Appendix B — Glossary
Plain definitions of the terms used throughout Aegis and this guide, in alphabetical order.
Where a term means something specific inside Aegis, that meaning is given. If you are new, the entries for control, evidence and framework are the ones to read first.
- Acknowledgment
- A record that a named person has read and accepted a policy. When a policy is published, administrators and managers can ask individuals or the whole workforce to acknowledge it. Each acknowledgment captures the person, the policy version they accepted, and the time, and can be exported as proof. Acknowledgments do not carry over to a new version — a fresh round is needed when a policy changes.
- Action Catalogue
- The exhaustive role-by-role reference of every action in Aegis, shipped as Appendix A of this guide. It is a document, not a screen in the application. Not to be confused with the Action Center (a menu entry) or action items (tracked tasks) — the three share a word and nothing else.
- Action Center
-
The first entry in the
Governancegroup of the left menu, at/action-center. A tabbed section whose Getting Started tab hosts the onboarding checklist that sets up your tenant (formerly the standalone Getting Started page, whose old address still redirects here). Distinct from action items, which are tracked follow-up tasks, and from the Action Catalogue, which is a reference document in this guide. - Action item
-
A follow-up task created from an AI action's result — for example "reassess
this critical vendor" kept as tracked work. Action items live on the
Action Itemstab of the Roadmap page (theAction Itemsmenu entry opens that tab), where each moves through Open, In progress and Done. Distinct from the Action Center menu entry and the Action Catalogue reference document. - Adequacy decision
- A formal European Commission decision that a country outside the EU protects personal data to an essentially equivalent standard. Transfers to such a country need no extra safeguards. Aegis tracks adequacy decisions as a transfer option and flags relevant ones when the Commission puts them under review.
- AI assistant
- The reasoning feature built into several Aegis modules. It can draft policy text, summarise risks, classify evidence, suggest remediation and help with data-protection assessments. Every suggestion is advisory and a person must review it before it is saved or acted on. AI features require the AI Assist feature flag and a licence tier of Essentials or above.
- Anomaly
- An unusual pattern in the audit log that Aegis has flagged as possibly significant — for example, someone downloading far more evidence than usual, or a connector failing repeatedly after weeks of stability. An anomaly is not automatically an incident; a person must triage each one and decide whether to escalate.
- Attestation
- An active confirmation that a piece of evidence is still accurate and current. Where an acknowledgment is about reading a policy, an attestation is about vouching that an evidence record still reflects reality — often used to refresh evidence before an audit without uploading a new file.
- Audit log
- The complete, append-only record of every action taken in Aegis. Every create, update, delete and workflow change is recorded with who did it, what they did, which record was affected, a readable summary and a before/after snapshot. It is available to administrators and cannot be edited or deleted — even by an administrator. It is the primary evidence trail for external auditors.
- Audit readiness
- Both a module and a score. The module gives a pre-audit checklist view of which controls have enough evidence, which policies are approved and which risks are treated, across all active frameworks. The score is the percentage of controls that have at least one current, linked piece of evidence. It is read-only — it reflects your work, it does not change it.
- CAPA (Corrective and Preventive Action)
-
The quality-management discipline of fixing what went wrong (corrective) and
stopping it happening elsewhere (preventive), required by ISO 9001 clause
10.2. In Aegis, mitigating actions on risks can be classified as corrective
or preventive, and the CAPA view in the
Riskmenu group collects them across all risks. Non-conformities feed this work: each one is driven through containment, root-cause analysis, corrective action and a check that the fix worked. - Connector
- An integration between Aegis and an external system. Connectors pull data in (such as vulnerability feeds, HR records or cloud findings) or push data out (such as Slack messages or webhooks). Each has a type, a configuration and a status. Connectors are a Manager-and-above area, and their credentials are encrypted at rest.
- Control
- A specific safeguard you put in place to manage a risk or meet a requirement — for example, requiring multi-factor authentication. In Aegis, controls come from the frameworks you activate. You set each control's implementation status and link policies, procedures, evidence and risks to it; the control text itself comes from the framework.
- CyFun
- The Belgian Cyber Fundamentals Framework, published by the Centre for Cybersecurity Belgium. It defines four assurance levels — Small, Basic, Important and Essential — and maps to ISO 27001 and NIS2. Aegis has a dedicated CyFun maturity view that tracks your scores and the gap to your target level.
