Rozwinięcie skrótów przydatne w lekturze tej sekcji:

 

AEMP – AXP Management Policy

AXP – American Express Company

API – Application Programming Interface

BBB – Better Business Bureau

BFL – Business Function Location

BIA – Business Impact Analysis

BST – Business Self-Testing

CBF – Critical Business Function

CEG – Colleague Experience Group (HR)

COE – Center of Expertise (Excellence)

COERA – Center of Expertise (Excellence) Risk Assessment Report

CSOC – Complementary Subservice Organization Controls

CUEC – Complementary User Entity Control

DD – Due Diligence

DPIA – Data Protection Impact Assessment

EDA – Enterprise Digital Analytics

EPCC – Enterprise Privacy Choice Capability

FCPA – Foreign Corrupt Practices Act

FSRA – Financial Statement Risk Assessment

GCO – General Counsel Organization

GMS – Global Merchant Service

GNICS – Global Network and International Card Services

GNO – Global Network Operations

GNP – Global Network Partnership

GSM – Global Supply Management

ICFR – Internal Control over Financial Reporting

IPCR – Information Protection Contract Requirement

IRA – Inherent Risk Assessment

ITGC – Information Technology General Controls

LOBCO – Line of Business Compliance Officers

MCO – Market Compliance Officers

MFN – Most Favored Nation

OE – Operational Excellence

OOS – Out of Scope

PAR – Privacy Access Request

PII – Personally Identifiable Info

PRA – Privacy Risk Assessment

PRE-L – Pre-engagement Logical Assessment

PRE-P – Pre-engagement Physical Assessment or Pre-Physical Review

RAQ – Risk Assessment Questionnaire

RTO – Recovery Time Objectives

SAR – Subject Access Request

SDE – Sensitive Data Elements

SLA – Service Level Agreement

SME – Risk Subject Matter Experts

SO – Service Organization

SOE – State-owned or State-controlled Entity

SOX – Sarbanes Oxley Act (if a Third-Party initiates financial transactions on behalf of AXP or impacts AXP’s financial statements)

SSO – Subservice Organization

SRF – Service Request Form

SS&BE – Strategic Sourcing and Business Enablement

TPP – Third-Party Processor

TPRM – Third-Party Risk Management

TRA – Third-Party Risk Assessment

TSM – Third-party Security Management

VRO – Vendor Risk Oversight

VTA – Vulnerability Threat Assessment