Thiqa

Glossary

Compliance terms, defined.

Short, plain definitions of the terms used across this site. They are general information, not legal advice.

Data protection

DPOData protection officer

The person an organisation names to oversee how it handles personal data: keeping its record of processing current, advising on its data protection duties, and acting as the contact point for regulators and for the people whose data it holds. Egypt’s PDPL provides for a DPO appointed to the entity and registered with the Personal Data Protection Center.

Hire a DPO
PDPLPersonal Data Protection Law (Egypt, Law 151 of 2020)

Egypt’s Personal Data Protection Law, Law No. 151 of 2020. It governs how personal data is collected, processed, stored and transferred, and it is enforced by the Personal Data Protection Center.

PDPL on Thiqa
PDPCPersonal Data Protection Center

Egypt’s data protection authority under the PDPL. It licenses organisations that process personal data, registers their data protection officers and investigates complaints.

Egyptian financial regulators

CBECentral Bank of Egypt

Egypt’s central bank. It licenses and supervises the country’s banks and the payment service providers and fintech firms under its remit, and issues requirements for them, including on cyber security.

CBE on Thiqa
FRAFinancial Regulatory Authority (Egypt)

The regulator of Egypt’s non-banking financial sector, including insurance, capital markets, leasing and microfinance.

Payment card security

PCI DSSPayment Card Industry Data Security Standard

The security requirements for any organisation that stores, processes or transmits payment card data. The PCI Security Standards Council maintains it; the card brands and acquiring banks enforce it.

PCI DSS on Thiqa
SAQSelf-Assessment Questionnaire

The PCI DSS validation an eligible merchant or service provider completes itself rather than through an assessor’s on-site review. There are several SAQ types, each matching a way of handling card data, and the acquirer confirms which one applies.

ROCReport on Compliance

The formal report of a full PCI DSS assessment, usually written by a Qualified Security Assessor. The largest merchants and most service providers validate this way instead of with an SAQ.

QSAQualified Security Assessor

An assessor qualified by the PCI Security Standards Council to evaluate an organisation’s compliance with PCI DSS.

Information security

ISO 27001ISO/IEC 27001

The international standard for an information security management system. It sets out how to identify information security risks, choose controls to treat them and keep improving. An accredited certification body certifies an organisation against it after an external audit.

ISO 27001 on Thiqa
ISMSInformation security management system

The policies, processes, roles and controls an organisation uses to manage information security risk, run as a continuing cycle of planning, operating, reviewing and improving. ISO 27001 specifies what an ISMS must include.

Annex A

The annex to ISO/IEC 27001 that lists reference information security controls. An organisation records which of them apply to it, and why, in its Statement of Applicability.

Compliance work

Control

A measure that keeps a risk within an acceptable level: a policy, a process, a technical setting or a routine check such as a quarterly access review. One control can satisfy requirements in several frameworks at once.

Controls on Thiqa
Evidence

The record that shows a control operated as described: a configuration export, a log, a signed review, a closed ticket. Auditors and assessors test controls by examining it, and most evidence stops proving anything once it is out of date.

Evidence on Thiqa
Policy

A written statement, approved by management, of what an organisation requires and who is responsible for it. Procedures describe how a policy is carried out; controls and evidence show that it is.

Policies on Thiqa
Risk register

The list of an organisation’s identified risks, each recorded with an owner, an assessment of likelihood and impact, the treatment decided for it and the controls that carry that treatment out.

Risk on Thiqa
Inherent / residual risk

Inherent risk is the level of a risk before any controls are applied; residual risk is the level that remains once they are. Residual risk is what management has to decide to accept.

GRCGovernance, risk and compliance

The combined practice of directing an organisation (governance), managing the risks it faces (risk) and meeting the laws, regulations and standards that apply to it (compliance). GRC software keeps the three in one system.

Thiqa’s features