SOCOPSFoundation
A friendly reference

Glossary

Attested state

What an organization's documentation, controls, and most recent audit assert to be true.

Live state

The actual current configuration and behavior of systems.

Drift

The gap between attested state and live state.

Vulnerability drift

Findings aging beyond their dispositioned timeframe without closure or re-acceptance.

Policy-template drift

Divergence between written policy, the template, and actual practice.

Evidence

A verifiable record that a control operated as intended.

Release-readiness evidence

The risk-proportionate record that a release was reviewed, approved, deployed, monitored, and evidenced.

Freshness

How recently evidence reflects the current state.

Continuous compliance

Operating controls and producing evidence as a daily state, not a periodic project.

Shadow AI

AI tools, agents, or APIs in use without formal inventory or review.

Control objective

What a control is meant to achieve, independent of any framework.

Obligation inventory

An owned record of applicable laws, frameworks, and contractual obligations, mapped to the controls that implement them.

Environment boundary

The controlled line between production and non-production environments.

Disposition

The recorded decision for a finding: remediate, mitigate, or formally risk-accept.

Compliance-in-cadence

Sustaining readiness through the rhythm an org already runs, not a compliance season.

v1.0 · validation draftRead it, then tell us where it falls apart.
Get involvedSupport the standard