Reference
GRC & Cybersecurity Glossary
Plain-English definitions of the standards, regulators, frameworks and technical terms MAST consultants work with every day.
35 terms · maintained by MAST's practice leads.
Center for Internet Security's 18 prioritised cybersecurity controls.
The governance, policies, processes and controls that an organisation uses to manage information security risk.
Business Continuity Management System (BCMS) standard.
Quality Management System (QMS) standard.
International standard for an Information Security Management System (ISMS).
Implementation guidance for the controls referenced in ISO/IEC 27001 Annex A.
US NIST Cybersecurity Framework with six functions: Govern, Identify, Protect, Detect, Respond, Recover.
Mandatory security standard for any organisation that stores, processes or transmits cardholder data.
Contract required under HIPAA between a Covered Entity and any third party that handles PHI on its behalf.
Privacy Information Management System (PIMS) extension to ISO/IEC 27001.
Any health information that can identify an individual, regulated under HIPAA.
PCI SSC-accredited individual or firm authorised to perform PCI DSS Report on Compliance audits.
PCI DSS validation route for merchants below Level 1 thresholds.
AICPA attestation report on a service organisation's Trust Services Criteria controls.
Mandatory ISO 27001 document listing applicable Annex A controls with justification for inclusion or exclusion.
AICPA criteria used to evaluate the design and operating effectiveness of a service organisation's controls for a SOC 2 report.
Mandatory healthcare cybersecurity standard issued by the Abu Dhabi Department of Health.
Central Bank of the UAE's mandatory cybersecurity standard for licensed financial institutions.
India's omnibus personal data protection law enacted in 2023.
EU regulation classifying and governing AI systems based on risk.
EU/EEA regulation governing the processing of personal data.
US federal law governing the protection of Protected Health Information (PHI).
KSA mandatory cybersecurity controls for OT/ICS environments.
UAE national cybersecurity authority that publishes the Information Assurance (IA) Standards.
Saudi Central Bank cybersecurity framework applicable to all SAMA-regulated entities.
PCI DSS term for the people, processes and technology that store, process or transmit cardholder data.
Capability combining forensic preservation and analysis with incident containment and recovery.
Industry-standard list of the most critical web application security risks.
Reference architecture for industrial control system network segmentation, organised in levels 0–5.
Mandatory annual security attestation programme for SWIFT-connected institutions.
Replacing sensitive data (e.g. PAN) with a non-sensitive token that has no exploitable meaning outside the token vault.
Combined service covering automated vulnerability scanning and manual exploitation testing.
Subscription-based engagement that provides CISO-level leadership without a full-time hire.