📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Compliance and resilience glossary

Plain-language definitions of the terms that show up across Lavawall®, from the public-sector and privacy acronyms to the resilience and assurance vocabulary. Alphabetical, and written to be read by a person, not a lawyer.

3PAO
Third-Party Assessment Organization. An independent, accredited assessor that verifies a cloud product meets a program's security requirements. Required at GovRAMP's Ready level and above, and throughout FedRAMP.
ADA Title II
The part of the Americans with Disabilities Act covering state and local government. A 2024 US Department of Justice rule requires their websites and mobile apps to meet WCAG 2.1 Level AA, with compliance dates in 2027 and 2028.
APL
Approved Products List. A published list of cloud products that have earned a given authorization status, so a government buyer can confirm a product's standing at a glance.
BAA
Business Associate Agreement. The HIPAA contract between a covered entity and a vendor that handles protected health information on its behalf, setting out each side's safeguards and breach duties.
BCP
Business Continuity Plan. The plan for keeping the organization running through a disruption, tying together recovery priorities, roles, and the incident-response and disaster-recovery plans.
BIA
Business Impact Analysis. The exercise that works out which processes matter most and what it costs when they stop, producing the recovery targets everything else is built on.
CCCS
Canadian Centre for Cyber Security. Canada's national cyber-security authority, and its baseline set of controls for small and medium organizations.
CCSPA
Critical Cyber Systems Protection Act. Canada's Bill C-8 law creating cyber-security duties for designated operators in federally regulated sectors: telecommunications, banking, energy, and transportation.
CIRO
Canadian Investment Regulatory Organization. The national self-regulatory body for investment dealers, formed in 2023 from IIROC and the MFDA, which sets cyber and incident-reporting expectations for its members.
CJI
Criminal Justice Information. The data the FBI CJIS Security Policy protects, such as criminal history records and related information.
CJI Data
The underlying records that the CJIS safeguards protect. See CJI.
CJIS
Criminal Justice Information Services. The FBI division that runs the national criminal-justice databases and publishes the CJIS Security Policy.
CJIS Security Policy
The FBI's security requirements for any agency or contractor that touches criminal justice information. Version 6.1 is current; parts of the older 5.9 requirements still apply and are still sanctionable.
Continuous control monitoring
Checking that controls are actually working on an ongoing basis, from live system data, rather than confirming them once a year and assuming they held.
Covered entity
Under HIPAA, a health plan, health-care clearinghouse, or health-care provider that transmits health information electronically. A covered entity is directly bound by the HIPAA rules.
CSA (CJIS Systems Agency)
The state-level agency responsible for administering CJIS access and compliance within its state. In Iowa, that is the Department of Public Safety.
CSA Staff Notice 33-322
The Canadian Securities Administrators' cyber-security expectations for registered firms, read into their existing obligation to maintain a reasonable compliance system.
CSO (CJIS Systems Officer)
The person at a CJIS Systems Agency accountable for the agency's CJIS compliance and day-to-day administration.
Dependency map
A picture of which systems and processes rely on which others, used to find single points of failure and to set the order in which things must be recovered.
DPA
Data Processing Agreement. The contract term that obliges a supplier to protect the personal information you give it. A DPA published on a vendor's trust centre means one is available; it does not mean your organization has executed it or is covered.
DRP
Disaster Recovery Plan. The technical plan for restoring systems and data after an outage: what to restore, in what order, and to what recovery targets.
Evidence
The records that prove a control was actually in place and operating: logs, configuration snapshots, access reviews, and the like, ideally timestamped and exportable for an auditor.
FedRAMP
The US federal program that authorizes cloud products for sale to federal agencies. It is the federal counterpart to GovRAMP, which serves state and local government.
FINTRAC
Financial Transactions and Reports Analysis Centre of Canada. Canada's financial-intelligence unit, which sets anti-money-laundering duties (know-your-client, reporting, record-keeping) for reporting entities.
FIPPA
Freedom of Information and Protection of Privacy Act. A provincial public-sector access-and-privacy law. British Columbia's version requires a privacy management program and, in many cases, Canadian data residency.
FOIP
Freedom of Information and Protection of Privacy. Alberta's former public-sector privacy law, replaced on 11 June 2025 by the Protection of Privacy Act and the Access to Information Act. Copy that still cites FOIP is describing a repealed statute.
GCC (Government Community Cloud)
A cloud environment Microsoft runs for US public-sector customers, segregated to meet government data-handling requirements.
GCC High
A higher-assurance Government Community Cloud environment for US customers with ITAR or controlled-unclassified-information obligations, with tighter personnel screening and data-residency controls.
GovRAMP (formerly StateRAMP)
