Digital Governance Glossary
The Digital Governance Glossary serves as a lexicon of the most used terms and definitions present in the DGSI standards.
This glossary is under continuous maintenance, if you would like a term to be added or revised, you can request it here.
Use the search function to find a term.
Term Definition Source
Access Control A set of policies, procedures, and technologies used to regulate access to data, systems, and other resources within an organization. Access control typically involves identifying authorized users, verifying their identities, and granting appropriate permissions based on their roles and responsibilities.
Access Control Policy A record of the conditions under which an access request is to be permitted or denied.
Access Request An automatic or manual request for access to one or more data resources.
Accessible (Data or resources) readily available for use or viewing by authorized individuals or systems, often requiring the provision of credentials (such as usernames and passwords) and verification of access rights.
Accessible (Design) designed to be usable by people of all abilities, ensuring equitable access and participation.
Access-to-information The legal right of individuals to obtain access to information held by public and private organizations, subject to specific exemptions and limitations outlined in applicable laws.
Accountable Answerable for actions, decisions and performance. ISO/IEC 38500:2015
Active Surveillance The observation and/or capturing of an individual’s activities.
Advanced Analytics Practices Advanced analytics are techniques that are able to find insights from large data sets to support predictive analysis. Examples of advanced practices include machine learning and artificial intelligence (AI); incorporates ethical considerations associated with the generated insights.
Affected Persons (Data) A person, entity, family or community affected by manual or automated decisions.
Aggregate Data A collection or combination of data from multiple individuals within a population that is used to make conclusions about the population.
Agile An approach based on iterative development, frequent inspection and adaptation, and incremental deliveries, in which requirements and solutions evolve through collaboration in cross-functional teams and through continuous stakeholder feedback. ISO/IEC/IEEE 26515: 2011 Systems and software engineering: Developing user documentation in an agile environment, modified
Artificial Intelligence (AI) A machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different automated decision systems vary in their levels of autonomy and adaptiveness after deployment.
Artificial Intelligence Principles Functional and performance-based requirements for AI/ML systems including valid, reliable, safe, fair, managing bias, secure, resilient, transparent, accountable, explainable, interpretable, privacy-enhanced as defined by the NIST AI Risk Management Framework Glossary.
Assessor Person who leads and conducts an assessment.
Assigned Identifier A numeric or alphanumeric string that is generated automatically and that uniquely distinguishes between Entities within a population without the use of any other identity attributes.
Assurance Confidence that a statement is true.
Assurance Level A level of confidence that a statement is true that may be relied on by others.
Attribute A property or characteristic of a thing.
Audit Log Chronological record of system activities which is sufficient to enable the reconstruction, review and examination of the sequence of environments and activities surrounding or leading to each event in the path of a transaction from its inception to the output of the final results.
Authentication A security mechanism used to verify the identity of a user or device attempting to access a system or application.
Authenticator Something that a holder controls (something they own, something they know, or something they are such is biometrics) that is used to demonstrate that the holder retains control of a credential.
Authoritative Source A set of records maintained by an authority that meets established criteria.
Authorization Granting of rights, which includes the granting of authorized access based on pre-defined criteria. ISO 7498-2:1989, 3.3.10.
Authorization Server A server that protects, on a resource owner’s behalf, resources hosted at a resource server.
Authorization Server Operator An operator of an authorization server.
Automated Decision System A technology that helps or replaces the judgment of a person using a rules-based system, regression analysis, predictive analytics, machine learning, deep learning, a neural network or other technique. Bill C-27, the Digital Charter Implementation Act
Availability Property of being accessible and usable upon demand by an authorized person or entity. ISO/IEC/IEEE 27000:2018, Information technology — Security techniques — Information security management systems — Overview and vocabulary, modified
Biometric Verification The verification of an individual’s identity using anatomical or physiological characteristics, such as face, fingerprints, retinas, or behavioural characteristics, such as keyboard stroke timing, or walking style.
Blockchain Distributed ledger with confirmed blocks organized in an append-only, sequential chain using cryptographic links. NOTE: Blockchains are designed to be tamper-resistant and to create final, definitive and immutable ledger records.
REFERENCE: ISO 22739:2020 Blockchain and distributed ledger technologies — Vocabulary
Bluetooth A wireless technology standard for exchanging data over short distances and under trademark by the Bluetooth SIG.
Breach of Security Safeguards Any act or omission that compromises either the confidentiality, integrity, or availability of Personal Information or the physical, technical, administrative or organizational safeguards put in place by a Data Controller or Processor that relate to the protection of the confidentiality, integrity or availability of Personal Information; or Receipt of a complaint in relation to the privacy practices of a Data Controller or Processor, or a breach or alleged breach of an agreement relating to such privacy practices.
Business Process Partially ordered set of enterprise activities that can be executed to achieve some desired end-result in pursuit of a given objective of an organization. ISO/IEC/IEEE 24765:2017
Capability Maturity Model A model that contains the essential elements of effective processes for one or more disciplines; describes an improvement path from ad hoc, immature processes to disciplined, mature processes with improved quality and effectiveness and aligned with the objectives of the organization.
Challenge-based Procurement Approaches where procurers outline the challenges and the needs (rather than prescribing a solution) and invite bidders to propose a variety of innovative solutions. NOTE: Also referred to as agile, open.
Client The intended recipient for a service output. External clients are generally Persons (citizens, permanent residents, etc.) and Organizations (public and private sector). Internal clients are generally employees and contractors.
Client Application An application that is capable of making access requests for protected resources with the resource owner’s authorization and on the requesting party’s behalf. REFERENCE: User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorization
Cloud Computing The storage and processing of data held on remotely located servers accessed over the internet.
Commercial-Off-The-Shelf (COTS) Hardware or software components that are widely available for purchase and can be integrated into special-purpose systems. VVSG 2.0.
Competency The combined utilization of personal abilities and attributes, skills and knowledge to effectively perform a job, role, function, task, or duty. Employment and Social Development Canada (2021), Skills and Competencies Taxonomy
Competent Personnel Individuals trained or qualified by knowledge and practical experience to enable the required task or tasks to be carried out properly.
Confidential Data Data exchanged between one or more parties under the intention that it is not to be disclosed.
Confidentiality Property that information is not made available to, disclosed to, or accessed by unauthorized individuals, entities, or processes. ISO/IEC TR 27550:2019
Consent The permission to have, use or share data freely and without coercion. Consent can be either communicated explicitly, on, or implied, through actions, and precedent.
Consent Directive An output of the consent registration process.
Consent Expiration The process of suspending the validity of a “yes” consent decision as a result of exceeding an expiration date and/or time limit.
Consent Registration The process of securely storing the consent notice statement and the person’s related consent decision. In addition, the identity information of the person, the version of the consent notice statement that was presented, the date and time that the consent notice statement was presented, and, if applicable, the expiration date or revocation date for the consent decision may be stored. Once the consent information has been stored, a notification on the consent decision made is issued to the relevant parties to the consent decision.
