GLOSSARY
The vocabulary, minus the jargon.
Compliance writing assumes a vocabulary most people were never taught. These are the terms as this site uses them, in plain language.
The basics
- GRC
- Governance, risk and compliance — the discipline of proving that an organization is run within the rules that bind it: laws, standards, and its own policies.
- Control
- A specific safeguard you operate — "admin access requires multi-factor authentication" is a control. Regulations demand outcomes; controls are how you actually achieve them.
- Framework
- A published set of requirements — NIS2, ISO 27001, SOC 2. Some are law, some are voluntary standards customers demand.
- Evidence
- The proof that a control is actually operating — a configuration export, a log, a signed policy. Auditors do not take your word; they take evidence.
- Gap analysis
- Comparing what a framework demands against what you actually do, and listing the difference. The list is the work plan.
- Audit trail
- The tamper-evident record of who did what, when — what makes a claim defensible months later, to an auditor or a regulator.
The NIS2 vocabulary
- Transposition
- An EU directive is not itself law — each member state writes it into national law, and those national versions differ. NIS2 has 27 of them. The national law is what binds you.
- Essential entity
- The stricter NIS2 tier — typically large organizations in Annex I sectors. Supervised proactively: regulators can inspect without waiting for an incident.
- Important entity
- The lighter NIS2 tier — medium organizations in Annex I sectors, medium and large in Annex II. Supervised reactively, usually after an incident or complaint.
- CSIRT
- Computer Security Incident Response Team — the national body that receives your incident reports under NIS2. Each member state names its own.
- Applicability
- The answer to "does this regulation bind us?" — decided by your sector, size, countries of operation and entity type, and re-decided as any of those change.
The platform vocabulary
- Crosswalk
- The mapping from one control to every framework that cites it. Implement multi-factor authentication once and the crosswalk lets it count toward NIS2, ISO 27001 and SOC 2 simultaneously.
- Private inference
- Running AI models on infrastructure you control rather than a shared third-party AI API. TruSecure's runs on hardware it operates in OVH's French and German datacenters.
- Open core
- A business model where the real core of the product is open source — TruSecure Community Edition — and the paid product is the same core, operated and supported as a managed service.
- Risk acceptance
- A named person deliberately choosing to live with a known risk, recorded with a reason and a review date. The opposite of ignoring it.
- Sub-processor
- A third party that processes data on your vendor's behalf. Your vendor's sub-processors are part of your supply-chain risk — TruSecure lists its own publicly.
- DPA (Data Processing Addendum)
- The contract that governs how a vendor processes personal data for you, required by GDPR Article 28.
- Point-in-time vs. continuous
- An audit photograph versus a live feed. Point-in-time says you were compliant on a date; continuous means the control state is monitored as it changes.
The short answer
Plain-language definitions of GRC and NIS2 vocabulary — controls, evidence, transpositions, essential and important entities, crosswalks, private inference — written for readers who do not work in compliance.