CloudCompliance

Cloud compliance glossary

The terms that come up when a cloud estate meets an audit, defined in a sentence or two each, with a link to the page that covers each one properly.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Cloud compliance borrows vocabulary from three places: the cloud providers, the audit standards and Canadian privacy law. These are the terms you will meet in a first project.

Cloud terms

Account, subscription, project
The main isolation boundary on AWS, Azure and Google Cloud respectively. See account structure.
Landing zone
A pre-built multi-account structure with identity, logging and guardrails every new account inherits. See the AWS and Azure guides.
Service control policy (SCP)
An AWS Organizations policy that limits what any principal in an account can do, including administrators.
Management group
An Azure container for subscriptions where policy and access are applied once and inherited.
Organization policy constraint
A Google Cloud rule applied at organization, folder or project that blocks non-compliant configuration.
CMEK or customer-managed key
An encryption key in the provider's key service whose policy and lifecycle you control. See key management.
CSPM
Cloud security posture management: tools that check configuration against a baseline. See CSPM tools.
Workload identity federation
Letting a pipeline or external workload obtain short-lived cloud credentials from a trusted token, instead of storing keys.

Audit terms

Shared responsibility model
The split between what the provider secures and what you do. See shared responsibility.
Subservice organization
A provider whose controls your SOC 2 relies on, such as your cloud provider.
Carve-out method
The usual way a SOC 2 treats a cloud provider: its controls are excluded from your report and covered by its own.
Complementary user entity controls (CUECs)
Controls a provider's SOC 2 report assumes its customers perform.
Observation window
The period a SOC 2 Type 2 covers, usually three to twelve months.
Evidence
The record an auditor samples to test a control. See evidence collection.
Exception
A tested instance where a control did not operate as described.
Statement of Applicability
The ISO 27001 document listing each Annex A control, whether it applies and how it is implemented.

Canadian terms

Data residency
Where data is stored, processed and accessed from. See data residency.
PIPEDA
The federal private sector privacy law. Does not require Canadian storage.
Law 25
Quebec's privacy law, which requires an assessment before personal information leaves Quebec. See Law 25 transfers.
Bill C-36
Federal privacy reform bill introduced on 15 June 2026, at second reading, proposing the Protecting Privacy and Consumer Data Act.
PHIPA
Ontario's health information law. See health data in the cloud.
What is the difference between a landing zone and an account structure?

An account structure is the layout of accounts or subscriptions. A landing zone is that layout plus the identity, logging, networking and guardrails that come with every account automatically.

Need someone fluent in all three vocabularies?

Firms in the network speak cloud, audit and Canadian privacy.

Get matched