Consent Renewal The process of extending the validity of a “yes” consent decision by means of increasing an expiration date limit.
Consent Request The process of asking a Person to agree to provide consent (“Yes”) or decline to provide consent (“No”) based on the contents of a presented consent notice statement, resulting in either a “yes” or “no” consent decision.
Consent Review The process of making the details of a stored consent decision visible to the Person who provided the consent.
Consent Revocation The process of suspending the validity of a “yes” consent decision as a result of an explicit withdrawal of consent by the Person (i.e., a “yes” consent decision is converted into a “no” consent decision).
Contextual Identity An Identity that is used for a specific purpose within a specific identity context.
NOTE: Examples include banking, business permits, health services, drivers licensing, or social media. Depending on the identity context, a contextual identity may be tied to a foundational identity (e.g., a driver’s licence) or may not be tied to a foundational identity (e.g., a social media profile). See also “foundational identity”.
Contextual or Functional Identity Evidence of Identity, which establishes the existence or digital representations of entities within a particular context and for a specified purpose after Foundational Evidence of Identity has been proven and accepted.
Contracting Authority Responsible for the solicitation development, management of the contract, and any changes to the contract.
Controller A natural or legal person, public authority, agency or other body which determines the purposes and means of the processing of data.
NOTE: The purposes and means of such processing may be determined by law.
Credential An assertion of identity, qualification, competence, authority, rights, privileges, permissions, status, eligibility, or asset ownership (or a combination of these). A credential contains a set of one or more claims asserted about one or more subjects.
Credential Assurance Confidence that a holder has maintained control over an issued credential and that the issued credential is valid.
Credential Assurance Level The level of confidence that a Holder has maintained control over an issued credential and that the issued credential is valid.
Credential Issuance The process of creating a credential from a set of claims and assigning the credential to a holder.
Credential Maintenance The process of updating the credential attributes (e.g., expiry date, scope of service, permissions) of an issued credential.
Credential Recovery The process of transforming a suspended credential back to a usable state (i.e., an issued credential).
Credential Revocation The process of ensuring that an issued credential is permanently flagged as unusable.
Credential Suspension The process of transforming an issued credential into a suspended credential by flagging the issued credential as temporarily unusable.
Credential Validation The process of verifying that the issued credential is valid (e.g., not tampered with, corrupted, modified, suspended, or revoked). The validity of the issued credential can be used to generate a level of assurance.
Credential Verification The process of verifying that a Holder has control over an issued Credential. Control of an issued Credential is verified by means one or more authenticators. The degree of control over the issued Credential can be used to generate a level of assurance.
Credential-Authenticator Binding The process of associating a credential issued to a holder with one or more authenticators. This process also includes authenticator life-cycle activities such as suspending authenticators (caused by a forgotten password or a lockout due to successive failed authentications, inactivity, or suspicious activity), removing authenticators, binding new authenticators, and updating authenticators (e.g., changing a password, updating security questions and answers, having a new facial photo taken).
Credential-Identity Binding The process of asserting one or more claims about one or more subjects.
Cross-Organizational Domain A domain where multiple organizations have entered into data exchange agreements.
Cryptographic Module The set of hardware, software, and/or firmware that implements cryptographic security functions (including cryptographic algorithms and key generation) and is contained within the cryptographic boundary.
Customer Authorization Process by which the customer consents to share selected information with data access platforms or data recipients, solely for a clearly defined purpose
In the context of open finance, this refers to the process by which the customer’s consent to share their financial account information with data access platforms or data recipients:
• Account credentials-based access – the customers provide their account credentials to the data recipient and/or the data access platform for access to the data provider on behalf of the customer. The resulting consent can only be revoked at the data recipient or the data access platform; and
• Tokenized access – The customers authorize the data providers directly to share their financial account information with the data recipients and/or the data access platforms.
Cyber Resiliency An entity’s ability to prepare for, prevent against, and continuously deliver the intended outcome, despite cyber attacks. Resilience to cyber attacks is essential to IT systems, critical infrastructure, business processes, organizations, societies, and nation-states.
Cyber Security Compensating Control A safeguard or countermeasure deployed, in lieu of, or in the absence of controls designed by a device manufacturer. These controls are external to the device design, configurable in the field, employed by a user, and provide supplementary or comparable cyber protection for a medical device.
Cyber Security Incident Any unauthorized attempt, whether successful or not, to gain access to, modify, destroy, delete, or render unavailable any computer network or system resource.
Cybersecurity The protection of digital information, as well as the integrity of the infrastructure housing and transmitting digital information. More specifically, cybersecurity includes the body of technologies, processes, practices and response and mitigation measures designed to protect networks, computers, programs and data from attack, damage or unauthorized access so as to ensure confidentiality, integrity and availability. Canadian Centre for Cyber Security
Data Information collected in the process of normal business practices such as structured and non-structured information generated from production and non-production systems.
Data Access Platforms Intermediaries that facilitate financial data access, transit, storage and/or permissioning on behalf of data recipients or customers, also commonly referred to as “data aggregators”. In some cases, data access platforms do not have a direct relationship with the customer. The data may be passed through without modification or may be normalized in line with permitted objectives (e.g., parsed for readability or used to confirm other data). Data access platforms should not be confused with parties who do not obtain customers’ consent but gather data, sometimes referred to as data brokers or data harvesters.
Data Accountability A responsibility for data, including a duty to report, explain or justify actions undertaken.
Data Anonymization Policies and Processes How and when to anonymize, aggregate and/or de-identify data, including open data, to appropriate levels; considers risks associated with record-level and aggregate data sharing, risk of privacy breaches, and risks from failing to use data to achieve objectives.
Data Artefacts Documents that capture agreed principles, policies, processes, or procedures so that they are measurable, predictable, repeatable, and transparent.
Data Availability The assurance that all appropriate data is accessible to authorized persons or entities.
Data Breach A security violation, in which sensitive, protected, or confidential data is copied, transmitted, viewed, stolen, altered or used by an individual or group unauthorized to do so. US Department of Health and Human Services
Data Change Management Policies and Processes Policies that describe how to manage and coordinate changes in data and data flows within and across systems and organizations; includes updates to core data artefacts to retain knowledge.
Data Controller A natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data.
Data Custodian An individual or group that is responsible for the safe collection, use, storage, and sharing of data in concordance with applicable data policy and legislation.
Data Disclosure The act of sharing data with an organization or individual or providing an organization or individual with access to data.
Data Domain Boundaries for one or more sets of data that reside within a data management environment. NOTE 1: These boundaries are used to identify the organizational users or groups who define access rules and quality parameters for the data stored within the data domain. NOTE 2: Data domains may be subdivided into one or more data products.
Data Ethics A branch of ethics that looks at how data may affect people and society.
