Cloud compliance glossary
The terms that come up when a cloud estate meets an audit, defined in a sentence or two each, with a link to the page that covers each one properly.
Cloud compliance borrows vocabulary from three places: the cloud providers, the audit standards and Canadian privacy law. These are the terms you will meet in a first project.
Cloud terms
- Account, subscription, project
- The main isolation boundary on AWS, Azure and Google Cloud respectively. See account structure.
- Landing zone
- A pre-built multi-account structure with identity, logging and guardrails every new account inherits. See the AWS and Azure guides.
- Service control policy (SCP)
- An AWS Organizations policy that limits what any principal in an account can do, including administrators.
- Management group
- An Azure container for subscriptions where policy and access are applied once and inherited.
- Organization policy constraint
- A Google Cloud rule applied at organization, folder or project that blocks non-compliant configuration.
- CMEK or customer-managed key
- An encryption key in the provider's key service whose policy and lifecycle you control. See key management.
- CSPM
- Cloud security posture management: tools that check configuration against a baseline. See CSPM tools.
- Workload identity federation
- Letting a pipeline or external workload obtain short-lived cloud credentials from a trusted token, instead of storing keys.
Audit terms
- Shared responsibility model
- The split between what the provider secures and what you do. See shared responsibility.
- Subservice organization
- A provider whose controls your SOC 2 relies on, such as your cloud provider.
- Carve-out method
- The usual way a SOC 2 treats a cloud provider: its controls are excluded from your report and covered by its own.
- Complementary user entity controls (CUECs)
- Controls a provider's SOC 2 report assumes its customers perform.
- Observation window
- The period a SOC 2 Type 2 covers, usually three to twelve months.
- Evidence
- The record an auditor samples to test a control. See evidence collection.
- Exception
- A tested instance where a control did not operate as described.
- Statement of Applicability
- The ISO 27001 document listing each Annex A control, whether it applies and how it is implemented.
Canadian terms
- Data residency
- Where data is stored, processed and accessed from. See data residency.
- PIPEDA
- The federal private sector privacy law. Does not require Canadian storage.
- Law 25
- Quebec's privacy law, which requires an assessment before personal information leaves Quebec. See Law 25 transfers.
- Bill C-36
- Federal privacy reform bill introduced on 15 June 2026, at second reading, proposing the Protecting Privacy and Consumer Data Act.
- PHIPA
- Ontario's health information law. See health data in the cloud.
What is the difference between a landing zone and an account structure?
An account structure is the layout of accounts or subscriptions. A landing zone is that layout plus the identity, logging, networking and guardrails that come with every account automatically.
Need someone fluent in all three vocabularies?
Firms in the network speak cloud, audit and Canadian privacy.
Get matched