Archives Glossary Terms

SSL

Secure Socket Layer A secure Internet connection which established an encrypted link between the user and web server to protect data in transit and verify the source.

AD

Active Directory A Microsoft network technology allowing central management of users, security policy and network services.

SOP

Standard Operating Procedure A documented guide for carrying out routine operations.

SAQ

SAQ Self Assessment Questionnaire A PCI requirement for an organisation to complete a questionnaire and make a attestation of compliance.  Usually for lower volumes of card transactions.

RoC

Report on Compliance A report produced following an assessment of compliance to PCI requirements for merchants who process a certain volume of card holder information. More on PCI.

PII

Personal Identifiable Information Information which may identify an individual person.  Often used in the scope of the Data Protection Act.

ROI

Return on Investment The benefits and rewards achieved after an investment has been made, justifying the initial outlay. Such as an increase of profit as a direct result of investing in ISO certification.

RAMS

Risk Assessment Method Statements RAMS combine risk assessment with safe systems of work or method statements that contractors must provide before working on many sites. Method Statements detail how an activity will be carried out and should include consideration of…

ISMS

Information Security Management System A structured system for managing the protection of information. Often following ISO 27001. may or may not be certified.

IS

Information System Software or other system for collecting, storing and processing information.