Data Export A data management service which retrieves a set of data from a database and creates a copy of that data organized according to a data interchange format. ISO/IEC TR 10032:2003, 2.20.
Data Import A data management service which inserts into a database a set of data organized according to a data interchange format. ISO/IEC TR 10032:2003, 2.21.
Data Institution A group or organization that manages data.
Data Integrity The maintenance and assurance of data accuracy and consistency over time in the absence of permissible data alteration.
Data Life Cycle Policies and Processes Policies that describe how to manage the full life cycle of data and records for their use locally and with trusted partners; includes data collection and preparation, linking and aggregation, and ongoing maintenance.
Data Linkage A method of connecting data from different sources for the purpose of analysis.
Data Literacy i) The ability to read, understand, create, interpret, and share data for the purposes of decision making.
ii) The competencies involved in working with data, including the ability to assess data quality and ensure data security, to maximize its value for the health and wellbeing of people and populations.
iii) An understanding of the value of data to the health and wellbeing of individuals, populations, and the health system.Statistics Canada
Data Model Graphical, lexical or combined representation of data, specifying their properties, structure, and interrelationships. NOTE: data models respect the controls set by data products which in turn reflect the access and other controls established by data domains and data owners. ISO/IEC 11179-1:2022. modified
Data Owner Person having responsibility and authority for the data. ISO 14292: 2012
Data Privacy The necessity to preserve and protect any information, collected by any Organization, from unauthorized access and use. It is a part of information technology that helps an individual or an organization determine what data within a system can be shared with others and which should be restricted. Also known as information privacy.
Data Protection Referring to the risk management activities involving the implementation, operation, and maintenance of controls designed to safeguard digital information (i.e., data) from unauthorized use, alteration, access, compromise, disclosure, inaccessibility, or destruction. “Data protection” is often used interchangeably with “information protection”, but the terms are not synonymous.
Data Quality The characteristics of optimized data, including completeness, consistency, uniqueness, timeliness, validity, and accuracy, integrity, and conformity.
Data Recipients Organization which receives data from a data owner. This is most likely the data custodian.
Data Requestors Organization that initiates and processes the request to receive data from a data owner. This may be a third-party organization.
Data Schema Physical implementation of a data model in a specific data management system. NOTE: A data schema can include implementation details such as data types, classifications, and access controls.
Data Security A method or methods used to keep data safe from destructive forces and unwanted actions of unauthorized users in order to protect the information.
Data Sharing The practice of exchanging data between individuals or groups to support programs and services.
Data Silo Storage environment for operational data that is specific to an individual application or system and not part of an interconnected network of data.
Data Sovereignty An Organization’s right to control access to and disclosure of its digital information. ISBN 978-0-660-27233-7 (Treasury Board Secretariat) and ISO/IEC DIS 22624:2019, modified
Data Standards A suite of standards that support high data quality, consistent interpretation and empowered data use; broken down into data content standards and data exchange standards as follows:
• data content standards provide meaning and structure to the organization’s data; and
• data exchange standards simplify the way data flows between systems.
Data Standards Policies and Processes Policies that describe how to adopt and deploy data content standards, data exchange standards, master data and associated specifications, guidelines, communication and evaluation.
Data Steward Role within an organization responsible for ensuring that data-related work is performed according to policies and practices as established through data governance. ISO/IEC 38505:2015
Data Stewardship The oversight of data assets that involves efforts to optimize data quality, and making decisions about who has access, for what purpose and to whose benefit.
Data Structure A specialized format for organizing, processing, retrieving, and storing data to facilitate its use.
Data Subject A person or entity to whom data relates, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data Supply Chain A defined set of data flows, often across organizations, that achieve a desired outcome. For example, to improve individual health outcomes primary care, acute care, testing, and specialist need data to be exchanged and useable. The objective of defining a data supply chain is to streamline activities associated with data collection, access, sharing, and use among its members while optimizing performance of desired outcomes.
Decentralized Identifier A globally unique persistent identifier that does not require a centralized registration authority and is often generated and/or registered cryptographically.
De-identification A process of removing or changing data so that it no longer identifies an individual or could, foreseeably, identify an individual in the future.
Denial of Service An attack that bombards a system with connections to keep it so busy that it is unable to accept legitimate connections. Canadian Centre for Cyber Security
Desktop As A Service (DAAS) A form of Virtual Desktop Infrastructure (VDI) in which traditional desktop computing capabilities are accessed remotely, typically via a web browser or dedicated application. Typically, there is no storage of either applications or data on the accessing endpoint.
Device A machine, specifically a piece of electronic equipment.
Digital Credential A portable digital record about a Subject (e.g., organization, individual, product) that can be held and presented through a Holder Component (e.g., digital wallet or vault). It is the digital representation of a traditional physical certificate or other types of information.
Digital Credential Authenticator Binding The process of associating a digital credential issued to a Holder with one or more authenticators. This process also includes authenticator life-cycle activities such as suspending authenticators (caused by a forgotten password or a lockout due to successive failed credential verification attempts, inactivity, or suspicious activity), removing authenticators, binding new authenticators, and updating authenticators (e.g., changing a password, updating security questions and answers, having a new facial photo taken).
Digital Credential Format The format of a digital credential defines how verifiers can accurately extract what is needed to perform a verification in a given context.
Digital Credential Management System The people, processes, and information technologies that enable the use of digital credentials.
Digital Credential Recovery The process of transforming a suspended digital credential back to a usable status (i.e., an issued digital credential).
Digital Credential Revocation The process of ensuring that an issued digital credential is permanently flagged as unusable.
Digital Credential Suspension The process of transforming an issued digital credential into a suspended digital credential by flagging
the issued digital credential as temporarily unusable.
Digital Credential Validation The process of verifying that the issued digital credential is valid (e.g., not tampered with, corrupted, modified, suspended, or revoked). The validity of the issued digital credential can be used to generate a level of assurance.
Digital Credential Verification The process of verifying that a Holder has control over an issued digital credential. Control of an issued digital credential is verified by means one or more authenticators. The degree of control over the issued digital credential can be used to generate a level of assurance.
Digital Ecosystem A collection of various tools and systems, and the actors who create, interact with, use, and remake them.
Digital Identity An electronic representation of a person or group to access services with trust and confidence.
Digital Trust Registry Enabling service for digital credentials, such as publicly accessible verifiable data registry that mediates the creation and verification of identifiers, keys, and other relevant data, such as credential schemas, revocation registries, issuer public keys, and so on, which might be required to use credentials.
Digital Trust Service An enabling service for digital credentials, such as verifiable data registries, issuing, and verifying services and digital wallets.
Digital Twin A computer-based virtual representation that looks and behaves the same as its real-world counterpart. Digital Twin Consortium
Digital Wallet Also referred to as an e-wallet, an electronic device, online service, or software program that enables secure electronic transactions.
