trust Centers are replacing the manual questionnaire process.
- [Trust Center: Why You Need One and How to Build It](/glossary/trust-center.md) - A practical guide to Trust Centers — what they are, how they differ from GRC tools, what to publish, how they accelerate B2B sales, and why European companies need one for NIS2, DORA, and enterprise buyer requirements.
- [Data Sovereignty: What It Means for European Companies](/glossary/data-sovereignty.md) - A practical guide to data sovereignty — what it is, how it differs from data residency and data localisation, why EU regulations demand it, and how European companies ensure sovereign control over their data.
- [Penetration Testing: How It Works and Why You Need It](/glossary/penetration-testing.md) - A practical guide to penetration testing — what it is, the different types, how the process works, how often to test, what to do with results, and how pen testing fits into compliance frameworks like ISO 27001, SOC 2, NIS2, and DORA.
- [GDPR Compliance: Requirements and How to Achieve It](/glossary/gdpr-compliance.md) - A practical guide to GDPR compliance — what the regulation requires, how it applies to B2B SaaS companies, key obligations around data processing, data subject rights, international transfers, and how to demonstrate compliance to enterprise buyers.
- [Incident Response: How to Build a Plan That Works](/glossary/incident-response.md) - A practical guide to incident response — what it involves, how to build an incident response plan, the phases of handling security incidents, regulatory requirements under NIS2, DORA, and ISO 27001, and how to communicate incidents to customers and regulators.
- [NIS2 Compliance: Requirements, Scope and How to Prepare](/glossary/nis2-compliance.md) - A practical guide to NIS2 compliance — what the directive requires, which organisations are affected, key obligations around risk management, incident reporting, supply chain security, and how to demonstrate compliance to regulators and buyers.
- [DORA Compliance: Requirements, Scope and How to Prepare](/glossary/dora-compliance.md) - A practical guide to DORA compliance — what the Digital Operational Resilience Act requires, which financial entities and ICT providers are affected, key obligations around ICT risk management, incident reporting, resilience testing, and third-party risk management.
- [Cyber Resilience Act (CRA): Requirements and How to Prepare](/glossary/cyber-resilience-act.md) - A practical guide to the EU Cyber Resilience Act — what the CRA requires for products with digital elements, who is affected, essential security requirements, conformity assessment procedures, and how software vendors can prepare.
- [Zero Trust Architecture: Core Principles and Rollout](/glossary/zero-trust-architecture.md) - A practical guide to Zero Trust architecture — what it is, how it differs from perimeter-based security, core principles like least privilege and micro-segmentation, implementation frameworks, and how B2B companies can adopt Zero Trust to meet compliance requirements.
- [Cloud Security Posture Management (CSPM): How to Implement](/glossary/cloud-security-posture-management.md) - A practical guide to Cloud Security Posture Management — what CSPM is, how it detects misconfigurations, core capabilities, how it fits into cloud security architecture, and how B2B SaaS companies can use CSPM to meet compliance requirements.
- [Supply Chain Security: How to Manage Supplier Risk](/glossary/supply-chain-security.md) - A practical guide to supply chain security — what it is, why supply chain attacks are increasing, key risk categories, how to assess and manage third-party risk, regulatory requirements under NIS2 and DORA, and how B2B companies can build resilient supply chains.
- [Business Continuity Planning (BCP): How to Build One](/glossary/business-continuity-planning.md) - A practical guide to Business Continuity Planning — what BCP is, how it differs from disaster recovery, key components of a business continuity plan, how BCP maps to ISO 27001, NIS2, and DORA requirements, and how B2B companies can build resilience against disruptions.
- [Security Audit: Types, Process and How to Prepare](/glossary/security-audit.md) - A practical guide to security audits — what they are, types of security audits (internal, external, compliance), the audit process, how to prepare for ISO 27001, SOC 2, and NIS2 audits, and how B2B companies can use audit readiness as a competitive advantage.
- [Access Control: Models, Best Practices and Compliance](/glossary/access-control.md) - A practical guide to access control — what it is, access control models (RBAC, ABAC, MAC, DAC), the principle of least privilege, how access control maps to ISO 27001, SOC 2, NIS2, and DORA requirements, and how B2B companies can implement effective access management.
- [Security Awareness Training: How to Build a Programme](/glossary/security-awareness-training.md) - A practical guide to security awareness training — what it is, why it matters for compliance and risk reduction, key topics to cover, how to measure effectiveness, compliance requirements under ISO 27001, SOC 2, NIS2, and DORA, and how B2B companies can build a security-conscious culture.
- [Data Classification: Levels, Frameworks and Implementation](/glossary/data-classification.md) - A practical guide to data classification — what it is, classification levels, how to build a data classification scheme, regulatory requirements under ISO 27001, SOC 2, NIS2, GDPR, and DORA, and how B2B companies can use data classification to improve security and demonstrate compliance.
- [Encryption: Definition and Compliance Guide](/glossary/encryption.md) - Learn how encryption protects data at rest, in transit, and in use. Covers AES, RSA, TLS, key management, and compliance requirements under ISO 27001, SOC 2, NIS2, DORA, and GDPR.
- [Vulnerability Management: Definition and Compliance Guide](/glossary/vulnerability-management.md) - Learn how to build a vulnerability management programme that satisfies ISO 27001, SOC 2, NIS2, and DORA. Covers scanning, prioritisation, remediation SLAs, and audit evidence.
- [Endpoint Security: Definition and Compliance Guide](/glossary/endpoint-security.md) - Learn how to protect laptops, servers, and mobile devices with modern endpoint security. Covers EDR, XDR, MDM, hardening baselines, and compliance requirements under ISO 27001, SOC 2, NIS2, and DORA.
