Skip to main content
GLOSSARY

The vocabulary, minus the jargon.

Compliance writing assumes a vocabulary most people were never taught. These are the terms as this site uses them, in plain language.

The basics

GRC
Governance, risk and compliance — the discipline of proving that an organization is run within the rules that bind it: laws, standards, and its own policies.
Control
A specific safeguard you operate — "admin access requires multi-factor authentication" is a control. Regulations demand outcomes; controls are how you actually achieve them.
Framework
A published set of requirements — NIS2, ISO 27001, SOC 2. Some are law, some are voluntary standards customers demand.
Evidence
The proof that a control is actually operating — a configuration export, a log, a signed policy. Auditors do not take your word; they take evidence.
Gap analysis
Comparing what a framework demands against what you actually do, and listing the difference. The list is the work plan.
Audit trail
The tamper-evident record of who did what, when — what makes a claim defensible months later, to an auditor or a regulator.

The NIS2 vocabulary

Transposition
An EU directive is not itself law — each member state writes it into national law, and those national versions differ. NIS2 has 27 of them. The national law is what binds you.
Essential entity
The stricter NIS2 tier — typically large organizations in Annex I sectors. Supervised proactively: regulators can inspect without waiting for an incident.
Important entity
The lighter NIS2 tier — medium organizations in Annex I sectors, medium and large in Annex II. Supervised reactively, usually after an incident or complaint.
CSIRT
Computer Security Incident Response Team — the national body that receives your incident reports under NIS2. Each member state names its own.
Applicability
The answer to "does this regulation bind us?" — decided by your sector, size, countries of operation and entity type, and re-decided as any of those change.

The platform vocabulary

Crosswalk
The mapping from one control to every framework that cites it. Implement multi-factor authentication once and the crosswalk lets it count toward NIS2, ISO 27001 and SOC 2 simultaneously.
Private inference
Running AI models on infrastructure you control rather than a shared third-party AI API. TruSecure's runs on hardware it operates in OVH's French and German datacenters.
Open core
A business model where the real core of the product is open source — TruSecure Community Edition — and the paid product is the same core, operated and supported as a managed service.
Risk acceptance
A named person deliberately choosing to live with a known risk, recorded with a reason and a review date. The opposite of ignoring it.
Sub-processor
A third party that processes data on your vendor's behalf. Your vendor's sub-processors are part of your supply-chain risk — TruSecure lists its own publicly.
DPA (Data Processing Addendum)
The contract that governs how a vendor processes personal data for you, required by GDPR Article 28.
Point-in-time vs. continuous
An audit photograph versus a live feed. Point-in-time says you were compliant on a date; continuous means the control state is monitored as it changes.

The short answer

Plain-language definitions of GRC and NIS2 vocabulary — controls, evidence, transpositions, essential and important entities, crosswalks, private inference — written for readers who do not work in compliance.