Distributed Ledger Ledger that is shared across a set of Distributed Ledger Technology (DLT) nodes and synchronized between the DLT nodes using a consensus mechanism. ISO 22739:2020 Blockchain and distributed ledger technologies — Vocabulary
Domain-based Message Authentication, Reporting & Conformance (DMARC) An email authentication protocol. It is designed to given email domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing.
Domain Name System (DNS) Hierarchical, distributed global naming system used to identify entities connected to the Internet.
NOTE: The Top-Level Domains (TLDs) are the highest in the hierarchy.ISO/TR 14873:2013
Domain An environment or context that includes a set of system resources and a set of system entities that have the right to access the resources as defined by a common security policy, security model, or security architecture. National Institute of Standards and Technology
NIST SP 800-53 Rev. 5
Double Materiality The two perspectives of materiality. It includes both financial materiality and impact materiality. Double materiality is sometimes described as “on/of”: referring to impacts “on” and “of” an entity. Others refer to inside-out and outside-in: for example considering how an entity contributes to climate change (“inside-out” vision) and how the risk climate change poses for the entity (“outside-in” vision).
dynamic materiality considers both actual impacts, an impact that has already occurred or is occurring (in progress) and potential impact: an impact that may occur but has not yet done so.
eIDAS Electronic Identification, Authentication, and Trust Services (eIDAS) is a European Union regulation that oversees electronic identification and trust services for electronic transactions in the European Union’s internal market. It regulates electronic signatures, electronic transactions, involved bodies, and their embedding processes to provide a safe way for users to conduct business online such as electronic funds transfer or transactions with public services.
Electronic Signature (E-Signature) A legal digital equivalent to a handwritten signature.
Enabling Capability Practices and techniques that may help the organization achieve its desired outcomes.
Encryption Protection of information by making it unreadable by everyone except those with the key to decrypt it. NCSC.GOV.UK
Enterprise Mobility Management Systems that manage movable computing devices or services for an enterprise.
Entity A thing with a distinct and independent existence, such as a Person, Organization, or device, that can be Subject to legislation, policy, or regulations within a context, and which may have certain rights, duties, and obligations. An Entity can perform one or more roles in the digital ecosystem.
Ethical Impact Assessment A framework to ensure that AI developments align with the promotion and protection of human rights and human dignity, environmental sustainability, fairness, inclusion, and gender equality. It underscores that these goals and principles should inform technological developments in an ex-ante manner. UNESCO. (2023). Ethical Impact Assessment: A Tool of the Recommendation on the Ethics of Artificial Intelligence
Ethics by Design A method of protecting human values and upholding ethics within the design of technology, products, and services.
Evidence An assertion data supporting the existence or verity of something.
Evidence of Contextual Identity Evidence of contextual identity (of an Organization)
Evidence of identity that corroborates the evidence of foundational identity and assists in linking the identity information to an Organization. It may also provide additional information such as market activity, signature, or address. Examples include records of licences to carry on logging or mining activities, or to cultivate cannabis; and registrations of charitable status.
Evidence of contextual identity (of a Person)
Evidence of identity that corroborates the evidence of foundational identity and assists in linking the identity information to a Person. It may also provide additional information such as a photo, signature, or address. Examples include social insurance records; records of entitlement to travel, drive, or obtain health services; and records of marriage, name change, or death originating from a jurisdictional authority.
Evidence of Foundational Identity Evidence of foundational identity (of an Organization)
Evidence of identity that established core identity information about an Organization such as legal name, date of event, address, status, primary contact. Examples are registration records, certificates of compliance, and incorporation records from an authority with the necessary jurisdiction.
Evidence of foundational identity (of a Person)
Evidence of identity that establishes core identity information about a Person such as given name(s), surname, date of birth, and place of birth. Examples are records of birth, immigration, or citizenship from an authority with the necessary jurisdiction.
Evidence of Identity A record from an authoritative source indicating an Entity’s Identity. There are two categories of evidence of identity: foundational and contextual. See “evidence of foundational identity” and “evidence of contextual identity”.
FAIR Principles An industry standard to allow the reuse of data by making sure it is Findable, Accessible, Interoperable, and Reusable.
Federation 1. The act of establishing a relationship between two entities.
2. An association comprising any number of service providers and identity providers.REFERENCE: Glossary for the OASIS Security Assertion Markup Language (SAML) V2.0
Feedback Opinions, comments and expressions of interest in a product, service or complaints handling-process.
Financial Institutions (FIs) Institutions in the business of accepting deposits, issuing loans, bonds, securities, or managing transactions and savings of persons including banks, credit unions, pension funds, insurance companies, etc.
Findable Metadata and data should be easy to find for both humans and computers. Machine-readable metadata are essential for automatic discovery of datasets and services.
Firmware A specific class of software encoded directly into a hardware device that controls its defined functions and provides the low-level control for the device’s specific hardware (such as the firmware that initially boots an operating system). VVSG 2.0.
Foundational Event A significant discrete episode that occurs in the life span of a Person or an Organization. By law a foundational event must be recorded with a government entity and is subject to legislation and regulation. Examples of foundational events for Persons are live birth, stillbirth, adoption, legitimation, recognition of parenthood, immigration, legal residency, naturalized citizenship, name change, marriage, annulment of marriage, legal separation, divorce, and death. Examples of foundational events for Organizations are registration of charter, merger, amalgamation, surrender of charter, and dissolution.
Foundational Identity An Identity that has been established or changed as a result of a foundational event (e.g., birth, Person legal name change, immigration, legal residency, citizenship, death, Organization legal name registration, Organization legal name change, bankruptcy). See also “contextual identity”.
Geo-Jurisdiction Cross-Jurisdiction) A cross-border flow of data where jurisdictional policies are applied to determine what actions are permissible for the data with regards to storage, processing, and transit. ISO/IEC DIS 22624:2019, modified
Governing Body Person or group of people who are accountable for the performance and conformance of the organization. ISO/IEC 38500:2015
Hardened Operating System Operating system which has been configured or designed specifically to minimize the potential for compromise or attack. NOTE: This may be a general operating system, such as Linux, which has been configured for this environment or may be a more custom-built solution.
ISO/IEC 27033-4:2014.
Holder An entity that controls one or more digital credentials from which a presentation can be expressed to a verifier. A holder is usually, but not always, the subject of a digital credential.
Holder Component Information technology through which digital credentials can be stored and presented, such as a digital wallet or vault.
Human In The Loop An automated decision system that requires human input for any aspect of task execution, or when a human is accountable for executing the administrative decision.
Human On The Loop An automated decision system can operate independently but under human oversight, with intervention as needed, i.e., a human oversees and may override the automated administrative decision.
Human Out Of The Loop A determination is made by an automated decision system without human intervention, i.e., human cannot view, oversee, or override the automated administrative decision.
Identification In the context of biometric identification, the process of establishing the identity of an unknown person by establishing a connection between unknown and unverified data and known and verified data.
