Rozwinięcie skrótów przydatne w lekturze tej sekcji:
AEMP – AXP Management Policy
AXP – American Express Company
API – Application Programming Interface
BBB – Better Business Bureau
BFL – Business Function Location
BIA – Business Impact Analysis
BST – Business Self-Testing
CBF – Critical Business Function
CEG – Colleague Experience Group (HR)
COE – Center of Expertise (Excellence)
COERA – Center of Expertise (Excellence) Risk Assessment Report
CSOC – Complementary Subservice Organization Controls
CUEC – Complementary User Entity Control
DD – Due Diligence
DPIA – Data Protection Impact Assessment
EDA – Enterprise Digital Analytics
EPCC – Enterprise Privacy Choice Capability
FCPA – Foreign Corrupt Practices Act
FSRA – Financial Statement Risk Assessment
GCO – General Counsel Organization
GMS – Global Merchant Service
GNICS – Global Network and International Card Services
GNO – Global Network Operations
GNP – Global Network Partnership
GSM – Global Supply Management
ICFR – Internal Control over Financial Reporting
IPCR – Information Protection Contract Requirement
IRA – Inherent Risk Assessment
ITGC – Information Technology General Controls
LOBCO – Line of Business Compliance Officers
MCO – Market Compliance Officers
MFN – Most Favored Nation
OE – Operational Excellence
OOS – Out of Scope
PAR – Privacy Access Request
PII – Personally Identifiable Info
PRA – Privacy Risk Assessment
PRE-L – Pre-engagement Logical Assessment
PRE-P – Pre-engagement Physical Assessment or Pre-Physical Review
RAQ – Risk Assessment Questionnaire
RTO – Recovery Time Objectives
SAR – Subject Access Request
SDE – Sensitive Data Elements
SLA – Service Level Agreement
SME – Risk Subject Matter Experts
SO – Service Organization
SOE – State-owned or State-controlled Entity
SOX – Sarbanes Oxley Act (if a Third-Party initiates financial transactions on behalf of AXP or impacts AXP’s financial statements)
SSO – Subservice Organization
SRF – Service Request Form
SS&BE – Strategic Sourcing and Business Enablement
TPP – Third-Party Processor
TPRM – Third-Party Risk Management
TRA – Third-Party Risk Assessment
TSM – Third-party Security Management
VRO – Vendor Risk Oversight
VTA – Vulnerability Threat Assessment