Glossary
A
- Analyst Risk › Vulnerability
- A stakeholder role in the Vulnerability module. The Analyst is responsible for researching and scoring a vulnerability but does not have formal review or approval authority.
- Approver All modules
- A stakeholder role assigned to a record who must formally approve it before it can become Active. An Approver acts after all Reviewers have completed their review.
- Artifacts Compliance › Assessments
- Files and documents uploaded as supporting evidence within an assessment. Artifacts are linked to specific assessment responses to demonstrate compliance with a requirement. They are sourced from the Document Inventory.
- Assessment Parameter Compliance › Assessments
- A configuration block that defines how an assessment is scored and governed. Parameters include Scoring Methodology, Risk Appetite, Acceptable Compliance Score, and settings such as whether Evidence, Probable Risks, or Comments are required per response.
- Authority Document Governance / Compliance
- A compliance framework, standard, regulation, or policy standard managed in ClearGRC (e.g., ISO 27001, NIST CSF, PCI-DSS). Authority Documents contain Citations and Question Catalogs and are the basis for assessments and cross-references.
- Awaiting Approval Workflow
- A lifecycle stage that a record enters after all required Reviewers have completed their review. The record remains in this state until an Approver formally approves or rejects it.
B
- Business Objective Risk
- An organizational goal or target that can be linked to assets and risks in ClearGRC, providing context for why an asset is valuable or why a risk matters to the organization.
C
- CIA Level Admin › Security Taxonomy
- A classification based on Confidentiality, Integrity, and Availability — the three pillars of information security. CIA Levels are configured in the Security Taxonomy and applied to policies, controls, and assets.
- Citation Governance / Compliance
- A specific control, requirement, or clause extracted from an Authority Document. Citations are the line-item requirements that controls are mapped to and that assessments are evaluated against.
- Confidence Level Risk › Control
- A measure attached to a control indicating how reliably it is operating based on the most recent test results. A higher confidence level indicates the control is consistently effective.
- Control Identifier Risk › Control
- A unique reference code (also shown as Control Idn) assigned to each control record in ClearGRC, used to link controls to citations, risks, and assessment responses.
- Control Testing Risk › Control
- The process of verifying that a control is operating as intended. Test results are recorded in ClearGRC and contribute to the control’s Confidence Level and Effectiveness rating.
- Cross-Reference Compliance
- A ClearGRC feature that maps Citations across multiple Authority Documents, identifying overlapping requirements. This allows a single control or assessment response to satisfy requirements from multiple frameworks simultaneously.
- Custodian Risk › Asset / Risk Response
- A stakeholder role assigned to assets and risk responses. The Custodian is responsible for the day-to-day management and stewardship of the record, distinct from the Owner who holds ultimate accountability.
E
- Effective From Governance › Policy / Authority Document
- The date from which a policy, authority document, or citation becomes applicable. Records with a future Effective From date are not yet enforced.
- Evidence Compliance / Risk › Control
- Files or documentation that demonstrate compliance with a citation or control requirement. In assessments, Evidence is attached per response. In controls, it is captured as part of Control Testing.
- Exception Governance
- A formal record in ClearGRC documenting an approved deviation from a policy or control. Each exception includes a justification, a Valid From / Valid To date range, and goes through the standard review and approval workflow.
- Executive Summary Compliance › Assessments / Governance › Policy
- A high-level narrative field on assessments and policies that provides a concise overview of the record’s purpose, scope, and key findings or decisions.
F
- False Positive Risk › Vulnerability
- A flag on a vulnerability record indicating that the reported vulnerability is not a genuine weakness in the environment. Marking a vulnerability as a false positive excludes it from active risk calculations.
G
- Gap Assessment Compliance › Assessments
- An assessment type in ClearGRC that evaluates the difference between an organization’s current compliance state and the requirements of a target framework. Results highlight which citations are not yet satisfied.