Identifier The set of identity attributes used to uniquely distinguish a particular person, organization, or device within a population.
Identity A reference or designation used to uniquely distinguish a particular Person, organization, or device. There are two types of Identity: foundational and contextual. See “foundational identity” and “contextual identity”.
Identity Assurance Confidence that a person, organization, or device is who or what it claims to be.
Identity Assurance Level The level of confidence that a person, organization, or device is who or what it claims to be.
Identity Attribute A property or characteristic associated with an identifiable person, organization, or device (also known as “identity data element”).
Identity Context The environment or set of circumstances within which an organization operates and within which it delivers its programs and services. Identity context is determined by factors such as mandate, target population (i.e., clients, customer base), and other responsibilities prescribed by legislation or agreements.
Identity Continuity The process of dynamically confirming that the subject has a continuous existence over time (i.e., “genuine presence”). This process can be used to ensure that there is no malicious or fraudulent activity (past or present) and to address identity spoofing concerns.
Identity Data Element See “identity attribute”.
Identity Establishment The process of creating a record of identity of a subject within a program/service population that may be relied on by others for subsequent programs, services, and activities.
Identity Evidence Determination The process of confirming that the evidence of identity presented (whether physical or electronic) is acceptable.
Identity Information The set of identity attributes that is sufficient to distinguish one entity from all other entities within a program/service population and that is sufficient to describe the entity as required by the program or service. Depending on the context, identity information is either a subset of personal information or a subset of organizational information.
Identity Information Determination The process of determining the identity context, the identity information requirements, and the identifier.
Identity Information Notification The disclosure of identity information about an Entity by an authoritative party to a relying party that is triggered by a foundational event, a change in their identity information, or an indication that their identity information has been exposed to a risk factor (e.g., the death of the Person, a charter surrender, use of expired documents, a privacy breach, fraudulent use of the Identity information).
Identity Information Retrieval The disclosure of identity information about an Entity by an authoritative party to a relying party that is triggered by a request from the relying party.
Identity Information Validation The process of confirming the accuracy of identity information about a Subject as established by the Issuer.
Identity Linking The process of mapping one or more assigned identifiers to a Subject.
Identity Maintenance The process of ensuring that a Subject’s identity information is accurate, complete, and up-to-date.
Identity Management The set of principles, practices, processes, and procedures used to realize an Organization’s mandate and its objectives related to Identity.
Identity Model A simplified (or abstracted) representation of an identity management methodology (also known as “identity scheme”).
NOTE: Examples include centralized, federated, and decentralized Identity models.
Identity Proofing A process of establishing a level of confidence with respect to the Foundational or Functional (Conceptual Identity) of an applicant through validation and verification during enrollment in an Identity Management System (IdMS).
• Validation: This is a process to authenticate or legitimize Personal Identifiers (or Identity Attributes) presented by applicants during enrollment in an Identity Management System.
o foundational evidence of identity
o contextual or functional identity
• Verification: Provable high confidence in the claimed connection between applicant and validated Personal Identifiers or Identity Attributes.
Identity Provider A kind of service provider that creates, maintains, and manages identity information for entities and provides entity authentication to other service providers within a federation. REFERENCE: Glossary for the OASIS Security Assertion Markup Language (SAML) V2.0
Identity Resolution The process of establishing the uniqueness of a Subject within a population through the use of identity information.
Identity Scheme See “identity model”.
Identity Verification The process of confirming that the identity information is under the control of the Subject.
Impact Refers to the measurable change (positive or negative) in the life of a beneficiary/stakeholders, which lasts in time.
Impact Materiality The consideration of actual or potentially significant impacts that an entity (entity’s operations and its upstream and downstream value chain) has on the environment and society.
Impact Model A collective term for the various ways that entities can describe how their actions impact people and ecosystems. An impact model describes the causal links between activities and outcomes. Theory of change, logic model, impact chain and impact thesis are each example of an impact model.
– Theory of change: An outcomes-based hypothesis of how the entity is expected to contribute positively to positive impact generation. The impact thesis may be separate to, but ideally is integrated into, strategy, business models or investment thesis, as applicable.
– Logic Model: A structured table that links inputs, and activities to measurable outputs and outcomes.
– Impact chain: A visual representation of how an entity affects change, focused on noting how early impacts lead to further impacts.SDG-Impact-Standards-Glossary.pdf (undp.org)
Impact Risk The likelihood that impact will be different than expected, and that the difference will be material from the perspective of the people or the planet who experience impact. IMP references 9 types of risk that include evidence risk, external risk, stakeholder participation risk, drop-off risk, efficiency risk, execution risk, alignment risk, endurance risk and unexpected impact risk.
Impact Statement May go by several names, in essence, it’s a public statement about your entity’s understanding of the positive and negative impacts of your activities and operations.
Impartiality Objectivity, neutrality, and fairness along with the awareness of bias and reduction of prejudice.
Note 1 to entry: It is important for impartiality that possible conflicts of interest are declared, resolved or do not exist.ISO 21043-1:2018
Incident Response Plan A document that establishes processes, procedures, and documentation related to how your organization detects, responds to, and recovers from incidents. Cyber threats, natural disasters, and unplanned outages are examples of incidents that will impact your network, systems, and devices. Canadian Centre for Cyber Security
Indicator Quantitative or qualitative factor or variable that provides a simple and reliable means to measure achievement, to reflect the changes connected to an intervention, or to help assess the performance of an actor. IMP Glossary
Indigenous Data Sovereignty A recognition that Indigenous peoples, communities and Nations should participate, steward and control data that are created with or about themselves and ensure ultimate authority to be sovereign in their governance over their data and knowledge. University of Toronto Research Guide: Indigenous Studies3F4
Information A form of data that has already been interpreted and has meaning in a specific context. Global Alliance for Genomics and Health (GA4GH)
Information and Privacy Commissioners/Ombudsmen and Data Protection Supervisory Authorities Independent bodies appointed by government, whose roles entail providing fair, independent, and impartial advice and information about privacy and access -to-information rights and responsibilities; and enforcing access-to-information and/or privacy laws that set out the rules for how government institutions and organizations must handle personal information.
Information Governance A process of ensuring that rules and oversight are in place to uphold legal, ethical and practical requirements when handling information. Canada Health Infoway
Information Protection Referring to the risk management activities involving the development, implementation, operation, and maintenance of controls designed to safeguard non-digital information from unauthorized use, alteration, access, compromise, disclosure, inaccessibility, or destruction. “Information protection” is often used interchangeably with “data protection” but the terms are not synonymous.
Injury The damage that businesses suffer from the compromise of information systems and IT assets.
Integrated Dataset A set of data from different sources that brings together different pieces of data from different people.
Integrated Surveillance A combination of active and passive systems using a single infrastructure that gathers information about multiple diseases or behaviors of interest to several intervention programs.
Integrity The ability to protect information from unauthorized modification or deletion.