- DORA
- The Digital Operational Resilience Act, an EU law that applies to financial entities and their ICT suppliers and came into full application in January 2025. It requires managing ICT risk, classifying and reporting incidents, testing resilience and governing third-party dependencies. Aegis tracks DORA compliance with sub-modules for ICT assets, third-party oversight, testing and incident reporting.
- DPA (Data Processing Agreement)
- A contract between a data controller and a data processor, required by GDPR Article 28. It sets out what is processed, why, for how long, and the obligations of each party. Aegis tracks a DPA per vendor, with signing and expiry dates and links to the vendor record and any related transfers.
- DPIA (Data Protection Impact Assessment)
- A structured assessment required by GDPR Article 35 when a processing activity is likely to be high-risk to individuals. It describes the processing, weighs necessity and proportionality, assesses the risks and identifies measures to address them. Aegis guides you through the standard structure and links each DPIA to its processing activities.
- DSR (Data Subject Request)
- A request from an individual exercising a GDPR right — access, rectification, erasure, restriction, portability, objection, or rights around automated decisions. Aegis manages these in a dedicated queue with deadline tracking (one calendar month, extendable to three in complex cases), fulfilment workflows and audit logging.
- ESG (Environmental, Social and Governance)
- The umbrella term for reporting on an organisation's environmental footprint, social impact and governance practices, increasingly demanded by regulation and by customers. In Aegis, the Environmental Metrics page records per-site environmental KPIs — water, energy, waste, emissions, turnover — per measurement period, building the trend data behind your ESG reporting.
- EU AI Act prohibited systems
- Artificial-intelligence uses that the EU AI Act bans outright as "unacceptable risk" — for example, social scoring by public authorities, certain biometric categorisation, and AI that manipulates people through subliminal techniques. Aegis offers a prohibited-practices checklist to map your AI inventory against these categories.
- Evidence
- Any artefact that proves a control is implemented and working — a certificate, screenshot, report, log extract or audit letter. In Aegis, evidence lives in the evidence library, linked to the controls it supports, with an optional expiry date. Each item has a freshness status of Current, ExpiringSoon or Expired. Evidence is the bridge between what you say you do and what an auditor can verify.
- Feature flag
- A switch that turns a capability on or off based on your licence tier. Examples include AI Assist, board reports and anomaly detection. Feature flags are driven purely by the licence tier — distinct from module gates (set by your operator) and role gates (set by your role). You can see your active flags under Settings → Licence.
- Framework
- A published set of requirements you measure yourself against, such as ISO 27001, NIS2, CyFun, DORA, GDPR, the EU AI Act, ISO 27701 or ISO 42001. Each framework contains a set of controls. You activate the frameworks relevant to you, and Aegis tracks your progress over time. Several can be active at once, and controls can be matched across them.
- KPI widget
- A data card on the dashboard showing a single key figure — your compliance score, open risks, overdue policies, evidence expiring soon, open incidents or audit readiness. You can choose which widgets appear and where, from the dashboard's edit mode.
- Licence tier
- Your subscription level, which determines the features and modules available. Aegis has four tiers — Essentials, Starter, Professional and Enterprise — each including everything below it plus more. Your current tier and what it includes are shown under Settings → Licence.
- Mock audit
- A simulated audit run inside Aegis to practise for a real one. You pick a framework and scope, and an assessor works through the controls, marking each and recording findings. Mock audits run in their own space and do not affect your live compliance score.
- Module
- An on/off switch for a major area of Aegis (such as Risks, Policies or GDPR), set by your operator at the tenant level. A disabled module is hidden from the sidebar entirely. This is different from a feature flag (licence-driven) and a role gate (user-driven). If a module you expect is missing, ask your platform operator.
- NIS2 essential versus important
- NIS2 divides regulated organisations into two categories. Essential entities — in sectors such as energy, transport, banking, health and digital infrastructure — face stricter supervision and heavier penalties. Important entities — in sectors such as postal services, waste, manufacturing and food — face lighter-touch supervision. You classify yourself during onboarding, and Aegis surfaces the matching obligations.
- Non-conformity
-
A failure to meet a requirement you are committed to — a control not
followed, a process that produced the wrong outcome, an audit finding. Aegis
logs quality non-conformities on the Non-Conformities page in the
Governancegroup and drives each through containment, root-cause analysis, corrective action and effectiveness verification, the cycle ISO 9001 clause 10.2 requires. See also CAPA. - Onboarding wizard
- The short setup flow that runs the first time a new tenant signs in. It collects your company name and industry, your NIS2 sector, your organisation size and your primary framework. It cannot be skipped — the rest of the application needs the resulting organisation profile before it will load.
