Glossary
Compliance terms, explained plainly
Shared vocabulary makes compliance conversations shorter. These are the terms that come up most often.
- Assessment objective
- A discrete element of a requirement that is evaluated individually during an assessment.
- C3PAO
- A CMMC Third-Party Assessment Organization authorized to conduct formal CMMC assessments.
- CUI
- Controlled Unclassified Information — government-created or owned information requiring safeguarding under law, regulation, or government-wide policy.
- Control
- A safeguard or countermeasure implemented to satisfy a security or governance requirement.
- DIB
- The Defense Industrial Base — the organizations that supply the Department of Defense.
- Evidence
- Documentation or artifacts that substantiate how a requirement is satisfied.
- FCI
- Federal Contract Information — information provided by or generated for the government under a contract, not intended for public release.
- Finding
- A deficiency identified during an assessment or review.
- Gap
- The difference between a requirement's expectation and its current implementation.
- GRC
- Governance, Risk, and Compliance — the disciplines an organization uses to direct, manage risk in, and demonstrate conformance of its operations.
- POA&M
- Plan of Action & Milestones — a structured record of deficiencies with corrective actions, owners, and target dates.
- Remediation
- The work performed to resolve an identified deficiency.
- Risk register
- The maintained list of identified risks, with ownership, rating, treatment, and review dates.
- Scope
- The systems, environments, people, and facilities to which a set of requirements applies.
- SPRS
- The Supplier Performance Risk System, used by the Department of Defense to collect certain supplier assessment information.
- SSP
- System Security Plan — documentation describing a system, its boundary, and how applicable security requirements are satisfied.
- Third-party risk
- Risk introduced through vendors, suppliers, and other external relationships.
Ready to bring your compliance program together?
See how CyberComply can help centralize requirements, evidence, risks, remediation, documentation, and assessment readiness.