Integrity Failure Log A record of failures detected during the verification of files or data that are critical to the operation or security of a system, or any identified integrity issues related to that system’s data.
In the case of electronic poll books, this refers to an electronic record of failures detected during the verification of files critical to the operation or security of an electronic poll book or an integrity issue found with any electronic poll book data.New Jersey Electronic Poll Book Regulations.
Interoperability A method of ensuring capacity for seamless sharing of data and information between stakeholders by means of policy, governance, workflow and, especially, technical alignment including both at the level of software and standardized concepts and definitions for data elements.
Interoperable The data usually needs to be integrated with other data. In addition, the data needs to interoperate with applications or workflows for analysis, storage, and processing.
Issuer An Entity that asserts one or more Claims about one or more Subjects, creates a Credential from these Claims, and assigns the Credential to a Holder.
Issuer Component Information technology through which digital credentials can be issued and revoked.
IT Information technology.
Key Owner The party (person or organization) designated as custodian of an encryption key, with the right to determine to whom the key is distributed, and to define how the key may be used.
Knowledge-Based Confirmation An Identity Verification method that uses personal information or shared secrets to prove that the Subject presenting the identity information is in control of the Identity.
NOTE: Knowledge-based confirmation is achieved by means of the challenge-response model: the Subject presenting the identity information is asked questions, the answers to which should be known only to the Subject and Verifier (e.g., financial information, credit history, shared secret, cryptographic key, mailed-out access code, password, personal identification number, assigned identifier).
Least Privilege The principle of giving an individual only the set of privileges that are essential to performing authorized tasks. This principle limits the damage that can result from the accidental, incorrect, or unauthorized use of an information system. Canadian Centre for Cyber Security
Ledger Information store that keeps records of transactions that are intended to be final, definitive and immutable. ISO 22739:2020 Blockchain and distributed ledger technologies — Vocabulary
Logic and Accuracy (L&A) Testing Equipment and system readiness tests whose purpose is to detect malfunctioning devices and improper election-specific setup before the equipment or systems are used in an election. Election officials conduct L&A tests on all ballot designs prior to the start and end of an election, as part of the process of setting up the system and the devices for an election according to jurisdiction practices and conforming to any local laws. NIST election terminology glossary.
Machine Learning A set of techniques that allows machines to improve their performance and usually generate models in an automated manner through exposure to training data, which can help identify patterns and regularities, rather than through explicit instructions from a human. It may however in some instances include explicit instructions from a human. The process of improving a system’s performance using machine learning techniques is known as training.
Malicious Code Programs or code written for the purpose of gathering information about systems or users, destroying system data, providing a foothold for further intrusion into a system, falsifying system data and reports, or providing time-consuming irritation to system operations and maintenance personnel. NOTE 1: Malicious code attacks can take the form of viruses, worms, Trojan horses, or other automated exploits. NOTE 2: Malicious code is also often referred to as “malware”. IEC/TS 62443-1-1:2009
Malware Malicious software designed to infiltrate or damage a computer system, without the owner’s consent. Common forms of malware include computer viruses, worms, Trojans, spyware, and adware. Canadian Centre for Cyber Security, Glossary
Marginal/Ambiguous Mark A mark on the ballot that cannot be definitively assigned by the vote tabulator.
Materiality Materiality is a process used to help identify the impacts that need to be managed and to determine the sufficiency of information needed to make a decision.
May A key word that indicates flexibility of choice with no implied preference.
Metadata Data that define and describe other data. ISO/IEC 11179-1:2022
Metrics Numerical measures used in calculations or qualitative values to account for the social, environmental, and financial performance of an activity. GIIN, Methodology for Standardizing and Comparing Impact Performance
Model Refers to a methodology, system, and/or approach that applies theoretical and (expert) judgmental assumptions and statistical techniques to process input data in order to generate quantitative estimates. A model has three distinct components: i) a data input component that may also include relevant assumptions; ii) a processing component that translates the inputs into estimates; and iii) a result component that presents these estimates in a format that is useful and meaningful to business lines and control functions. OSFI Guideline E-23, 2017
Model Development A unit(s)/individual(s) responsible for designing, developing, evaluating, and documenting models which may also perform ongoing monitoring and outcomes analysis as well as periodic reassessment once a model is in use. OSFI Guideline E-23, 2017
Model Governance Establishment of end-to-end policies, practices, and procedures to ensure that a model is fit-for-purpose, designed to avoid error or bias, and produces valid and verifiable outputs including accountabilities for model explainability, fairness, impacts, and human controls. OSFI Guideline E-23 Update Letter, May 2022, modified
Model Risk The risk of adverse financial (e.g., capital, losses, revenue) and reputational consequences arising from the design, development, implementation and/or use of a model. It can originate from, among other things, inappropriate specification; incorrect parameter estimates; flawed hypotheses and/or assumptions; mathematical computation errors; inaccurate, inappropriate or incomplete data; inappropriate, improper or unintended usage; and inadequate monitoring and/or controls. OSFI Guideline E-23
Monitoring An operational stage in the machine learning lifecycle that comes after model deployment. It entails monitoring AI/ML models for changes such as model degradation, data drift, and concept drift, and ensuring that model is maintaining an acceptable level of performance. Domino Data Lab
Multi-Factor Authentication Authentication that uses a combination of two or more different authentication factors – something a user/operator knows (e.g., a password), has (e.g., a physical token), or is (e.g., a biometric) – to verify a user/operator’s identity.
Network System Failures (Widespread) An incident affecting the confidentiality, integrity, or availability of a network.
OCAP® Principles of data governance that describe how First Nations’ data and information should be collected, protected, used, and shared. “OCAP” is an acronym for Ownership, Control, Access, and Possession. First Nations Information Governance Centre
OCAS Principles of data governance that describe how Métis peoples’ data and information should be collected, protected, used, and shared. “OCAS” is an acronym for Ownership, Control, Access, and Stewardship. Indigenous Knowledges & Data Governance Protocol – Indigenous Innovation Initiative, 2021
One Time Password (OTP) A single-use password that is generated by a data holder. A customer uses this to authenticate.
Open In the context of procurement, accessible, transparent, clear and understandable.
Open Banking / Open Finance An ecosystem in which financial account information is made available to customers to share with data recipients, limited primarily to deposit accounts (chequing and savings accounts), as well as respective payments activity, for individuals and SMEs.
Open Banking Policy / Open Finance Policy An enterprise-level document that describes the purpose, goals, principles and scope of the organization’s open banking and/or open finance program.
Operational Technology (OT) Programmable systems or managed devices that interact with the physical environment. These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Example of such medical devices are X-ray machines, dialysis machines, patient monitoring devices, simulation technology devices etc. NIST 800-37 Rev. 2, modified
Operator An entity that operates an authorization server or a resource server or a client application for the benefit of a client
Organization Person or group of people that has its own functions, with responsibilities, authorities and relationships to achieve its objectives. NOTE: The concept of organization includes, but is not limited to, sole-trader, company, corporation, firm, enterprise, authority, partnership, association, charity or institution, of part of combination thereof, whether incorporated or not, public or private.