- Permission
-
A granular check that decides whether a specific action is allowed.
Permissions follow a
RESOURCE_ACTIONpattern, such asPOLICY_CREATE. Roles are bundles of permissions. When an action is blocked, Aegis names the missing permission. - Policy
- A written organisational rule defining how you behave in a given area — the primary governance documents in Aegis. Policies follow a four-stage lifecycle: Draft, InReview, Approved and Retired. Once approved, all signed-in users can read a policy. Policies are versioned, can be mapped to controls, linked to evidence, translated, and sent for acknowledgment.
- Procedure
- A step-by-step instruction for how to carry out a task, usually supporting a policy. Where a policy says "the organisation must perform regular backups", a procedure says how and when. Procedures follow the same Draft, InReview, Approved, Retired lifecycle as policies and can be mapped to controls.
- Residual risk
- The level of risk that remains after controls and treatment have been applied. Aegis derives it from the gap between a risk's initial score and the treatment effectiveness the owner records — it is shown in the risk detail view and used in reporting to show whether the remaining exposure is acceptable.
- Risk register
- The full catalogue of identified risks in your tenant. Each risk has a title, description, category, owner, an impact score (1–5), a likelihood score (1–5), a status and a treatment plan. The overall score (impact × likelihood) is computed on the fly. A heatmap visualises how risks are distributed.
- Risk treatment
- The decision about what to do with a risk. Aegis supports four options: mitigate (add controls to reduce it), accept (tolerate it within appetite), transfer (shift it to a third party, such as via insurance), or avoid (stop the activity that creates it). The choice and resulting action plan are recorded on the risk, and they drive its status.
- Role
- A named bundle of permissions assigned to each person. Aegis has exactly four — Viewer, Contributor, Manager and Admin — forming a strict hierarchy where each higher role includes all the powers below it. Roles cannot be customised below the Enterprise tier.
- ROPA (Record of Processing Activities)
- The documented inventory of your personal-data processing, required by GDPR Article 30. Each entry describes who processes the data, why, the legal basis, the categories of people and data, any recipients and transfers, and retention periods. Aegis manages these as processing activities, linkable to DPIAs, vendors and evidence.
- SBOM (Software Bill of Materials)
- A structured list of the software components and dependencies that make up an application — like an ingredient list for software. SBOMs are expected under frameworks such as the EU Cyber Resilience Act. Aegis ingests SBOMs in CycloneDX or SPDX format, tracks the components and flags those with known vulnerabilities.
- SCC (Standard Contractual Clauses)
- Model contract clauses approved by the European Commission that provide safeguards for transferring personal data from the EU to countries without an adequacy decision. Aegis tracks SCCs as a transfer option and can prompt you for the associated Transfer Impact Assessment documents.
- Special-category data (GDPR Article 9)
- Personal data the GDPR treats as especially sensitive: health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic and biometric data, and data about a person's sex life or orientation. Processing it is prohibited unless a specific Article 9 condition applies — explicit consent being the most common — and it demands extra safeguards. Aegis marks these categories in processing records and warns when one is selected.
- Tenant
- Your organisation's own deployment of Aegis. Aegis is single-tenant — one isolated instance per customer, with no infrastructure shared between customers. All your users, policies, risks, vendors and evidence belong to your tenant and are kept apart from every other.
- Vendor criticality
- A four-level rating of how important a vendor is to your operations: Low, Medium, High or Critical. It is set when you create or edit a vendor and drives risk weighting — a Critical vendor with issues raises higher-priority alerts than a Low one with the same issues.
- Workflow
- An automation rule Aegis runs in response to events. Each workflow has a trigger (such as a policy moving to review, or evidence about to expire) and one or more actions (such as sending an email or posting a message). Workflows can be Draft, Active, Paused or Archived; active ones fire when their trigger condition is met, and their runs are recorded.
- Workspace
- Used interchangeably with tenant in the interface. When you see "workspace" in the header, settings or notifications, it means your organisation's Aegis instance. The workspace name is the company name set during onboarding and appears on exported reports and board packs.
Where this connects
For the roles named throughout these definitions, see What each role can do. To start from the beginning, see What Aegis is.