Glossary
Document management glossary
Vendors and standards use the same words to mean different things, which makes requirements documents ambiguous. Each entry here gives a short definition first, then what the term means when you have to configure or audit it, and which standard defines it where one does.
Jump to a letter
62 件の用語を収録. Terms are auto-linked on first mention across the guides and blog, so you rarely need to come here directly.
#
- 21 CFR Part 11
- 21 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
A
- Access review
- An access review is a periodic check that the people who have access to something still need it.
- API key
- An API key authenticates a program rather than a person.
- Approval workflow
- An approval workflow is a configured path a document must clear before it can be relied on, defining the steps, the approvers and the order.
- Audit trail
- An audit trail is an append-only record of every action taken on a document — views, downloads, edits, approvals, permission changes and deletions — with the acting user, timestamp and affected version.
B
- Break-glass access
- Break-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Business associate agreement
- A business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
C
- Chain of custody
- Chain of custody is the documented, unbroken record of who has held, accessed or altered an item of evidence, and when.
- Check-in / check-out
- Check-out locks a document for editing by one person and shows others who holds it; check-in releases the lock and creates a new version.
- Common data environment
- A common data environment is the agreed single source of information for a project, through which all information is collected, managed and shared.
- Contract lifecycle management
- Contract lifecycle management covers the whole life of an agreement: request, drafting, negotiation, approval, signature, storage, obligation tracking and renewal.
D
- Data processing addendum
- A data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- Data residency
- Data residency is the commitment that data is stored and processed within a specified country or region.
- Disposition
- Disposition is what happens to a record when its retention period expires: destruction, transfer to an archive, or a decision to extend.
- Document capture
- Document capture is the process of getting documents into a system and making them usable: scanning or importing, recognising text, classifying, extracting fields and applying metadata.
- Document control
- Document control is the discipline of ensuring only approved documents are in use, superseded ones cannot be mistaken for current, and every change is authorised and recorded.
- Document generation
- Document generation produces a finished document by merging structured data into an approved template.
- Document management system
- A document management system is software that captures, stores, versions, secures and retrieves an organisation's documents from one repository.
- Document migration
- Document migration is the movement of documents, their metadata and their version history from one system to another.
- Document numbering
- Document numbering assigns each document a unique identifier, generated by the system according to rules configured per document type.
- Document type
- A document type classifies what a document is — a contract, a policy, an invoice, a batch record.
- Duplicate detection
- Duplicate detection identifies documents whose content is already present in the repository, normally by comparing a cryptographic hash of the file.
E
- e-Form
- An e-form captures structured data through defined fields with validation, rather than collecting it as text inside a document.
- eIDAS
- eIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- Electronic signature
- An electronic signature is data attached to or logically associated with a document that indicates the signer's approval of it.
- Email-to-folder import
- Email-to-folder import monitors a mailbox and files incoming messages and their attachments into a specified folder automatically.
- Encryption at rest
- Encryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Enterprise content management
- Enterprise content management is the broader discipline covering documents, records, web content, capture, archiving and business process automation across an organisation.
- Escalation
- Escalation is the automatic reassignment or notification that occurs when a workflow step is not actioned within a defined period.
- ESIGN Act
- The ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
F
- Full-text search
- Full-text search queries the words inside documents rather than only their names and metadata.
G
- GDPR
- The General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
- Golden thread
- The golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.
H
- HIPAA
- HIPAA is the US framework governing protected health information.
I
- Information governance
- Information governance is the framework of accountability, policies and controls determining how an organisation creates, uses, retains and disposes of its information.
- Intelligent document processing
- Intelligent document processing combines optical character recognition with machine learning to classify a document, extract named fields from it and route it onward.
- ISO/IEC 27001
- ISO/IEC 27001 is the international standard for information security management systems.
L
- Legal hold
- A legal hold suspends the routine destruction of records that may be relevant to litigation, an investigation or an audit.
M
- Metadata
- Metadata is structured information about a document rather than inside it: its type, owner, date, status, retention class and any fields specific to its kind.
O
- Optical character recognition
- Optical character recognition converts an image of text into machine-readable characters.
P
- Permission inheritance
- Permission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
- Policy acknowledgement
- Policy acknowledgement is a recorded attestation that a named individual has read a specific version of a specific policy, at a given time.
R
- Records management
- Records management governs how long a document is kept and what happens at the end of that period.
- Recycle bin
- A recycle bin holds deleted documents so they can be restored.
- Redaction
- Redaction is the permanent removal of information from a copy of a document before it is disclosed, leaving the original intact.
- Retention schedule
- A retention schedule sets out, for each class of record, how long it is kept, what event starts the clock and what happens when the period expires.
- Right to erasure
- The right to erasure allows an individual to require deletion of their personal data in defined circumstances.
- Role-based access control
- Role-based access control grants permissions to roles rather than to individuals, and assigns people to roles.
S
- SEC Rule 17a-4
- SEC Rule 17a-4 governs how broker-dealers preserve their records.
- Semantic search
- Semantic search matches meaning rather than exact strings, using vector representations of text.
- Single sign-on
- Single sign-on lets users authenticate to an application using an identity provider they already use.
- SOC 2
- SOC 2 is an attestation report in which an independent accounting firm describes and tests a service organisation's controls against the AICPA trust services criteria.
- Spoliation
- Spoliation is the destruction, alteration or failure to preserve evidence that is relevant to litigation.
- Statement of applicability
- A statement of applicability lists every Annex A control in ISO/IEC 27001, states whether each one is applicable, and justifies the decision either way.
- Sub-processor
- A sub-processor is a third party a processor engages to help process personal data on a controller's behalf.
- Subject access request
- A subject access request is an individual's request for a copy of the personal data an organisation holds about them, together with information about how it is used.
T
- Taxonomy
- A taxonomy is the structure by which documents are organised and found — folders, categories, document types and the metadata that describes them.
- Two-factor authentication
- Two-factor authentication requires a second proof of identity beyond a password, typically a time-based code or a hardware key.
V
- Version control
- Version control keeps every revision of a document as part of one record rather than as separate files, marks which version is currently in force, and retains superseded versions as evidence.
W
- Watermarking
- Watermarking applies a visible marker to a document preview or download — draft status, confidentiality level, or recipient identity.
- Webhook
- A webhook is an HTTP request a system sends to a URL you nominate when an event occurs, so your application is told rather than having to ask.
- WORM storage
- WORM storage is a medium that permits data to be written once and read many times, but never altered or erased before its retention period expires.