Organizational Information Information about an identifiable organization.
Outcome Result of the performance (or non-performance) of a function or process.
In the context of impact statements, an outcome is an effect your program produces on the population served or issues affected, such as anticipated changes in knowledge, skills, attitudes, behavior, condition, or status. Changes should be measured and monitored and linked directly to the activity.
OWASP Open web application security project.
Pairwise Pseudonymous Identifier An identifier known to and used only between a specific client-application/server pair or client/operator pair.
Password Manager A computer program that allows users to store, generate, and manage their passwords for local applications and online services. A password manager assists in generating and retrieving complex passwords, storing such passwords in an encrypted database, or calculating them on demand.
Patching The act of applying updates to computer software or firmware.
Payment Account Means an account held in the name of one or more payment service users which is used for the execution of payment transactions.
Payment Initiation Service (PIS) Means a service to initiate one or more payment orders at the request of the payment service user with respect to a payment account held at another payment service provider.
Payment Initiation Service Provider (PISP) An organization that provides payment initiation services.
Permissioning The process by which consent for data access is granted and revoked by the customer.
Permissions Set of rules which describe what a user or group of users may access or control within a system. ISO/IEC 18598:2016
Person A human being (referred to in law as a “natural person”) including “minors” and others who might not be deemed to be Persons under the law.
Personal Abilities and Attributes Inherent and developed aptitudes that facilitate the acquisition of knowledge and skills to perform at work. Employment and Social Development Canada (2021), Skills and Competencies Taxonomy
Personal Information information about an individual that can be used to reveal their identity.
Personally Identifiable Data A term to describe personal data about identified or identifiable individuals.
Person-Centric Data In the context of health, robust personal health information (or data) record that is designed to follow an individual over time and across locations for the entire course of their health journey.
Phishing An attack where a scammer calls, text messages, emails, or uses social media to trick individuals into clicking a malicious link, downloading malware, or sharing sensitive information. Phishing attempts are often generic mass messages, but the message appears to be legitimate and from a trusted source (e.g., from a bank, courier company). Canadian Centre for Cyber Security
Physical Possession Confirmation An Identity Verification method that requires physical possession or presentation of evidence (e.g., a Credential) to prove that the Subject presenting the identity information is in control of the Identity.
Plain Language Wording, structure, and design are so clear that the intended readers can easily find what they need, understand what they find, and use that information.
Population Descriptors The grouping or categorization of people based on a common or similar characteristic, such as by race, ethnicity, or ancestry.
Potentially Detrimental Action Any action that is irreversible, could potentially result in any loss of data, or cause operational disruptions to the customer(s) and their business.
Privacy Refers to the right to be let alone, and to have some control over whether or how your personal information is collected and used. Its meaning is context-dependent, and includes:
a. “Information privacy” or, more generally “privacy”, typically refers to the right of individuals to control the collection, use, processing, storage, and disclosure of information about themselves; to control by whom it is collected, used, processed, stored and disclosed; and under what circumstances or conditions.
b. “Physical privacy” relates to the ability to prevent intrusion in one’s physical space.
Privacy Breach Theft of, loss of, or unauthorized collection, use or disclosure of, personal information.
Privacy by Default Means that the “privacy by design” principle is incorporated by default into any system or business, so that personal data is automatically protected without any action from the data subject.
Privacy by Design Design framework in which privacy is considered and integrated into the initial design stage and throughout the complete lifecycle of products, processes or services that involve processing of personally identifiable and de-identified information, including product retirement and the eventual deletion of any associated personally identifiable information. NOTE: The lifecycle also includes changes or updates.
ISO 31700-1:2023 Consumer protection — Privacy by design for consumer goods and services — Part 1: High-level requirements
Privileged User A user/operator who, by virtue of function, and/or seniority, has been allocated powers within a system, which are significantly greater than those available to the majority of a user/operator. ISO/IEC 24775-2:2021, 3.1.47.
Process Set of interrelated or interacting activities which transforms inputs into outputs.
NOTE 1: Inputs to a process are generally outputs of other processes.
NOTE 2: Process in an organization is generally planned and carried out under controlled conditions to add value.
NOTE 3: A process where the conformity of other resulting product cannot be readily or economically verified is referred to as a “special process”.ISO 9001:2005 Quality management systems — Requirements
Processing To collect, use, access, disclose, delete, retain, or archive, Personal Information, whether or not by automated means.
Processor Any entity processing personal information on behalf of a Data Controller under an agreement with a Data Controller or a Joint Data Controller. In some circumstances, the Processor and the Data Controller could be the same party.
Procuring Organization Organization obtaining digital products and/or services from an external provider. NOTE: Also known as purchasing organization.
Product Result of a process. ISO 9001:2005 ISO Quality management systems — Requirements
Protected Resource A resource, access to which is protected by an authorization server.
Protection Realm A networked system responsible for governing a specific subset of users and protection spheres.
Protection Sphere The intersection of sensitive data relating to a common topic or criteria, and the people in the “need-to-know” who share a common goal or mission.
Provider Organization that provides a product or service. NOTE: Also known as supplier or vendor.
Ransomware A type of malware that denies a user’s access to a system or data until real or virtual goods and/or funds are paid. Cybersecurity for SMEs
Recognized Body An organization or entity that has been granted official status, acknowledgement or authority by a government, professional association, or another established authority.
Record Retrievable information.
Redundant Data Data stored in two or more places
Relying Party A system entity that decides to take an action based on information from another system entity. For example, a SAML relying party depends on receiving assertions from an asserting party (a SAML authority) about a subject REFERENCE: Glossary for the OASIS Security Assertion Markup Language (SAML) V2.0
Remote Control Control of a machine by wireless or wired transmission of signals from a remote-control box not located on the machine to a receiving unit located on the machine. ISO 15817:2012, 3.7, modified.
Requesting Party A client that uses a client application to seek access to a protected resource. The requesting party may or may not be the same entity as the resource owner.
NOTE: A requesting party is a Verifier if the given protected resource is a Credential.REFERENCE: User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorization
Resource Data contained in an information system, or a service provided by a system.
NOTE: A resource may also be a claim or a credential.REFERENCE: Glossary for the OASIS Security Assertion Markup Language (SAML) V2.0
Resource Model A document that describes the kinds of resources available in a federated network.
Resource Owner A client capable of granting access to a protected resource. REFERENCE: User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorizatio
Resource Server A server that hosts resources on a resource owner’s behalf and is capable of accepting and responding to requests for protected resources. REFERENCE: User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorization
Reusable Metadata and data should be well-described so that they can be replicated and/or combined in different settings.
Revocation The process or act of ending or removing permission for access.
