Glossary
Compliance terms, defined.
Short, plain definitions of the terms used across this site. They are general information, not legal advice.
Data protection
- DPOData protection officer
The person an organisation names to oversee how it handles personal data: keeping its record of processing current, advising on its data protection duties, and acting as the contact point for regulators and for the people whose data it holds. Egypt’s PDPL provides for a DPO appointed to the entity and registered with the Personal Data Protection Center.
Hire a DPO- PDPLPersonal Data Protection Law (Egypt, Law 151 of 2020)
Egypt’s Personal Data Protection Law, Law No. 151 of 2020. It governs how personal data is collected, processed, stored and transferred, and it is enforced by the Personal Data Protection Center.
PDPL on Thiqa- PDPCPersonal Data Protection Center
Egypt’s data protection authority under the PDPL. It licenses organisations that process personal data, registers their data protection officers and investigates complaints.
Egyptian financial regulators
- CBECentral Bank of Egypt
Egypt’s central bank. It licenses and supervises the country’s banks and the payment service providers and fintech firms under its remit, and issues requirements for them, including on cyber security.
CBE on Thiqa- FRAFinancial Regulatory Authority (Egypt)
The regulator of Egypt’s non-banking financial sector, including insurance, capital markets, leasing and microfinance.
Payment card security
- PCI DSSPayment Card Industry Data Security Standard
The security requirements for any organisation that stores, processes or transmits payment card data. The PCI Security Standards Council maintains it; the card brands and acquiring banks enforce it.
PCI DSS on Thiqa- SAQSelf-Assessment Questionnaire
The PCI DSS validation an eligible merchant or service provider completes itself rather than through an assessor’s on-site review. There are several SAQ types, each matching a way of handling card data, and the acquirer confirms which one applies.
- ROCReport on Compliance
The formal report of a full PCI DSS assessment, usually written by a Qualified Security Assessor. The largest merchants and most service providers validate this way instead of with an SAQ.
- QSAQualified Security Assessor
An assessor qualified by the PCI Security Standards Council to evaluate an organisation’s compliance with PCI DSS.
Information security
- ISO 27001ISO/IEC 27001
The international standard for an information security management system. It sets out how to identify information security risks, choose controls to treat them and keep improving. An accredited certification body certifies an organisation against it after an external audit.
ISO 27001 on Thiqa- ISMSInformation security management system
The policies, processes, roles and controls an organisation uses to manage information security risk, run as a continuing cycle of planning, operating, reviewing and improving. ISO 27001 specifies what an ISMS must include.
- Annex A
The annex to ISO/IEC 27001 that lists reference information security controls. An organisation records which of them apply to it, and why, in its Statement of Applicability.
Compliance work
- Control
A measure that keeps a risk within an acceptable level: a policy, a process, a technical setting or a routine check such as a quarterly access review. One control can satisfy requirements in several frameworks at once.
Controls on Thiqa- Evidence
The record that shows a control operated as described: a configuration export, a log, a signed review, a closed ticket. Auditors and assessors test controls by examining it, and most evidence stops proving anything once it is out of date.
Evidence on Thiqa- Policy
A written statement, approved by management, of what an organisation requires and who is responsible for it. Procedures describe how a policy is carried out; controls and evidence show that it is.
Policies on Thiqa- Risk register
The list of an organisation’s identified risks, each recorded with an owner, an assessment of likelihood and impact, the treatment decided for it and the controls that carry that treatment out.
Risk on Thiqa- Inherent / residual risk
Inherent risk is the level of a risk before any controls are applied; residual risk is the level that remains once they are. Residual risk is what management has to decide to accept.
- GRCGovernance, risk and compliance
The combined practice of directing an organisation (governance), managing the risks it faces (risk) and meeting the laws, regulations and standards that apply to it (compliance). GRC software keeps the three in one system.
Thiqa’s features