Glossary
Definitions for the acronyms and terms used throughout this documentation. Platform-specific terms describe how GRC-ITSM uses them, which is sometimes narrower than general industry usage.
Compliance terms
| Term |
Definition |
| AAR |
After Action Report. Root cause, lessons learned, and corrective actions authored on an incident record and approved by the After Action Report Approvers CAB before the incident resolves. |
| BOD |
Binding Operational Directive. A compulsory direction from CISA to federal agencies; BOD 26-04 governs risk-based vulnerability remediation and KEV due dates. |
| CUI |
Controlled Unclassified Information. Federal information requiring safeguarding under CMMC and DFARS. |
| IIW |
Integrated Inventory Workbook. The FedRAMP field set for system inventory reporting; GRC-ITSM renders it live from the asset register. |
| KEV |
Known Exploited Vulnerability. A CVE in CISA's KEV catalog; KEV findings carry catalog due dates that survive full mitigation. |
| KSI |
Key Security Indicator. The FedRAMP 20x unit of security capability; validated machine-based or manually, with failures tracked as vulnerabilities. |
| OCR |
Ongoing Certification Report. The FedRAMP 20x recurring report on continuous-monitoring posture. |
| ODV |
Organization-Defined Value. A parameter a framework leaves to the organization to set; each policy document carries an ODV table with its chosen values and framework defaults. |
| PAIN |
Potential Agency Impact N-rating. The FedRAMP 20x impact scale (PAIN 1-5) assigned to incidents and vulnerabilities; sets reporting clocks and remediation priority. PAIN 5 is the default when a rating is not promptly estimated. |
| POA&M |
Plan of Action and Milestones. The tracked remediation plan for findings that cannot be immediately resolved. |
| SCN |
Significant Change Notification. The FedRAMP notification obligation for adaptive and transformative changes, on fixed business-day clocks. |
| SDR |
Security Decision Record. The machine-readable record of security decisions maintained in the FedRAMP Certification Package. |
| SSP |
System Security Plan. The authorization document describing how a system implements its controls. |
| Term |
Definition |
| Alert |
A notification and triage ticket from integrated tools and automated processes. Alerts are the entry point; genuine events escalate in place to an Incident. |
| CAB |
The platform's approval board construct (labeled "Change Advise Board" in configuration, equivalent to the ITIL Change Advisory Board). Each request type has a named CAB with role-based membership: the User Access Request Approvers CAB, Change Request Approvers CAB, Deviation Approvers CAB, and After Action Report Approvers CAB. |
| DR |
Deviation Request. See Vulnerability Deviation. |
| Issue |
The per-asset ticket for a tracked vulnerability or configuration finding, carrying its Remediation SLA. |
| OLA |
Operational-Level Agreement. An internal clock tracked on a ticket; incident reporting timeframes (Initial/Ongoing/Final reports) are tracked as OLAs. |
| Remediation SLA |
The SLA policy enforcing remediation timeframes on Issues -- severity-based (30/90/180 days) on FedRAMP Rev5, PAIN-ladder-based on FedRAMP 20x. |
| Trust Center |
The self-service portal surface set through which certification data is shared: Request Services, My Requests & Tickets, Policies & Procedures, ConMon Reports, and Certification Documents. |
| UAR |
User Access Request. The ticket type governing every account action -- creation, modification, disablement, termination, MFA, privileged account management, and recertification -- with CAB approval and machine validation evidence. |
| Vulnerability Deviation |
The ticket type for formal deviation from standard remediation: False Positive (FP), Operational Requirement (OR), Risk Adjustment (RA), or OR RA. Approved by the Deviation Approvers CAB. |