I
- Identified By / Identified On Risk
- Fields on a Risk record capturing who first identified the risk (Identified By) and the date it was discovered (Identified On). Used for traceability and reporting.
- Inherent Risk Risk
- A Risk Classification in ClearGRC indicating that the risk represents the baseline exposure before any controls or mitigations are applied. Inherent risks can have linked Residual Risk records that capture post-control exposure.
L
- Location All modules
- An organizational scope field used to associate records — such as risks, policies, and assets — with a specific physical or logical location within the organization.
M
- Maintenance Frequency Risk › Control
- A setting on a control record that defines how often the control should be reviewed, tested, or updated to remain effective.
N
- Nessus Scanner Risk › Vulnerability
- A vulnerability scanning tool by Tenable. ClearGRC supports direct import of Nessus scan results into the Vulnerability module, automatically creating vulnerability records from the scan output.
- Next Review Date Governance › Policy
- The scheduled date by which a policy must next be reviewed. ClearGRC can send reminders as the date approaches based on configured Reminder Rules.
- NVD Inventory Risk › Vulnerability
- The National Vulnerability Database integration in ClearGRC. Allows users to search for CVEs by identifier and import them directly into the Vulnerability module with pre-populated CVSS scores and descriptions.
P
- Policy Acknowledgment Governance › Policy
- A formal confirmation recorded in ClearGRC indicating that a user has read and accepted the terms of an active policy. Used to track policy awareness across the organization.
- Policy Attestation Governance › Policy
- The process by which designated stakeholders verify and confirm that a policy has been reviewed, is accurate, and remains appropriate. Attestation is distinct from Acknowledgment — it is a reviewer action, not an end-user action.
- Probable Risk Compliance › Assessments
- A potential risk identified during an assessment response. When enabled in the Assessment Parameter, respondents can flag probable risks against specific citations, which are then available for promotion to the Risk Register.
- Procedure Evidence Governance › Process
- Documentation attached to a specific procedure step within a Process record to demonstrate that the procedure is followed in practice.
Q
- Question Catalog Governance / Compliance
- A curated set of assessment questions associated with an Authority Document. Question Catalogs define the specific questions presented to respondents when an assessment is run against that framework.
- Question Set Compliance › Assessments
- The collection of questions selected from a Question Catalog for use in a specific assessment instance. A Question Set defines what respondents will be asked during the assessment.
R
- Readiness Assessment Compliance › Assessments
- An assessment type that evaluates how prepared an organization is to meet a specific compliance standard before undergoing a formal external audit. Results indicate readiness gaps and areas requiring remediation.
- Reminder Rule Admin › Config
- A system configuration that automatically sends notifications to record owners and stakeholders as key dates approach — such as a policy’s Next Review Date or an exception’s expiry.
- Residual Risk Risk
- A Risk Classification in ClearGRC designating a risk that represents the remaining exposure after controls and mitigations have been applied. A Residual Risk must be linked to a parent Inherent Risk record.
- Response Option Compliance › Assessments
- A predefined answer choice presented to respondents for each question in an assessment. Each Response Option carries a Response Score that feeds into the overall compliance calculation.
- Response Score Compliance › Assessments
- The numeric value (0–100) assigned to a Response Option. When a respondent selects an option, its score is applied to the assessment’s overall compliance score calculation.
- Reviewer All modules
- A stakeholder role assigned to a record who must evaluate it before it can proceed to the Approver. Multiple Reviewers can be assigned; unanimity can be required via the Unanimity Review setting.
- Risk Classification Risk
- A designation on a Risk record indicating whether it is an Inherent Risk (pre-control baseline) or a Residual Risk (post-control exposure linked to an Inherent Risk parent).
- Risk Identifier Risk
- A unique reference code (also shown as Risk Idn) assigned to each risk record, used across modules to link and trace risks to responses, controls, and assessments.
- Risk Level Risk › Vulnerability
- A severity rating automatically computed from a vulnerability’s CVSS score. Risk Level is read-only and reflects the configured Risk Matrix thresholds (e.g., Critical, High, Medium, Low).
