Body
Purpose
This glossary defines common terminology used throughout the Enterprise Architecture Framework, Architecture Controls, Policies, Standards, Architecture Decision Records (ADRs), Patterns, Products, and implementation documentation.
Where a term is governed by a University policy, the applicable policy number is identified in the Policy Dependency field. Definitions linked to policies should be reviewed whenever the referenced policy changes.
A
Access Control
Definition: The processes, mechanisms, and technologies used to grant, restrict, review, modify, and revoke access to systems, services, applications, and data.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
Application Identity
Definition: A non-human identity used by an application to authenticate and access services, resources, APIs, or data.
Policy Dependency: None
Architecture Decision Record (ADR)
Definition: A document that records a significant architecture decision, the rationale for that decision, and the consequences of adopting it.
Policy Dependency: None
Architecture Pattern
Definition: An approved implementation approach used to consistently satisfy architecture requirements and standards.
Policy Dependency: None
Audit Log
Definition: A record of activities, events, actions, changes, or access that supports operational review, investigations, compliance, and accountability.
Policy Dependency: 285.1 Cybersecurity
Authentication
Definition: The process of verifying the identity of a user, service, application, or system.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
Authorization
Definition: The process of determining what actions an authenticated identity is permitted to perform.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
D
Data Classification
Definition: The process of identifying and categorizing data according to its sensitivity, regulatory requirements, contractual obligations, institutional requirements, and business value.
Policy Dependency: 921.0 Data Classification
Data Classification Level
Definition: A designation assigned to data that identifies the level of protection, handling requirements, access restrictions, and governance controls that must be applied throughout the data lifecycle.
Policy Dependency: 921.0 Data Classification
Data Disposal
Definition: The approved process for permanently removing or destroying data that is no longer required.
Policy Dependency: 924.0 Data Disposal
Data Protection
Definition: The safeguards and controls used to maintain the confidentiality, integrity, availability, recoverability, and accountability of data throughout its lifecycle.
Policy Dependency: 922.0 Data Management, Use and Protection
E
Encryption at Rest
Definition: Protection of stored data through approved encryption mechanisms while data resides on storage media.
Policy Dependency: 922.0 Data Management, Use and Protection
Encryption in Transit
Definition: Protection of data through approved encrypted communication methods while data is transmitted between systems, services, applications, or networks.
Policy Dependency: 922.0 Data Management, Use and Protection
Enterprise Identity Service
Definition: An approved centralized identity platform used as the authoritative source for authentication and authorization.
Policy Dependency: None
Enterprise Workload
Definition: A workload operating under the enterprise control baseline and approved to process Public, Sensitive/Internal, Highly Sensitive, and authorized Restricted data classifications.
Policy Dependency: None
G
Governance
Definition: The processes, controls, oversight mechanisms, standards, and decision authorities used to manage technology environments consistently and accountably.
Policy Dependency: 285.1 Cybersecurity
Governance Boundary
Definition: A designated scope within which governance controls, policies, standards, monitoring requirements, and compliance obligations are applied and enforced.
Policy Dependency: None
Governance Inheritance
Definition: The application of governance controls through hierarchical assignment such that subordinate resources inherit required governance, security, compliance, and operational controls.
Policy Dependency: None
H
HIPAA Workload
Definition: A regulated workload that creates, stores, processes, transmits, or provides access to Protected Health Information (PHI).
Policy Dependency: None
I
Identity Governance
Definition: The processes used to provision, modify, review, and remove access throughout the identity lifecycle.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
Incident Investigation
Definition: Activities performed to understand, analyze, document, and respond to operational or security events.
Policy Dependency: 911.0 Data Security Incident Response
Innovation Workload
Definition: A workload supporting experimentation, research, evalutation, proofs of concept, or emerging technologies. Innovation workloads may process Public and Sensitive/Internal data, but shall not process Highly Sensitive or Restricted data.
Policy Dependency: None
L
Least Privilege
Definition: The principle that users, services, and systems receive only the permissions necessary to perform approved business functions.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
Logging
Definition: The collection and retention of records relating to system activity, security events, operational actions, and administrative actions.
Policy Dependency: 285.1 Cybersecurity
M
Monitoring
Definition: The collection, analysis, and use of operational, security, audit, and platform telemetry to support visibility, operations, investigations, and compliance activities.
Policy Dependency: 285.1 Cybersecurity
O
Operational Continuity
Definition: The capability of a workload to continue or resume operations during and after disruptions, failures, or recovery activities.
Policy Dependency: 925.0 Backup and Recovery Systems
P
Protected Health Information (PHI)
Definition: Individually identifiable health information protected under the Health Insurance Portability and Accountability Act (HIPAA) and associated regulations.
Policy Dependency: None
Privileged Access
Definition: Administrative or elevated access that permits management, configuration, or control of systems, services, applications, or data.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
R
Recovery
Definition: The restoration of systems, applications, services, or data following a failure, disruption, corruption event, or disaster.
Policy Dependency: 925.0 Backup and Recovery Systems
Regulated Data
Definition: Data subject to legal, regulatory, contractual, research, licensing, grant or institutional requirements governing its use, disclosure, transmission, storage, retention, protection, or disposal.
Policy Dependency: 922.0 Data Management, Use and Protection
Regulated Workload
Definition:
A workload requiring enhanced governance, security, monitoring, auditability, recovery, or compliance controls due to regulatory, contractual, legal, or institutional requirements.
Policy Dependency: None
Role-Based Access Control (RBAC)
Definition: An authorization model that assigns access permissions through defined roles rather than direct assignment to individuals.
Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems
S
Service Identity
Definition: A non-human identity used by applications, automation, integrations, and platform services for authentication and resource access.
Policy Dependency: None
Shared Service
Definition: A centrally managed platform capability that can support multiple workloads while maintaining workload isolation and governance requirements.
Policy Dependency: None
W
Workload
Definition: A collection of applications, services, databases, integrations, infrastructure components, and supporting capabilities that together deliver a business or technical function.
Policy Dependency: None
Workload Isolation
Definition: The deployment of workloads into dedicated cloud governance, administrative, operational, and security boundaries appropriate for business, regulatory, and operational requirements.
Policy Dependency: None