Skip to main content
reopt Handbook
reopt Handbook
AI Security and Compliance Operations

Strategy and Governance

Risk GovernanceData ProtectionSecure Architecture

Security Controls

Prompt Injection DefenseAccess Control and SecretsAudit Readiness

Operations and Leadership

Incident ResponseBoard Reporting

Appendix

GlossaryVerificationUpdates
Handbook›AI Security and Compliance›Glossary
한국어English

Glossary

Shared terminology for AI security and compliance operations.

Key takeaways

  • This glossary gives engineering and security teams shared definitions for policy, incident reports, audit responses, and board materials.
  • Core inventory terms include the AI system register, control catalog, and evidence map that ties controls to stored proof.
  • Risk vocabulary covers residual risk (what remains after controls) versus risk appetite (what leadership will accept).
  • Operational terms span prompt injection, tool calling, human-in-the-loop approval, data minimization, and break-glass access.

Terms

TermMeaning
AI system registerInventory of AI features, models, tools, vendors, owners, and risk class
Control catalogList of security controls mapped to risks and evidence
Evidence mapWhere proof of each control is stored and how often it is refreshed
Prompt injectionAttack that uses text input or retrieved content to alter model behavior
Residual riskRisk remaining after controls are applied
Risk appetiteAmount and type of risk leadership is willing to accept
Tool callingModel-driven invocation of external functions, APIs, or actions
Human-in-the-loopHuman approval or review before risky action is completed
Data minimizationReducing data exposure to what the task actually needs
Break-glass accessEmergency privileged access with strict logging and review

Usage

Use this glossary when writing policy, incident reports, audit responses, and board materials so engineering and security teams use the same language.

Related docs

Verification

A checklist for validating AI security and compliance operations.

Risk Governance

Create an AI risk governance loop with ownership, scoring, approval, and review.

Agent Documentation Security

Agentic Documentation · Reduce prompt injection, MCP tool poisoning, Plugin supply chain risk, and excessive agency.

References

Vercel Enterprise AI Platform · Source categories for adapting the Vercel enterprise AI platform handbook.

Board Reporting

Translate AI security and compliance posture into executive decisions.

Verification

A checklist for validating AI security and compliance operations.

On this page

TermsUsage