Dictionary · TSP Section 100
2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (with Revised Points of Focus - 2022)
Nouns
75 senses- access to personal information
- glossary
The ability to view personal information held by an organization. This ability may be complemented by an ability to update or correct the information. Access defines the intersection of identity and data, that is, who can do what to which data. Access is one of the fair information practice principles. Individuals need to be able to find out what personal information an entity has on file about them and how the information is being used. Individuals need to be able to correct erroneous information in such records.
- Architecture
- glossary
The design of the structure of a system, including logical components, and the logical interrelationships of computers, operating systems, networks, or other elements, whether internally or externally hosted.
- Authentication
- glossary
The process of verifying the identity or other attributes claimed by or assumed of an entity (user, process, or device) or to verify the source and integrity of data.
- authorization
- glossary
The process of granting access privileges to a user, program, or process by a person that has the authority to grant such access.
- board or board of directors
- glossary
Individuals with responsibility for overseeing the strategic direction of the entity and the obligations related to the accountability of the entity. Depending on the nature of the entity, such responsibilities may be held by a board of directors or supervisory board for a corporation, a board of trustees for a not-for-profit entity, a board of governors or commissioners for a government entity, general partners for a partnership, or an owner for a small business.
- business partner
- glossary
An individual or business (and its employees), other than a vendor, that has some degree of involvement with the entity's business dealings or agrees to cooperate, to any degree, with the entity (for example, a computer manufacturer who works with another company that supplies it with parts).
- collection
- glossary
The process of obtaining personal information from the individual directly (for example, through the individual's submission of an internet form or a registration form) or from another party, such as a business partner.
- Commitment
- glossary
Declarations made by management to customers regarding the performance of one or more systems that provide services or products. Commitments can be communicated in written individualized agreements, standardized contracts, service-level agreements, or published statements (for example, a security practices statement). A commitment may relate to one or more trust services categories. Commitments may be made on many different aspects of the service being provided or the product, production, manufacturing, or distribution specifications.
- Component
- glossary
One of five elements of internal control, including the control environment, risk assessment, control activities, information and communication, and monitoring activities.
- Compromise
- glossary
Refers to a loss of confidentiality, integrity, or availability of information, including any resultant impairment of (1) processing integrity or availability of systems or (2) the integrity or availability of system inputs or outputs.
- Controls
- glossary
Policies and procedures that are part of the entity's system of internal control. The objective of an entity's system of internal control is to provide reasonable assurance that principal system objectives are achieved.
- control activity
- glossary
An action established through policies and procedures that help ensure that management's directives to mitigate risks to the achievement of objectives are carried out.
- Consent
- glossary
This privacy requirement is one of the fair information practice objectives. Individuals must be able to prevent the collection of their personal data, unless legally required. If an individual has a choice about the use or disclosure of his or her information, consent is the individual's way of giving permission for the use or disclosure. Consent may be affirmative (for example, opting in) or implied (for example, not opting out). There are two types of consent:
- explicit consent
- glossary
A requirement that an individual "signifies" agreement with a data controller by some active communication between the parties.
- implied consent
- glossary
When consent may reasonably be inferred from the action or inaction of the individual.
- COSO
- glossary
The Committee of Sponsoring Organizations of the Treadway Commission. COSO is a joint initiative of five private-sector organizations and is dedicated to providing thought leadership through the development of frameworks and guidance on enterprise risk management, internal control, and fraud deterrence. (See www.coso.org.)
- cybersecurity objectives
- glossary
Objectives that address the cybersecurity risks that could affect the achievement of the entity's overall business objectives (including compliance, reporting, and operational objectives).
- data controller
- glossary
An organization that (alone or jointly with others) determines the purposes for and the means by which personal data is processed.
- Data Processor
- glossary
An organization that processes personal data at the direction of a data controller. In many cases, a service organization may process personal data for its business-to-business (B2B) customers (user entities), which in turn may function as data controllers. In other cases, a service organization may function as a data controller, depending on the facts and circumstances.
- data subject
- glossary
The individual about whom personal information is collected.
- Noun #42540
- glossary
As used in the COSO definition of internal control, the internal control system design is intended to provide reasonable assurance of the achievement of an entity's objectives.
- Disclosure
- glossary
The provision of access to or the release, transfer, or divulging in any other manner of information outside the entity holding the information. Disclosure is often used interchangeably with the terms sharing and onward transfer .
- disposal
- glossary
A phase of the data life cycle that pertains to how an entity removes or destroys data or information.
- effectiveness (of controls)
- glossary
Encompasses both the suitability of the design of controls and the operating effectiveness of controls to provide reasonable assurance that the entity's principal system objectives are achieved.
- endpoint devices
- glossary
Connected hardware or virtual devices that communicate across a network, such as mobile devices, laptops, desktops, and sensors.
- Entity
- glossary
A legal entity or management operating model of any size established for a particular purpose. A legal entity may, for example, be a business enterprise, a not-for-profit organization, a government body, or an academic institution. The management operating model may follow product or service lines, divisions, or operating units, with geographic markets providing for further subdivisions or aggregations of performance.