- Risk Matrix Admin › Risk Profile
- A configuration table that maps combinations of Likelihood and Impact ratings to Risk Level labels (e.g., Critical, High, Medium, Low). The Risk Matrix governs how scores translate to severity across the Risk module.
- Risk Profile Admin
- The organizational configuration in ClearGRC that defines the Risk Matrix, Risk Level thresholds, and Treatment Plan options. The Risk Profile is the foundation for how all risk records are scored and categorized.
- Risk Response Risk
- A formal action plan in ClearGRC documenting how a specific risk will be addressed. Risk Responses use one of four strategies: Mitigate, Accept, Avoid, or Transfer. Each response includes responsible parties, timelines, and links to controls or policies.
- Risk Type Risk
- A classification tag applied to a risk record to categorize it by nature (e.g., Operational, Strategic, Financial, Compliance). Multiple Risk Types can be assigned to a single risk.
- Roll Back Governance › Policy
- An action available on a policy that reverts the record to a previous approved version. Useful when a recently approved version contains errors and the prior version needs to be restored as the active one.
S
- Scoring Methodology Compliance › Assessment Parameter
- The algorithm used to calculate the overall compliance score for an assessment from the individual Response Scores of all answered questions. Configured as part of the Assessment Parameter.
- Security Objective Governance / Risk
- A CIA-based classification (Confidentiality, Integrity, or Availability) applied to policies, processes, and controls to indicate which information security principle the record supports.
- Security Taxonomy Admin
- The ClearGRC configuration module for defining CIA Levels and asset classification categories used across Governance and Risk records.
- Self Assessment Compliance › Assessments
- An assessment type in ClearGRC where internal team members evaluate their own compliance against a framework’s requirements, without external auditor involvement.
- Source Risk
- A field on a Risk record that identifies the origin of the risk. Options in ClearGRC include: Internal Audit, Manual Entry, TPRA, Residual Risk, and Others.
- Subscription Status Governance › Authority Document
- The active or inactive state of an Authority Document within ClearGRC. Only subscribed (active) Authority Documents are available for use in assessments and citation management.
T
- Tag All modules
- A key:value metadata label that can be attached to records across all ClearGRC modules for custom categorization, filtering, and reporting. Tags appear as colored badges on record detail pages.
- Third Party Assessment Compliance › Assessments
- An assessment type in ClearGRC used to evaluate third-party vendors or partners against compliance requirements. Results feed into the Third Party Inventory and inform TPRA risk records.
- TPRA (Third Party Risk Assessment) Risk / Compliance
- A formal evaluation of the risks introduced by engaging a third-party vendor or partner. In ClearGRC, TPRA is also a valid Risk Source, indicating the risk originated from a third-party assessment finding.
- Treatment Plan Admin › Risk Profile
- A preconfigured risk treatment approach defined in the Risk Profile. Treatment Plans provide standard remediation templates that can be applied when creating Risk Responses.
U
- Unanimity Review All modules
- A workflow setting on a record that requires every assigned Reviewer to complete their review before the record advances to the Awaiting Approval stage. When disabled, a single reviewer completing their review is sufficient.
- Under Review Workflow
- A workflow state indicating that a record has been submitted for review and is currently being evaluated by one or more assigned Reviewers.
- Upload Request Admin › Operations
- An administrative feature in ClearGRC for managing and tracking bulk file upload operations, such as importing vulnerability data or documents in bulk.
V
- Version Governance › Policy / Authority Document
- A numbered iteration of a policy or authority document. Each time a policy completes the review and approval cycle, a new version is created. Previous versions are retained and accessible via the review log. Policies can be rolled back to an earlier version if needed.
W
- Workflow State All modules
- The current lifecycle stage of a record in ClearGRC. The standard progression is: Draft → Under Review → Awaiting Approval → Active. Some modules also include Retired and Archived states for records that are no longer current.
