Appendix H: Definitions
AICPA · 2017
This appendix is nonauthoritative and is included for informational purposes only.For purposes of this guide, certain key terms are defined as follows:access to personal information.The ability of the data subject to view personal information held by an entity.This ability may be complemented by an ability to update or correct the information.Access defines the intersection of identity and data, that is, who can do what to which data.Access is one of the fair information practice principles.Individuals must be able to find out what personal information an entity has on file about them and how the information is being used.Individuals need to be able to correct erroneous information in such records.architecture.The design of the structure of a system, including logical components, and the logical interrelationships of a computer, its operating system, a network, or other elements.authentication.The process of verifying the identity or other attributes claimed by or assumed of an entity (user, process, or device) or the process of verifying the source and integrity of data.authorization.The process of granting access privileges to a user, program, or process by a person that has the authority to grant such access.board, board of directors, or directors.Individuals with responsibility for overseeing the strategic direction of the entity and the obligations related to the accountability of the entity.Depending on the nature of the entity, such responsibilities may be held by a board of directors or supervisory board for a corporation, a board of trustees for a not-for-profit entity, a board of governors or commissioners for a government entity, general partners for a partnership, or an owner for a small business.business partner.An individual or business (and its employees), other than a vendor, who has some degree of involvement with the entity's business dealings or agrees to cooperate, to any degree, with the entity (for example, a computer manufacturer who works with another company who supplies them with parts). collection.The process of obtaining personal information from the individual directly (for example, through the individual's submission of an Internet form or a registration form) or from another party such as a business partner.commitments.Declarations made by management to customers regarding performance of the entity or its goods or services.Commitments can be communicated in written individualized agreements, standardized contracts, service-level agreements, or published statements (for example, a security practices statement).A commitment may relate to one or more trust services categories.Commitments may be made on many different aspects of the service being provided, including the following:r Specification of the algorithm used in a calculation ©2017, AICPA AAG-CYB APP HGuide: Reporting on an Entity's Cybersecurity Risk Management Program and Controls, 2nd Edition.AICPA.