- entity-wide
- glossary
Activities that apply across the entity - most commonly in relation to entity-wide controls.
- environmental
- glossary
Of or having to do with the matters that can damage the physical elements of information systems (for example, fire, flood, wind, earthquake, power surges, or power outages). An entity implements controls and other activities to detect, prevent, and manage the risk of casualty damage to the physical elements of the information system from environmental elements.
- external user
- glossary
Users, other than entity personnel, who are authorized by entity management, customers, or other authorized persons to interact with the entity's information system.
- Functional requirements
- glossary
Requirements that must be met for the system to correctly fulfill its designed purpose.
- information and systems
- glossary
Refers to information in electronic form (electronic information) during its use, processing, transmission, and storage and systems that use, process, transmit or transfer, and store information or that produce, manufacture, or distribute products.
- information asset
- glossary
Data and the associated software and infrastructure used to process, transmit, and store information or to produce, manufacture, or distribute products.
- Infrastructure
- glossary
The collection of physical or virtual resources that supports an overall IT environment, including the server, storage, network elements, and endpoint devices.
- internal control
- glossary
A process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
- nonfunctional requirements
- glossary
System attributes such as security, reliability, performance, maintainability, scalability, and usability that define how well a system will operate.
- outsourced service providers
- glossary
A service provider that performs business processes, operations, or controls on behalf of the entity when such business processes, operations, or controls are necessary to achieve the entity's objectives.
- personal information
- glossary
Information that is about, or can be related to, an identifiable individual.
- Practitioner
- glossary
As used in this document, a CPA who performs an examination of controls within an entity's system relevant to security, availability, processing integrity, confidentiality, or privacy.
- principal system objectives
- glossary
System objectives that relate to the trust services category or categories addressed by the examination and that could reasonably be expected to influence the relevant decisions of intended users. (See system objectives .)
- privacy commitments
- glossary
Declarations made by management regarding the performance of a system processing personal information. Such commitments can be communicated in written agreements, standardized contracts, service-level agreements, or published statements (for example, a privacy practices statement). In addition, privacy commitments may be made on many different aspects of the service being provided.
- privacy notice
- glossary
A written communication by entities that collect personal information, to the individuals about whom personal information is collected, about the entity's ( a ) policies regarding the nature of the information that they will collect and how that information will be used, retained, disclosed, and disposed of or anonymized and ( b ) commitment to adhere to those policies. A privacy notice also includes information about such matters as the purpose of collecting the information, the choices that individuals have related to their personal information, the security of such information, and how individuals can contact the entity with inquiries, complaints, and disputes related to their personal information. When a user entity collects personal information from individuals, it typically provides a privacy notice to those individuals.
- process or control framework
- glossary
A framework that contains a set of processes or controls, established by another party, that organizations are expected to implement in support of establishing an effective system of internal control. These frameworks are usually developed by an industry group, regulator, governmental entity, standard-setting body, or other organization (collectively referred to as sponsoring organizations ) to obtain information from organizations with which they do business about their processes and controls. The most common types of process or control frameworks relate to security and privacy.
- product
- glossary
Tangible or intangible goods manufactured or produced by an entity. Throughout this document, the term is used interchangeably with goods.
- report users
- glossary
Intended users of the practitioner's report in accordance with AT-C section 205, Assertion-Based Examination Engagements . fn 1 There may be a broad range of report users for a general-purpose report but only a limited number of specified parties for a report that is restricted in accordance with paragraph .64 of AT-C section 205.
- Residual risk
- glossary
The risk to the achievement of objectives that remains after management's response has been designed and implemented.
- Retention
- glossary
A phase of the data life cycle that pertains to how long an entity stores information for future use or reference.
- risk
- glossary
The possibility that an event will occur and adversely affect the achievement of objectives.
- risk response
- glossary
The decision to accept, avoid, reduce, or share a risk.
- security event
- glossary
An occurrence, arising from actual or attempted unauthorized access or use by internal or external parties, that impairs or could impair the availability, integrity, or confidentiality of information or systems: result in unauthorized disclosure or theft of information or other assets; or cause damage to systems.
- security incident
- glossary
A security event that requires action on the part of an entity to protect information assets and resources.
- senior management
- glossary
The CEO or equivalent organizational leader and senior management team.
- service provider
- glossary
A supplier (such as a service organization) engaged to provide services to the entity. Service providers include outsourced service providers as well as suppliers that provide services not associated with business functions, such as janitorial, legal, and audit services.
- SOC 2 examination
- glossary
An examination engagement to report on whether ( a ) the description of the service organization's system is in accordance with the description criteria, ( b ) the controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria, and ( c ) in a type 2 report, the controls operated effectively to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria. The SOC 2 examination is performed in accordance with the attestation standards and AICPA Guide SOC 2 ® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy .
- SOC 3 ® engagement
- glossary
An examination engagement to report on the suitability of design and the operating effectiveness of an entity's controls over a system relevant to one or more of the trust services categories.
