PLAIN-LANGUAGE GLOSSARY

The terms behind
managed IT.

Use this reference while reviewing proposals, service descriptions, security plans, and contracts.

Backup

A protected copy of data or a system that can be used to restore information after deletion, corruption, failure, or an incident.

Business associate agreement

An agreement defining responsibilities in a relationship subject to HIPAA business associate requirements. Applicability depends on the actual service and data; consult the responsible adviser.

Business continuity

The plans and capabilities that keep critical business processes operating during a disruption, not merely the restoration of technology.

Co-managed IT

A model in which internal IT and an external provider divide clearly defined operational responsibilities.

Conditional access

Access policies that evaluate signals such as identity, device, and context before allowing access. The exact features depend on the platform and configuration.

DNS

Domain Name System: the records that direct domain names to services such as websites and email. Keep ownership and administrator access documented.

EDR

Endpoint detection and response: software and operations used to detect, investigate, and contain suspicious activity on devices.

Help desk

The intake, communication, troubleshooting, and escalation function for employee technology questions and incidents.

Immutable backup

A backup copy designed so it cannot be altered or deleted during a defined retention period.

Incident response

The coordinated technical and business process for investigating, containing, communicating, and recovering from a security incident.

Least privilege

Granting only the permissions needed for an approved task or role, with review and removal when the need ends.

MDM

Mobile device management: administration of supported device settings, applications, and policies through a management service.

MDR

Managed detection and response: an operated security service that monitors, investigates, and responds to threats.

MFA

Multifactor authentication: verifying identity with more than one type of factor, such as something you know and something you possess.

MSP

Managed service provider: a company that operates defined technology services under an ongoing agreement.

NOC

Network operations center: a team or function that monitors and supports infrastructure and availability.

Privileged access

Permissions that can make significant administrative changes. Document who holds them, what they cover, and how use and removal are controlled.

RMM

Remote monitoring and management: tools used to observe and administer systems remotely. Tool access requires clear authorization and oversight.

RPO

Recovery point objective: the acceptable data-loss window measured in time for a system or process.

RTO

Recovery time objective: the target time for restoring a system or process after disruption.

Runbook

A documented operational procedure describing prerequisites, steps, owners, and validation for a recurring task or recovery activity.

Service desk

A broader support function that manages requests, incidents, communication, knowledge, and service processes.

SLA

Service-level agreement: documented service commitments such as coverage, priority, response, escalation, and reporting.

SOC

Security operations center: the people, process, and technology used to monitor, investigate, and respond to security events.

SSO

Single sign-on: using an identity service to access connected applications. Application scope and access removal still need verification.

Tenant

An organization’s logical environment within a cloud service. Record its identifier, business owner, and administrator access.

Ticket

The system record used to track a request, incident, communication, ownership, timing, and resolution.

vCIO

Virtual chief information officer: an external role intended to connect technology planning, risk, budget, and business priorities.

Zero trust

A security approach that continuously verifies access based on identity, device, context, and least privilege rather than assuming internal traffic is trusted.

Zero-day

A newly discovered vulnerability for which defenders may have little warning or no broadly available patch.

PUT TERMS IN CONTEXT

Service language should connect to an operating process.

Ask who owns the work, what triggers action, how performance is reported, and where the commitment appears in the agreement.

Explore the service library →
REVIEW THE CONTRACT

Translate the proposal into clear ownership.

Scope, service levels, security roles, pricing, access, and transition obligations should be explicit before signing.

Read the contract guide →