- [SIEM: The Complete Guide for Security and Compliance Teams](/glossary/siem.md) - Learn how to select, deploy, and operate a SIEM for threat detection, incident response, and compliance evidence. Covers log sources, detection rules, SOAR integration, and framework requirements under ISO 27001, SOC 2, NIS2, and DORA.
- [Identity and Access Management (IAM): Definition](/glossary/identity-and-access-management.md) - Learn how to implement identity and access management that satisfies ISO 27001, SOC 2, NIS2, and DORA. Covers SSO, MFA, RBAC, ABAC, privileged access, identity governance, and audit evidence.
- [Disaster Recovery: Definition and Compliance Guide](/glossary/disaster-recovery.md) - Learn how to build and test disaster recovery plans that satisfy ISO 27001, SOC 2, NIS2, and DORA. Covers RPO, RTO, DR strategies, cloud DR, testing approaches, and audit evidence.
- [Network Security: Definition and Compliance Guide](/glossary/network-security.md) - Learn how to implement network security controls that satisfy ISO 27001, SOC 2, NIS2, and DORA. Covers firewalls, segmentation, IDS/IPS, VPN, DNS security, and compliance evidence.
- [DevSecOps: Definition and Compliance Guide](/glossary/devsecops.md) - Learn how to integrate security into your CI/CD pipeline and satisfy ISO 27001, SOC 2, NIS2, and DORA requirements. Covers SAST, DAST, SCA, container security, IaC scanning, and compliance evidence.
- [API Security: Definition and Compliance Guide](/glossary/api-security.md) - Learn how to secure APIs and satisfy ISO 27001, SOC 2, NIS2, and DORA requirements. Covers authentication, rate limiting, input validation, OWASP API Top 10, API gateways, and compliance evidence.
- [Threat Modeling: Definition and Compliance Guide](/glossary/threat-modeling.md) - Learn how to implement threat modeling that satisfies ISO 27001, SOC 2, NIS2, and DORA. Covers STRIDE, PASTA, attack trees, data flow diagrams, risk assessment, and compliance evidence.
- [Data Privacy: Definition and Compliance Guide](/glossary/data-privacy.md) - Learn how to implement data privacy controls that satisfy GDPR, ISO 27001, SOC 2, NIS2, and DORA. Covers data classification, consent management, DPIAs, data subject rights, and compliance evidence.
- [Security Operations Center (SOC): Definition](/glossary/security-operations-center.md) - Learn how to build and operate a Security Operations Center that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers SOC models, SIEM integration, incident detection, threat hunting, and compliance evidence.
- [Multi-Factor Authentication (MFA): Definition](/glossary/multi-factor-authentication.md) - Learn how to implement multi-factor authentication that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers MFA methods, FIDO2/WebAuthn, conditional access, phishing-resistant MFA, and compliance evidence.
- [Privileged Access Management (PAM): Definition](/glossary/privileged-access-management.md) - Learn how to implement privileged access management that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers PAM architecture, session management, just-in-time access, credential vaulting, and compliance evidence.
- [Cloud Security: Definition and Compliance Guide](/glossary/cloud-security.md) - Learn how to implement cloud security controls that satisfy ISO 27001, SOC 2, NIS2, and DORA requirements. Covers shared responsibility, cloud-native security, CSPM, workload protection, and compliance evidence.
- [Business Impact Analysis (BIA): Definition](/glossary/business-impact-analysis.md) - Learn how to conduct a business impact analysis that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers BIA methodology, RTO/RPO determination, critical process identification, and compliance evidence.
- [Cyber Insurance: Definition and Compliance Guide](/glossary/cyber-insurance.md) - Learn how cyber insurance works, what it covers, and how it connects to ISO 27001, SOC 2, NIS2, and DORA compliance. Covers policy types, coverage gaps, application requirements, and premium reduction strategies.
- [Log Management: Definition and Compliance Guide](/glossary/log-management.md) - Learn how to implement log management that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers log collection, retention, analysis, SIEM integration, and compliance evidence.
- [Patch Management: Definition and Compliance Guide](/glossary/patch-management.md) - Learn how to implement patch management that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers patching strategies, SLA timelines, vulnerability prioritisation, and compliance evidence.
- [Ransomware Protection: Definition and Compliance Guide](/glossary/ransomware-protection.md) - Learn how to implement ransomware protection that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers prevention strategies, backup resilience, incident response, recovery planning, and compliance evidence.
- [Continuous Monitoring: Definition and Compliance Guide](/glossary/continuous-monitoring.md) - Learn how to implement continuous monitoring that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers monitoring strategies, control effectiveness, automated evidence collection, and compliance reporting.
- [Change Management: Definition and Compliance Guide](/glossary/change-management.md) - Learn how to implement change management that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers change control processes, CAB reviews, risk assessment, rollback planning, and compliance evidence.
- [Role-Based Access Control (RBAC): Definition](/glossary/role-based-access-control.md) - Learn how to implement role-based access control that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers RBAC design, role hierarchy, least privilege, access reviews, and compliance evidence.
- [Data Loss Prevention (DLP): Definition and Compliance Guide](/glossary/data-loss-prevention.md) - Learn how to implement data loss prevention that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers DLP strategies, data classification, policy design, monitoring channels, and compliance evidence.
- [Security Posture Management: Definition and Compliance Guide](/glossary/security-posture-management.md) - Learn how to implement security posture management that satisfies ISO 27001, SOC 2, NIS2, and DORA requirements. Covers posture assessment, control effectiveness, gap analysis, risk scoring, and compliance reporting.