- SOC for Cybersecurity examination
- glossary
An examination engagement to report on whether ( a ) management's description of the entity's cybersecurity risk management program is presented in accordance with the description criteria and ( b ) the controls within that program were effective to achieve the entity's cybersecurity objectives based on the control criteria. A SOC for Cybersecurity examination is performed in accordance with the attestation standards and AICPA Guide Reporting on an Entity's Cybersecurity Risk Management Program and Controls .
- SOC for Supply Chain examination
- glossary
An examination engagement to report on whether ( a ) the description of the entity's system is presented in accordance with the description criteria and ( b ) the controls stated in the description, which are necessary to provide reasonable assurance that the entity achieved its principal system objectives, were effective based on the applicable trust services criteria. Such an examination is based on guidance contained in AICPA Guide Reporting on an Examination of Controls Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy in a Production, Manufacturing, or Distribution System (SOC for Supply Chain guide).
- software
- glossary
A collection of instructions that tell a computer how to operate. Software may be both internally developed and purchased from vendors and can include both application software (for example, user applications and database management systems) and system software (for example, operating systems, drivers, utilities, programming software, and interfaces).
- stakeholder
- glossary
Parties that are affected by the entity, such as shareholders, the communities in which an entity operates, employees, customers, and suppliers.
- subsequent events
- glossary
Events or transactions that occur after the specified period addressed by the description but prior to the date of the practitioner's report. Such events or transactions could have a significant effect on the evaluation of whether the description is presented in accordance with the description criteria or whether controls were effective to provide reasonable assurance that the entity's principal system objectives were achieved based on the applicable trust services criteria.
- supplier
- glossary
See vendor .
- system
- glossary
Refers to the infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve one or more of the entity's specific business objectives (for example, delivery of services or production of goods) in accordance with management-specified requirements.
- system boundaries
- glossary
The specific aspects of an entity's infrastructure, software, people, procedures, and data necessary to perform a function (such as producing, manufacturing, or distributing a product) or provide a service. When systems for multiple functions or services share aspects, infrastructure, software, people, procedures, and data, the systems will overlap, but the boundaries of each system will differ.
- system component
- glossary
Refers to the individual elements of a system, which may be classified into the following five categories: infrastructure, software, people, processes, and data.
- system event
- glossary
An occurrence that could lead to the loss of, or disruption to, operations, services, or functions and could result in an entity's failure to achieve its system objectives. Such an occurrence may arise from actual or attempted unauthorized access or use by internal or external parties and ( a ) impair (or potentially impair) the availability, integrity, or confidentiality of information or systems; ( b ) result in unauthorized disclosure or theft of information or other assets or the destruction or corruption of data; or ( c ) cause damage to systems. Such occurrences also may arise from the failure of the system to process data as designed or from the loss, corruption, or destruction of data used by the system.
- system incident
- glossary
A system event that requires action on the part of entity management to prevent or reduce the impact of the event on the entity's achievement of its system objectives.
- system objectives
- glossary
The entity's objectives, established by entity management, that are embodied in the product commitments it makes to customers, including producing or manufacturing a product that meets product performance specifications and other production, manufacturing, or distribution specifications. The system objectives also include the requirements established for the functioning of the system to meet production, manufacturing, or distribution commitments.
- system requirements
- glossary
Specifications regarding how the system should function to ( a ) meet the entity's commitments to customers and others (such as customers' customers); ( b ) meet the entity's commitments to suppliers and business partners; ( c ) comply with relevant laws and regulations and guidelines of industry groups, such as business or trade associations; and ( d ) achieve other entity objectives that are relevant to the trust services category or categories addressed by the description. Requirements are often specified in the entity's system policies and procedures, system design documentation, contracts with customers, and government regulations. System requirements may result from the entity's commitments relating to security, availability, processing integrity, confidentiality, or privacy. For example, a commitment to programmatically enforce segregation of duties between data entry and data approval creates system requirements regarding user access administration.
- third party
- glossary
An individual or organization other than the entity and its employees. Third parties may be customers, suppliers, business partners, or others.
- threat
- glossary
Any circumstance or event, arising from human actions or natural events, that could potentially impair ( a ) the achievement of an entity's objectives, its assets, or activities of its personnel, or ( b ) other entities through unauthorized access, destruction, disclosure, modification of data, or denial of service.
- trust services
- glossary
A set of professional attestation and advisory services based on a core set of criteria related to security, availability, processing integrity, confidentiality, or privacy.
- unauthorized access
- glossary
Access to information or system components that ( a ) has not been approved by a person designated to do so by management and ( b ) compromises segregation of duties, confidentiality commitments, or otherwise increases risks to the information or system components beyond the levels approved by management (that is, access is inappropriate).
- vendor (or supplier)
- glossary
An individual or business (and its employees) that is engaged to provide goods or services to the entity. Depending on the services provided (for example, if the vendor operates certain controls on behalf of the entity that are necessary to achieve the entity's objectives), it also might be a service provider.
- vulnerability
- glossary
Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.
- policy
- glossary
Management or board member statements of what should be done to effect control. Such statements may be documented, explicitly stated in communications, or implied through actions and decisions. Policies serve as the basis for procedures.
- criterion
- glossary
The benchmarks used to measure or evaluate the subject matter.