SaaS Software as a Service: centrally hosted software accessed primarily via web browsers, often licensed in a subscription model.
Screen Scraping (aka Data Scraping and Web Scraping) A method for retrieving data from a digital system or online interface. Such access is often, but not limited to, from an HTML (Hypertext Markup Language) page via automated scripts, and can also occur through terminal emulation, APIs, or other interfaces. This method typically relies on credential-based access authorized by a user or entity.
In the case of financial account information, this refers to the retrieval of financial account information. Such access is often, but not limited to, from an HTML (hypertext markup language) page via electronic means (usually via automated script) but can also be from terminal emulation, API, or other interface. This method leverages the account credentials-based access variant of customer authorization.
Secondary Use of Data The use of data for a purpose that differs from the original intended use.
Secure Mobility Security of mobile devices e.g. cellular phones and tablets.
Security The processes, actions, policies, regulatory requirements, responses, and procedures applied, communicated, adhered to, agreed to, and monitored, to protect the confidentiality and integrity of an organization’s assets (data, information etc.)
Sensitive Data Data with potentially harmful effects in the event of disclosure or misuse. ISO/IEC TR 24028:2020 Information technology — Artificial intelligence — Overview of trustworthiness in artificial intelligence
Sensitive Information Information that requires protection against loss, modification, and unauthorized disclosure. NOTE: Sensitive information can include personal information, business information or classified information.
Sensitive Personal Information (SPI) Data that if used inappropriately, could promote inequities, or endanger personal health, wellbeing, or assets.
Server A computer or software system that provides services, resources, or data to other computers (called “clients”) over a network.
Service Interruption Incident that prevents access to a service or otherwise impairs normal operation.
Service Provider A system that provides services to Entities or other systems. REFERENCE: Glossary for the OASIS Security Assertion Markup Language (SAML) V2.0
Shall A requirement.
Should A keyword indicating flexibility of choice with a strongly preferred alternative; equivalent to the phrase “it is strongly recommended”.
Skills Developed capacities that an individual must have to be effective in a job, role, function, task, or duty. Employment and Social Development Canada (2021), Skills and Competencies Taxonomy
Small and Medium Sized Organization (SMO) Organization defined by a number of employees or size of financial activities that fall under certain thresholds, which vary from country to country. ISO 20400:2017 NOTE: In Canada this is defined by any organization with less than 500 employees.
Software Agent An application by which a resource owner manages credentials, approves or rejects access requests, and sets access control policies.
Software Installation/Removal Log An electronic record of software installed on, or removed from, an electronic poll book. New Jersey Electronic Poll Book Regulations.
Solution Provider Any organization involved in the development, deployment and/or maintenance of the solution.
Spear Phishing A phishing attack that targets a specific person, group or organization. It uses personal or professional details to entice an individual to respond, click on a link or open an attachment. Canadian Centre for Cyber Security
Stakeholder Person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity. ISO 31700-1:2023 Consumer protection — Privacy by design for consumer goods and services — Part 1: High-level requirements
Storage Component A foundational layer for secure data storage, including personal data, including data models for storage and transport, syntax, data at rest protection.
Subject An entity about which claims are asserted by an issuer.
Supplemental Capability An ability that provides added value and options for the organization.
Synthetic Data A form of simulated data that is often computer-generated, altered, augmented, or replaced to protect individual privacy while duplicating the statistical properties and relationships of the real data on which it is modeled.
System The people, processes and information technologies crafted to enable secure third-party access to data.
Target Device The device to which signals are transmitted or transferred.
Third-Party A person, group, or public authority other than the data subject, controller, or others that have permission to work with the data.
Traceability Ability to follow the movement of information through the stages of the information lifecycle.
Trust Framework A set of agreed on principles, definitions, standards, specifications, conformance criteria, and assessment approach.
Trusted Storage Media Non-volatile data storage media which uses the most recent FIPS 140 cryptographic standard or equivalent cryptographic technologies to assure the integrity and confidentiality of any data at rest on the media.
Trustee A person or an organization who has authorized control of information and is responsible for managing it.
Unauthorized (access, Disclosure, Use) Access to physical or logical network, system, sub-system, or data without authorization and/or authentication. An incident affecting the confidentiality, integrity, or availability of data. Use of a physical or logical network, system, or data without permission.
Unauthorized Access Access to physical or logical network, system, or data without permission.
Unauthorized Disclosure An incident affecting the confidentiality, integrity, or availability of data.
Unauthorized Use Use of a physical or logical network, system, or data without permission.
USB (Universal Serial Bus) Serial system for connecting a computer with external devices. ISO 2789:2022, 3.3.59.
User Access Logs An electronic record of all user access, that includes activities such as: the username, user permission level; the network address used; the date and time of the start of access; and the date and time of the end of access. New Jersey Electronic Poll Book Regulations, modified.
User Agency An ability of an entity to freely make choices in the specification of access control policies with respect to resources, including identity information, that describe or relate to that entity, or of which that entity is the resource owner.
User Interface The means through which a person interacts with an electronic device, software application, or system. It encompasses the visual, auditory, and tactile components that enable user input and system feedback, such as graphical elements (e.g., screens, icons, and menus), voice commands, keyboards, touchscreens, or other input/output mechanisms.
Verifiable Digital Credential Is a tamper-evident credential that has authorship that can be cryptographically verified. Verifiable digital credentials can be used to build verifiable presentations, which can also be cryptographically verified.
Verifier An Entity that accepts a Presentation from a Holder for the purposes of delivering services or administering programs.
Verifier Component information technology from which a digital credential can be verified authentic and valid.
Virtual Private Network (VPN) Restricted-use logical computer network that is constructed from the system resources of a physical network by using encryption and/or by tunnelling links of the virtual network across the real network. REFERENCE: ISO/IEC 18028-3:2005 Information technology — Security techniques — IT network security — Part 1: Network security Management
Wi-Fi Protected Access Security protocol and security certification program developed by the Wi-Fi Alliance to secure wireless computer networks. REFERENCE: ISO 20415:2019 Trusted mobile e-document framework — Requirements, functionality and criteria for ensuring reliable and safe mobile e-business
Wireless Local Area Networking (WLAN)/(Wi-Fi) Wireless local area networking technology that allows electronic devices to network, mainly using the 2,5 GHz and 5 GHz radio bands. NOTE 1: “Wi-Fi” is a trademark of the Wi-Fi Alliance. NOTE 2: “Wi-Fi” is generally used as a synonym for “WLAN” since most modern WLANs are based on these standards.
ISO/IEC 27033-6:2016
Workplace Physical location where work is performed. ISO 41011:2017 Facility management
Zero-Copy Application Utilize active metadata to power the user experience and to create a sole source of truth. Zero-copy experiences can appear the same, but they differ from traditional applications or operational copies in that their designs do not include a dedicated database or copy-based data integration. Crucially for data governance, they preserve the data access controls set by data owners in the physical data layer.