Glossary
Plain-English definitions of the terms that show up in compliance programs, audits, and engineering measurement — each with the context an operator actually needs.
Agent health
Agent health is the operational reliability of an AI agent in production — whether it stays within its guardrails, succeeds at tasks, and behaves predictably.
Continuous control monitoring, defined
Continuous control monitoring defined: how CCM differs from point-in-time audits, what automation can and cannot cover, and why coverage honesty matters.
Control register
A control register is the master inventory of an organization's controls — each with an owner, frequency, risk mapping, and test procedure. Learn what it holds.
COSO (Committee of Sponsoring Organizations)
COSO is the framework most companies use to design and evaluate internal control over financial reporting. Learn its five components and seventeen principles.
Deficiency evaluation
Deficiency evaluation is how a control failure is classified as a deficiency, significant deficiency, or material weakness. Learn how severity is assessed.
Deployment frequency, defined
Deployment frequency is how often a team ships to production. Learn how it is measured, how DORA tiers teams by it, and why it is read alongside the other keys.
DORA metrics, defined
The four DORA metrics defined — deployment frequency, lead time, change failure rate, time to restore — and the measurement pitfalls that corrupt them.
Evidence-based compliance, defined
Evidence-based compliance proves each control with verifiable, traceable artifacts, not self-attestation. Learn how it works and why auditors rely on it.
Information produced by the entity (IPE), defined
Information produced by the entity (IPE), explained: completeness and accuracy support, why every report used in a control needs it, and how baselining works.
IT general controls (ITGC), defined
IT general controls (ITGC) explained: the four domains — access, change, development, operations — why auditors rely on them, and what happens when they fail.
Risk appetite, defined
Risk appetite is the amount and type of risk an organization is willing to pursue or retain. Learn how it differs from risk tolerance and risk capacity.
SBOM (software bill of materials)
A software bill of materials (SBOM) is a machine-readable inventory of the components in a piece of software. Learn what an SBOM contains and why it matters.
Section 302 certification, defined
SOX Section 302, explained: what the CEO and CFO certify each quarter, how sub-certification cascades work, and why the sign-off needs a durable record.
Segregation of duties (SoD), defined
Segregation of duties, explained: classic conflicts like change-maker vs approver and grantor vs reviewer, compensating controls, and how SoD is evidenced.
Statement of Applicability (SoA), defined
The Statement of Applicability is the mandatory ISO/IEC 27001 document listing every Annex A control, whether it applies, why, and its implementation status.
Technical debt, defined
Technical debt defined: Cunningham's metaphor, deliberate vs inadvertent debt, how to measure it honestly, and why it belongs in board reporting.
Technical due diligence, defined
Technical due diligence defined: what tech DD examines in M&A and investment, consultancy-led vs platform-supported approaches, and what neither can replace.
Trust center, defined
A trust center is a public page where a company publishes its security, compliance, and privacy posture — certifications, subprocessors, and security documentation.
What are complementary user entity controls (CUECs)?
Complementary user entity controls (CUECs) are controls a SOC report expects the customer to implement so the provider's controls can operate as intended.
What is change failure rate?
Change failure rate is the share of production deployments that cause a failure needing remediation. Learn how this DORA metric is calculated and why it matters.
What is lead time for changes?
Lead time for changes is the time from a code commit to running in production. Learn how this DORA metric is measured and what drives long delivery times.
What is MTTR (mean time to restore)?
MTTR (mean time to restore) is the average time to recover service after a production failure. Learn how this DORA metric is calculated and what it signals.
What is the SPACE framework?
The SPACE framework measures developer productivity across five dimensions: satisfaction, performance, activity, communication, and efficiency — not raw output.