Compliance and resilience glossary
Plain-language definitions of the terms that show up across Lavawall®, from the public-sector and privacy acronyms to the resilience and assurance vocabulary. Alphabetical, and written to be read by a person, not a lawyer.
- 3PAO
- Third-Party Assessment Organization. An independent, accredited assessor that verifies a cloud product meets a program's security requirements. Required at GovRAMP's Ready level and above, and throughout FedRAMP.
- ADA Title II
- The part of the Americans with Disabilities Act covering state and local government. A 2024 US Department of Justice rule requires their websites and mobile apps to meet WCAG 2.1 Level AA, with compliance dates in 2027 and 2028.
- APL
- Approved Products List. A published list of cloud products that have earned a given authorization status, so a government buyer can confirm a product's standing at a glance.
- BAA
- Business Associate Agreement. The HIPAA contract between a covered entity and a vendor that handles protected health information on its behalf, setting out each side's safeguards and breach duties.
- BCP
- Business Continuity Plan. The plan for keeping the organization running through a disruption, tying together recovery priorities, roles, and the incident-response and disaster-recovery plans.
- BIA
- Business Impact Analysis. The exercise that works out which processes matter most and what it costs when they stop, producing the recovery targets everything else is built on.
- CCCS
- Canadian Centre for Cyber Security. Canada's national cyber-security authority, and its baseline set of controls for small and medium organizations.
- CCSPA
- Critical Cyber Systems Protection Act. Canada's Bill C-8 law creating cyber-security duties for designated operators in federally regulated sectors: telecommunications, banking, energy, and transportation.
- CIRO
- Canadian Investment Regulatory Organization. The national self-regulatory body for investment dealers, formed in 2023 from IIROC and the MFDA, which sets cyber and incident-reporting expectations for its members.
- CJI
- Criminal Justice Information. The data the FBI CJIS Security Policy protects, such as criminal history records and related information.
- CJI Data
- The underlying records that the CJIS safeguards protect. See CJI.
- CJIS
- Criminal Justice Information Services. The FBI division that runs the national criminal-justice databases and publishes the CJIS Security Policy.
- CJIS Security Policy
- The FBI's security requirements for any agency or contractor that touches criminal justice information. Version 6.1 is current; parts of the older 5.9 requirements still apply and are still sanctionable.
- Continuous control monitoring
- Checking that controls are actually working on an ongoing basis, from live system data, rather than confirming them once a year and assuming they held.
- Covered entity
- Under HIPAA, a health plan, health-care clearinghouse, or health-care provider that transmits health information electronically. A covered entity is directly bound by the HIPAA rules.
- CSA (CJIS Systems Agency)
- The state-level agency responsible for administering CJIS access and compliance within its state. In Iowa, that is the Department of Public Safety.
- CSA Staff Notice 33-322
- The Canadian Securities Administrators' cyber-security expectations for registered firms, read into their existing obligation to maintain a reasonable compliance system.
- CSO (CJIS Systems Officer)
- The person at a CJIS Systems Agency accountable for the agency's CJIS compliance and day-to-day administration.
- Dependency map
- A picture of which systems and processes rely on which others, used to find single points of failure and to set the order in which things must be recovered.
- DPA
- Data Processing Agreement. The contract term that obliges a supplier to protect the personal information you give it. A DPA published on a vendor's trust centre means one is available; it does not mean your organization has executed it or is covered.
- DRP
- Disaster Recovery Plan. The technical plan for restoring systems and data after an outage: what to restore, in what order, and to what recovery targets.
- Evidence
- The records that prove a control was actually in place and operating: logs, configuration snapshots, access reviews, and the like, ideally timestamped and exportable for an auditor.
- FedRAMP
- The US federal program that authorizes cloud products for sale to federal agencies. It is the federal counterpart to GovRAMP, which serves state and local government.
- FINTRAC
- Financial Transactions and Reports Analysis Centre of Canada. Canada's financial-intelligence unit, which sets anti-money-laundering duties (know-your-client, reporting, record-keeping) for reporting entities.
- FIPPA
- Freedom of Information and Protection of Privacy Act. A provincial public-sector access-and-privacy law. British Columbia's version requires a privacy management program and, in many cases, Canadian data residency.
- FOIP
- Freedom of Information and Protection of Privacy. Alberta's former public-sector privacy law, replaced on 11 June 2025 by the Protection of Privacy Act and the Access to Information Act. Copy that still cites FOIP is describing a repealed statute.
- GCC (Government Community Cloud)
- A cloud environment Microsoft runs for US public-sector customers, segregated to meet government data-handling requirements.
- GCC High
- A higher-assurance Government Community Cloud environment for US customers with ITAR or controlled-unclassified-information obligations, with tighter personnel screening and data-residency controls.