A standardized security assessment program for cloud products sold to US state and local government. StateRAMP renamed to GovRAMP in 2025; statuses, requirements, and existing authorizations carried over unchanged. Use both names on first mention.
HIA (Health Information Act, Alberta)
Alberta's law governing custodians who hold health information, with rules on collection, use, disclosure, and safeguards.
HIPAA Security Rule
The US standard for safeguarding electronic protected health information, setting administrative, physical, and technical safeguards for covered entities and their business associates.
IRS Publication 1075
The IRS's safeguards for any organization that receives Federal Tax Information. It is built on NIST SP 800-53 with IRS-specific additions, and the information must never leave the United States.
ITAR
International Traffic in Arms Regulations. US export-control rules that, among other things, require certain data to be handled only by US persons on US soil.
LASO (Local Agency Security Officer)
The person at a local agency, often a police department, responsible for CJIS security compliance and the point of contact for it.
Law 25 (Quebec)
Quebec's private-sector privacy law (Bill 64), with consent, breach-reporting, privacy-officer, and privacy-impact-assessment duties, and penalties up to 4% of worldwide turnover.
Master agreement
The overarching contract between two parties that sets the general terms, under which specific orders or statements of work then sit.
MDSAP
Medical Device Single Audit Program. A single regulatory audit of a device manufacturer's quality system that several countries' regulators accept. It is an audit route, not a standard you comply with.
MFIPPA
Municipal Freedom of Information and Protection of Privacy Act. Ontario's access-and-privacy law for municipalities and local boards, amended by Bill 194.
MTD
Maximum Tolerable Downtime. The longest a process can be down before the damage is unacceptable. If a recovery target is longer than the MTD, the plan does not add up.
OPC
Office of the Privacy Commissioner of Canada. The federal regulator that oversees PIPEDA and investigates privacy complaints.
PHI
Protected Health Information. Health information tied to an individual that HIPAA protects.
PHIPA
Personal Health Information Protection Act. Ontario's health-privacy law for health-information custodians.
PIPA (Alberta and BC)
Personal Information Protection Act. The private-sector privacy law in Alberta and, separately, in British Columbia, each substantially similar to PIPEDA.
PIPEDA
Personal Information Protection and Electronic Documents Act. Canada's federal private-sector privacy law, based on ten fair-information principles, with a real-risk-of-significant-harm test for breach reporting.
POPA
Protection of Privacy Act. Alberta's public-sector privacy law, in force 11 June 2025, which requires a documented privacy management program (section 25) among other duties.
QMSR
Quality Management System Regulation. The FDA's quality-system rule for medical devices, in force 2 February 2026, incorporating ISO 13485:2016 by reference. It is a quality system, not a cybersecurity framework.
RPO
Recovery Point Objective. How much data, measured in time, you can afford to lose. An RPO of one hour means backups must be no more than an hour apart.
RTO
Recovery Time Objective. How quickly a process must be back after it fails. It has to be shorter than the maximum tolerable downtime.
SAQ (PCI self-assessment questionnaire)
A PCI DSS self-assessment questionnaire. Which version applies (A, A-EP, B, B-IP, C, C-VT, or D) depends on how a merchant handles card data.
Section 524B (FDA premarket cybersecurity)
The US law requiring cybersecurity content in a medical-device premarket submission: a monitoring and coordinated-vulnerability-disclosure plan, secure design, and a software bill of materials. Mandatory since 29 March 2023.
Security Addendum
In CJIS, the CJIS Security Addendum: the contract a private contractor signs to handle criminal justice information, binding its staff to the policy and to fingerprint-based screening.
Single point of failure
A component whose failure alone takes down a process, because nothing else can carry the load. Continuity planning looks for these first.
SLED
State, Local, and Education. The US public-sector market below the federal level, and the buyers GovRAMP serves.
Sub-processor
A third party a vendor uses to help process your data. Privacy law and contracts usually require the vendor to disclose its sub-processors and pass the same duties down to them.
Tabletop exercise
A walk-through drill where a team talks through its response to a scenario, such as a breach or an outage, to test the plan before a real event.
Trust centre
A public page where a vendor publishes its security posture, certifications, and documents, so customers can answer their due-diligence questions once.
TX-RAMP
The State of Texas's own cloud-security assessment program, its equivalent of GovRAMP for products sold to Texas agencies.
Type I and Type II
The two SOC 2 report types. Type I checks that controls are suitably designed at a point in time; Type II checks that they operated effectively over a period, usually 6 to 12 months.
UAR
User Access Review. A periodic check that each person still needs the access they have, with the approvals recorded as evidence.

Missing a term you expected? The framework catalogue defines each framework in full, and the GRC page shows how they fit together. Last updated 28 August 2026.

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →