All 219 terms
Every term in the Cyber & AI Governance Dictionary, alphabetically. Prefer to browse by domain?
A
AAA (AAA)
Proving who you are, deciding what you can do, and logging what you did.
Account lockout
Temporarily disabling a login after too many failed password attempts.
Accountability
Having someone clearly answerable for an AI system's behavior.
Advanced persistent threat (APT)
A patient, well-resourced attacker that stays hidden in a network over time.
Agentic AI risk
The added risk when an AI doesn't just answer but takes actions on its own.
AI customer
An organization or individual that acquires an AI product or service.
ISO/IEC 22989
AI management system (AIMS)
An organization's ongoing, structured program for governing its AI use.
AI objectives
Specific, measurable goals the AIMS is working toward.
42001 · Clause 6
AI partner
An organization supplying services to an AI producer or provider.
ISO/IEC 22989
AI policy
The top-level, leadership-approved statement of AI governance commitments.
42001 · Clause 5
AI producer
The organization responsible for designing, building, and deploying an AI system.
ISO/IEC 22989
AI provider
An organization that supplies a product or service built on AI.
ISO/IEC 22989
AI red teaming
Deliberately attacking an AI system to find its weaknesses first.
AI risk assessment
Identifying and evaluating the risks a given AI system poses.
42001 · 6.1.2
AI risk treatment
Deciding how to handle each identified AI risk and selecting controls.
42001 · 6.1.3
AI subject
An individual affected by an AI system's decisions or outputs.
ISO/IEC 22989
AI system
A system that generates outputs — predictions, decisions — from defined objectives.
ISO/IEC 22989
AI system impact assessment
Assessing how an AI system affects people, not just the organization's own risk.
42001 · 6.1.4
AI system life cycle
The full span of an AI system's existence, from design to retirement.
ISO/IEC 5338:2023
AIMS scope
The documented boundary of what the AI management system covers.
42001 · Clause 4
Annex A controls
A reference set of AI-specific controls selected based on actual risk.
42001 · Annex A
Annex A.10 — Third-party and customer relationships
Controls for AI risk from suppliers and expectations with customers.
Annex A.10
Annex A.2 — Policies related to AI
Controls for establishing and reviewing an organization's AI policies.
Annex A.2
Annex A.3 — Internal organization
Controls for AI roles, reporting lines, and ethics escalation.
Annex A.3
Annex A.4 — Resources for AI systems
Controls covering the data, tooling, compute, and people AI depends on.
Annex A.4
Annex A.5 — Assessing impacts of AI systems
Controls for actually running AI system impact assessments.
Annex A.5
Annex A.6 — AI system life cycle
Controls spanning design through decommissioning of an AI system.
Annex A.6
Annex A.7 — Data for AI systems
Controls for the quality, provenance, and prep of data feeding AI systems.
Annex A.7
Annex A.8 — Information for interested parties
Controls for what's documented and disclosed about an AI system.
Annex A.8
Annex A.9 — Use of AI systems
Controls for intended use, objectives, and monitoring once deployed.
Annex A.9
Annex B — Implementation guidance
Informative guidance for actually implementing Annex A's controls.
42001 · Annex B
Annex C — AI-related objectives and risk sources
A catalogue of typical AI risk sources and related objectives.
42001 · Annex C
Annex D — Use across domains and sectors
Guidance on applying 42001 across sectors and alongside other standards.
42001 · Annex D
Assess
Step 5 of the RMF — an independent check on whether controls actually work.
NIST RMF · Step 5 of 7
Asset
Anything worth protecting — data, a system, a device, or a reputation.
Attack surface
Every point an attacker could try to get in through.
Authorize
Step 6 of the RMF — a senior official formally approves the system to run.
NIST RMF · Step 6 of 7
Awareness
Making sure staff understand the AI policy and their part in it.
42001 · Clause 7
B
C
Categorize
Step 2 of the RMF — classify the system by how much a loss would hurt.
NIST RMF · Step 2 of 7
Certification audit
The independent audit confirming an AIMS actually meets ISO/IEC 42001.
Certification body
The accredited organization authorized to audit and certify an AIMS.
42001 · certification
CIA triad (CIA)
The three goals of security: keep data private, unaltered, and available when needed.
Cloud IAM roles
Predefined permission sets assigned to a user or service in the cloud.
Cloud security posture management (CSPM)
Tools that continuously scan cloud environments for misconfigurations.
Communication
Defining what AIMS information gets shared, with whom, and how.
42001 · Clause 7
Competence
Making sure people doing AIMS work actually have the skills to do it.
42001 · Clause 7
Conditional access
Access rules that adapt to context — location, device health, risk.
Context of the organization
Identifying the issues and interested parties relevant to the AIMS.
42001 · Clause 4
Continual improvement
Keeping the AIMS getting better over time instead of standing still.
42001 · Clause 10
Control (preventive, detective, corrective)
A safeguard that reduces risk — preventive, detective, or corrective.
Control objective
The specific goal a given Annex A control exists to achieve.
42001 · Annex A
Corrective action
Fixing the root cause of a nonconformity, not just the symptom.
42001 · Clause 10
Credential stuffing
Trying leaked username/password pairs against other sites, betting on reuse.
Cross-site scripting (XSS)
Injecting malicious script into a site so it runs in another visitor's browser.
Cyber insurance
Insurance covering breach response, legal fees, and lost income from an incident.
D
Data classification
Labeling data by sensitivity so the right controls apply automatically.
Data loss prevention (DLP)
Tools that detect and block sensitive data from leaving improperly.
Data minimization
Collecting and keeping only the data actually needed for the task.
Data poisoning
Deliberately corrupting training data so a model learns the wrong behavior.
Data provenance
The documented origin and history of a dataset.
Data quality
How accurate, complete, and representative the data feeding AI actually is.
Data residency
Where data is physically stored, which can determine which laws apply.
Data retention
How long an organization keeps data before deleting it.
Deepfake fraud
Using AI-generated audio or video to convincingly impersonate someone.
Defense in depth
Layer multiple controls so one failure doesn't leave you fully exposed.
Demilitarized zone (DMZ)
A network zone between the public internet and the internal network.
Detect
The CSF function for spotting attacks and compromises as they happen.
NIST CSF 2.0 · Detect
Digital certificate
An electronic credential proving a website or signer is who they claim.
Digital forensics
A structured investigation after an incident to determine what happened.
Disaster recovery plan (DRP)
The technical plan for restoring IT systems after a major disruption.
Distributed denial-of-service (DDoS)
Flooding a system with traffic until it can't serve real users.
DNS filtering
Blocking lookups for known-malicious domains before a device can connect.
Documented information
The records an AIMS has to keep as evidence it's actually operating.
42001 · Clause 7
Due care vs. due diligence
Research before acting, versus ongoing effort to maintain protection after.
E
Encryption at rest and in transit
Encrypting data both while stored and while moving across a network.
End-to-end encryption (E2EE)
Only the sender and recipient can read it, not the service in between.
Endpoint
Any device connecting to the network — laptop, phone, server, printer.
Endpoint & extended detection and response (EDR/XDR)
Watches devices for malicious behavior; XDR extends that across more sources.
EU AI Act
The EU's risk-tiered AI law, phasing in obligations through 2027–2028.
EU AI Act
Explainability
Describing, in human terms, the factors behind a specific AI decision.
Exploit
The specific technique used to take advantage of a vulnerability.
F
G
General Data Protection Regulation (GDPR)
The EU's data protection law, giving individuals rights over their personal data.
Govern
The CSF 2.0 function for setting strategy, roles, and executive oversight.
NIST CSF 2.0 · Govern
Govern
The AI RMF function for setting accountability and policy for AI risk.
NIST AI RMF · Govern
Governance, risk & compliance (GRC)
Setting direction, managing uncertainty, and meeting obligations, together.
Guardrails
Technical controls that keep an AI system's inputs and outputs within bounds.
H
Hallucination
An AI confidently producing false or fabricated output.
Harmonized Structure
The common Clause 4–10 skeleton shared by all modern ISO management standards.
Hashing
A one-way fingerprint of data, used to verify integrity or store passwords.
HIPAA Security Rule
Sets specific safeguard requirements for protecting electronic health data.
Human oversight
Keeping a person meaningfully able to monitor or override an AI system.
I
IaaS, PaaS & SaaS
Three layers of cloud service: raw infrastructure, a platform, or a finished app.
Identify
The CSF function for cataloguing assets, data, and risk before protecting them.
NIST CSF 2.0 · Identify
Identity and access management (IAM)
The systems that create accounts, verify identity, and control access.
Identity provider (IdP)
The central service that verifies identity and issues trusted proof of it.
Immutable backup
A backup that can't be altered or deleted, even by an administrator.
Implement
Step 4 of the RMF — actually put the chosen controls in place.
NIST RMF · Step 4 of 7
Incident response plan (IRP)
A written, rehearsed plan for the first hours and days of an incident.
Indicator of compromise (IOC)
Evidence a system has already been breached.
Information security management system (ISMS)
An ongoing program for managing information security, built on ISO/IEC 27001.
Insider threat
Harm caused by someone with legitimate access, malicious or careless.
Interested parties
Everyone with a stake in how an organization manages its AI.
42001 · Clause 4
Internal audit
A self-check confirming the AIMS meets the standard and its own requirements.
42001 · Clause 9
Intrusion detection & prevention systems (IDS/IPS)
Watches traffic for attack patterns — one alerts, the other can block automatically.
ISO/IEC 22989
Defines the shared AI vocabulary the rest of the AI standards family builds on.
ISO/IEC 22989:2022
ISO/IEC 23053
A framework describing the building blocks of machine-learning-based AI systems.
ISO/IEC 23053
ISO/IEC 23894
Adapts general risk management principles specifically to AI.
ISO/IEC 23894:2023
ISO/IEC 27001
The international standard for building and certifying an ISMS.
ISO/IEC 38507
Gives governing bodies guidance on overseeing an organization's use of AI.
ISO/IEC 38507:2022
ISO/IEC 42001
The international standard for building and certifying an AI management system.
ISO/IEC 42001:2023
ISO/IEC 42005
Detailed guidance for conducting an AI system impact assessment.
ISO/IEC 42005:2025
ISO/IEC 42006
Sets the requirements certification bodies must meet to audit against 42001.
ISO/IEC 42006:2025
ISO/IEC 5338
Defines the processes that make up an AI system's life cycle.
ISO/IEC 5338:2023
ISO/IEC TR 24027
A technical report on measuring bias in AI systems and AI-aided decisions.
ISO/IEC TR 24027:2021
M
Machine learning (ML)
Building AI systems that learn patterns from data instead of fixed rules.
Malware
Software built to damage, disrupt, or gain unauthorized access to a system.
Man-in-the-middle attack (MITM)
An attacker secretly intercepts communication between two parties.
Manage
The AI RMF function for treating AI risk and responding when something goes wrong.
NIST AI RMF · Manage
Managed detection and response (MDR)
An outsourced service that actively monitors and responds to threats for you.
Management review
Leadership's periodic review of how the AIMS is performing.
42001 · Clause 9
Map
The AI RMF function for understanding a specific AI system's context and risks.
NIST AI RMF · Map
Measure
The AI RMF function for actually measuring and tracking identified AI risk.
NIST AI RMF · Measure
Membership inference
Determining whether someone's data was used to train a model.
Misconfiguration
A security setting left insecure — a common cause of cloud data exposure.
MITRE ATLAS
A knowledge base of real-world attacker tactics specifically against AI systems.
Model extraction
Querying a model repeatedly to steal a close copy of it.
Model inversion
Reconstructing sensitive training data by studying a model's outputs.
Monitor
Step 7 of the RMF — ongoing tracking of security after the system is live.
NIST RMF · Step 7 of 7
Monitoring and measurement
Tracking whether the AIMS and its controls are actually working.
42001 · Clause 9
Multi-factor authentication (MFA)
Requiring two or more proofs of identity to log in, not just a password.
N
Network segmentation
Dividing a network into zones so a breach can't spread everywhere.
Next-generation firewall (NGFW)
A firewall that also inspects the actual application content passing through.
NIST AI 600-1 (Generative AI Profile)
NIST's guidance on risks specific to generative AI, like confabulation.
NIST AI 600-1
NIST AI Risk Management Framework (NIST AI RMF)
A voluntary US framework built around four functions for managing AI risk.
NIST AI RMF 1.0
NIST Cybersecurity Framework 2.0 (NIST CSF 2.0)
A framework built around six functions for structuring a cybersecurity program.
NIST Risk Management Framework (RMF)
A seven-step US federal process for authorizing and monitoring a system's security.
NIST SP 800-37
NJ data breach notification
New Jersey's rule requiring state police notice before customer notice.
Non-repudiation
Proof strong enough that someone can't credibly deny an action.
Nonconformity
A point where the AIMS fails to meet a requirement.
42001 · Clause 10
O
OAuth 2.0
Lets one app access another on your behalf without ever seeing your password.
OpenID Connect (OIDC)
An identity layer on top of OAuth 2.0 that confirms who a user actually is.
Operational planning and control
Carrying out AI risk treatment and impact assessment day to day.
42001 · Clause 8
OWASP Top 10 for LLM Applications
A maintained list of the most significant security risks in LLM applications.
P
Passkeys
A passwordless sign-in method tied to a device that resists phishing.
Password manager
Generates and stores a unique, strong password for every account.
Patch management
Finding, testing, and installing updates that fix known vulnerabilities.
Payment Card Industry Data Security Standard (PCI DSS)
Security requirements for any organization handling payment card data.
Penetration testing
An authorized simulated attack to find exploitable weaknesses.
Personally identifiable information (PII)
Data that can identify a specific individual on its own or combined.
Phishing
A fake message designed to trick someone into handing over credentials or money.
Plan-Do-Check-Act (PDCA)
The Plan-Do-Check-Act cycle that Clauses 4–10 of every ISO management standard follow.
ISO Harmonized Structure
Planning of changes
Planning changes to the AIMS in a controlled way as AI use evolves.
42001 · Clause 6
Policy, standard & procedure
A policy sets the rule, a standard sets the requirement, a procedure the steps.
Prepare
Step 1 of the RMF — set priorities and groundwork before anything else.
NIST RMF · Step 1 of 7
Private / self-hosted AI
Running an AI model on infrastructure you control, so data never leaves.
Private / sovereign cloud
Infrastructure built to keep data under an organization's or country's control.
Privileged access management (PAM)
Extra controls around the small number of highly powerful admin accounts.
Prompt injection
Hidden or direct instructions that trick an AI into doing something unintended.
Protect
The CSF function for putting safeguards in place to manage known risk.
NIST CSF 2.0 · Protect
Protected health information (PHI)
Individually identifiable health information covered under HIPAA.
Public key infrastructure (PKI)
The system of certificates and keys that proves identity without a shared secret.
R
Ransomware
Malware that encrypts your files and demands payment to unlock them.
Recertification
The renewed audit, typically every three years, that keeps certification valid.
Recover
The CSF function for restoring normal operations after an incident.
NIST CSF 2.0 · Recover
Recovery point objective (RPO)
The maximum acceptable data loss, measured in time.
Recovery time objective (RTO)
The maximum acceptable time to get a system back up after a disruption.
Residual risk
The risk still left over after controls have been applied.
Resources
Providing what the AIMS actually needs to function — people, time, budget.
42001 · Clause 7
Respond
The CSF function for acting on an incident while it's actively happening.
NIST CSF 2.0 · Respond
Retrieval-augmented generation (RAG)
Having an AI pull from trusted documents before answering, to reduce hallucination.
Risk
The chance a threat exploits a weakness and causes harm.
Risk criteria
The organization's own yardsticks for likelihood, impact, and acceptable risk.
42001 · Clause 6
Risk register
A living list of identified risks, their impact, and who owns each one.
Role-based access control (RBAC)
Granting access based on a person's role, not configuring each account by hand.
Roles and responsibilities (42001)
Clearly assigning who owns which part of the AIMS.
42001 · Clause 5
S
Salting
Adding random data before hashing so identical passwords don't match.
Security Assertion Markup Language (SAML)
An older standard for passing proof of login between systems for SSO.
Security awareness training
Ongoing education that teaches staff to recognize phishing and handle data.
Security information and event management (SIEM)
Collects logs across systems and correlates them to surface suspicious activity.
Security operations center (SOC)
The team that watches security alerts and responds around the clock.
Security posture
An organization's overall readiness against cyber risk right now.
Select
Step 3 of the RMF — choose the controls that fit the system's risk level.
NIST RMF · Step 3 of 7
Separation of duties
Splitting a sensitive task across more than one person to prevent abuse.
Session hijacking
Stealing a valid login session to act as an already-authenticated user.
Shadow AI
AI tools employees use on their own, without IT's knowledge or approval.
Shared responsibility model
The split between what the cloud provider secures and what you secure.
Single sign-on (SSO)
Logging in once to access many connected applications.
Smishing & vishing
Phishing delivered by text message or phone call instead of email.
SOC 2
An auditor's report on how well a service provider's security controls hold up.
Social engineering
Manipulating a person, not a system, into breaking security procedure.
Spear phishing
Phishing aimed at one specific person using details that make it believable.
SQL injection (SQLi)
Sneaking database commands into a web form to run them against the database.
Statement of Applicability (SoA)
The document listing which Annex A controls apply, and why.
42001 · 6.1.3 / Annex A
Supply chain attack
Compromising a trusted vendor to reach their downstream customers.
T
Tabletop exercise
A practice run of an incident response plan, without touching live systems.
Third-party risk management (TPRM)
Assessing the security risk vendors and contractors introduce to you.
Threat
Anything that could cause harm by exploiting a weakness.
Threat intelligence
Information about active attackers used to anticipate and recognize them.
Tokenization
Replacing a sensitive value with a placeholder that's useless if stolen.
Top management commitment
Leadership actively owning the AI policy, not delegating it entirely.
42001 · Clause 5
Transparency
Making appropriate information about an AI system available to who needs it.
Transport Layer Security (TLS)
The encryption protocol behind the padlock icon in your browser.
Trustworthiness
An AI system's demonstrated reliability across accuracy, safety, and fairness.
V
Vendor security questionnaire
Standard questions used to assess a vendor's security before signing.
Virtual private network (VPN)
An encrypted tunnel connecting a remote device to a private network.
Vulnerability
A weakness a threat could take advantage of.
Vulnerability scanning
Automated, regular scanning to find known weaknesses before attackers do.
Sources & disclaimer
- Definitions on this page are original, plain-language explanations.
- The ISO standards themselves are available for purchase from iso.org.
- This page is general information, not legal or certification advice.