Short definitions for enterprise-security governance, architecture, and control-validation terms.
| Term | Definition |
|---|---|
| Zero trust | A security approach that continuously evaluates identity, device, context, and least privilege rather than granting broad trust based only on location |
| Risk appetite | The amount and type of risk an organization is willing to accept |
| Threat model | A structured analysis of assets, threats, attack paths, trust boundaries, and mitigations |
| Key lifecycle | Creation, use, rotation, backup or escrow where approved, revocation, and destruction of cryptographic keys |
| Control validation | Evidence-based testing that a safeguard operates as intended and provides the expected risk reduction |
| Third-party risk | Risk introduced by a vendor, supplier, partner, or external service provider |
| Compensating control | An alternate safeguard that reduces risk when a primary control cannot be implemented |
| Inherent risk | Risk before relevant safeguards are applied |
| Residual risk | Risk that remains after safeguards are applied |
| Defense in depth | Layered controls that reduce reliance on any single safeguard |
A control changes behavior or reduces exposure. Evidence shows that the control exists, is operating, and is reviewed. Both are needed for a mature security program.