- GovRAMP (formerly StateRAMP)
- A standardized security assessment program for cloud products sold to US state and local government. StateRAMP renamed to GovRAMP in 2025; statuses, requirements, and existing authorizations carried over unchanged. Use both names on first mention.
- HIA (Health Information Act, Alberta)
- Alberta's law governing custodians who hold health information, with rules on collection, use, disclosure, and safeguards.
- HIPAA Security Rule
- The US standard for safeguarding electronic protected health information, setting administrative, physical, and technical safeguards for covered entities and their business associates.
- IRS Publication 1075
- The IRS's safeguards for any organization that receives Federal Tax Information. It is built on NIST SP 800-53 with IRS-specific additions, and the information must never leave the United States.
- ITAR
- International Traffic in Arms Regulations. US export-control rules that, among other things, require certain data to be handled only by US persons on US soil.
- LASO (Local Agency Security Officer)
- The person at a local agency, often a police department, responsible for CJIS security compliance and the point of contact for it.
- Law 25 (Quebec)
- Quebec's private-sector privacy law (Bill 64), with consent, breach-reporting, privacy-officer, and privacy-impact-assessment duties, and penalties up to 4% of worldwide turnover.
- Master agreement
- The overarching contract between two parties that sets the general terms, under which specific orders or statements of work then sit.
- MDSAP
- Medical Device Single Audit Program. A single regulatory audit of a device manufacturer's quality system that several countries' regulators accept. It is an audit route, not a standard you comply with.
- MFIPPA
- Municipal Freedom of Information and Protection of Privacy Act. Ontario's access-and-privacy law for municipalities and local boards, amended by Bill 194.
- MTD
- Maximum Tolerable Downtime. The longest a process can be down before the damage is unacceptable. If a recovery target is longer than the MTD, the plan does not add up.
- OPC
- Office of the Privacy Commissioner of Canada. The federal regulator that oversees PIPEDA and investigates privacy complaints.
- PHI
- Protected Health Information. Health information tied to an individual that HIPAA protects.
- PHIPA
- Personal Health Information Protection Act. Ontario's health-privacy law for health-information custodians.
- PIPA (Alberta and BC)
- Personal Information Protection Act. The private-sector privacy law in Alberta and, separately, in British Columbia, each substantially similar to PIPEDA.
- PIPEDA
- Personal Information Protection and Electronic Documents Act. Canada's federal private-sector privacy law, based on ten fair-information principles, with a real-risk-of-significant-harm test for breach reporting.
- POPA
- Protection of Privacy Act. Alberta's public-sector privacy law, in force 11 June 2025, which requires a documented privacy management program (section 25) among other duties.
- QMSR
- Quality Management System Regulation. The FDA's quality-system rule for medical devices, in force 2 February 2026, incorporating ISO 13485:2016 by reference. It is a quality system, not a cybersecurity framework.
- RPO
- Recovery Point Objective. How much data, measured in time, you can afford to lose. An RPO of one hour means backups must be no more than an hour apart.
- RTO
- Recovery Time Objective. How quickly a process must be back after it fails. It has to be shorter than the maximum tolerable downtime.
- SAQ (PCI self-assessment questionnaire)
- A PCI DSS self-assessment questionnaire. Which version applies (A, A-EP, B, B-IP, C, C-VT, or D) depends on how a merchant handles card data.
- Section 524B (FDA premarket cybersecurity)
- The US law requiring cybersecurity content in a medical-device premarket submission: a monitoring and coordinated-vulnerability-disclosure plan, secure design, and a software bill of materials. Mandatory since 29 March 2023.
- Security Addendum
- In CJIS, the CJIS Security Addendum: the contract a private contractor signs to handle criminal justice information, binding its staff to the policy and to fingerprint-based screening.
- Single point of failure
- A component whose failure alone takes down a process, because nothing else can carry the load. Continuity planning looks for these first.
- SLED
- State, Local, and Education. The US public-sector market below the federal level, and the buyers GovRAMP serves.
- Sub-processor
- A third party a vendor uses to help process your data. Privacy law and contracts usually require the vendor to disclose its sub-processors and pass the same duties down to them.
- Tabletop exercise
- A walk-through drill where a team talks through its response to a scenario, such as a breach or an outage, to test the plan before a real event.
- Trust centre
- A public page where a vendor publishes its security posture, certifications, and documents, so customers can answer their due-diligence questions once.
- TX-RAMP
- The State of Texas's own cloud-security assessment program, its equivalent of GovRAMP for products sold to Texas agencies.
- Type I and Type II
- The two SOC 2 report types. Type I checks that controls are suitably designed at a point in time; Type II checks that they operated effectively over a period, usually 6 to 12 months.
- UAR
- User Access Review. A periodic check that each person still needs the access they have, with the approvals recorded as evidence.
Missing a term you expected? The framework catalogue defines each framework in full, and the GRC page shows how they fit together. Last updated 28 August 2026.