Skip to content

Glossary

Definitions for the acronyms and terms used throughout this documentation. Platform-specific terms describe how GRC-ITSM uses them, which is sometimes narrower than general industry usage.


Compliance terms

Term Definition
AAR After Action Report. Root cause, lessons learned, and corrective actions authored on an incident record and approved by the After Action Report Approvers CAB before the incident resolves.
BOD Binding Operational Directive. A compulsory direction from CISA to federal agencies; BOD 26-04 governs risk-based vulnerability remediation and KEV due dates.
CUI Controlled Unclassified Information. Federal information requiring safeguarding under CMMC and DFARS.
IIW Integrated Inventory Workbook. The FedRAMP field set for system inventory reporting; GRC-ITSM renders it live from the asset register.
KEV Known Exploited Vulnerability. A CVE in CISA's KEV catalog; KEV findings carry catalog due dates that survive full mitigation.
KSI Key Security Indicator. The FedRAMP 20x unit of security capability; validated machine-based or manually, with failures tracked as vulnerabilities.
OCR Ongoing Certification Report. The FedRAMP 20x recurring report on continuous-monitoring posture.
ODV Organization-Defined Value. A parameter a framework leaves to the organization to set; each policy document carries an ODV table with its chosen values and framework defaults.
PAIN Potential Agency Impact N-rating. The FedRAMP 20x impact scale (PAIN 1-5) assigned to incidents and vulnerabilities; sets reporting clocks and remediation priority. PAIN 5 is the default when a rating is not promptly estimated.
POA&M Plan of Action and Milestones. The tracked remediation plan for findings that cannot be immediately resolved.
SCN Significant Change Notification. The FedRAMP notification obligation for adaptive and transformative changes, on fixed business-day clocks.
SDR Security Decision Record. The machine-readable record of security decisions maintained in the FedRAMP Certification Package.
SSP System Security Plan. The authorization document describing how a system implements its controls.

Platform terms

Term Definition
Alert A notification and triage ticket from integrated tools and automated processes. Alerts are the entry point; genuine events escalate in place to an Incident.
CAB The platform's approval board construct (labeled "Change Advise Board" in configuration, equivalent to the ITIL Change Advisory Board). Each request type has a named CAB with role-based membership: the User Access Request Approvers CAB, Change Request Approvers CAB, Deviation Approvers CAB, and After Action Report Approvers CAB.
DR Deviation Request. See Vulnerability Deviation.
Issue The per-asset ticket for a tracked vulnerability or configuration finding, carrying its Remediation SLA.
OLA Operational-Level Agreement. An internal clock tracked on a ticket; incident reporting timeframes (Initial/Ongoing/Final reports) are tracked as OLAs.
Remediation SLA The SLA policy enforcing remediation timeframes on Issues -- severity-based (30/90/180 days) on FedRAMP Rev5, PAIN-ladder-based on FedRAMP 20x.
Trust Center The self-service portal surface set through which certification data is shared: Request Services, My Requests & Tickets, Policies & Procedures, ConMon Reports, and Certification Documents.
UAR User Access Request. The ticket type governing every account action -- creation, modification, disablement, termination, MFA, privileged account management, and recertification -- with CAB approval and machine validation evidence.
Vulnerability Deviation The ticket type for formal deviation from standard remediation: False Positive (FP), Operational Requirement (OR), Risk Adjustment (RA), or OR RA. Approved by the Deviation Approvers CAB.