- Business System
- A defined combination of people, processes, technology, and data that performs a repeatable function within the organization β such as payroll processing, customer support, or inventory management.
- System Owner
- The designated individual or role accountable for maintaining, updating, and ensuring the correct use of a specific business system.
- Systems Register
- A formal inventory listing all operational systems within an organization, typically including ownership, classification, dependencies, and compliance status.
- Access Control
- The rules and mechanisms that determine who can view, edit, or administer a particular business system or its underlying data.
- Data Classification
- A framework that categorizes data by sensitivity level β such as public, internal, confidential, or restricted β to guide appropriate handling and protection.
- Integration Dependency
- A documented connection between two or more business systems where one system relies on data or functionality provided by another.
- Compliance Obligation
- A legal, regulatory, or contractual requirement that affects how a business system must be operated, secured, or documented.
- Review Cadence
- The scheduled frequency β monthly, quarterly, or annual β at which a system entry in the register is reviewed and updated for accuracy.
- Single Point of Failure
- A system or component with no redundancy whose failure would halt a critical business process β identified through systematic documentation so mitigation can be planned.
- Shadow IT
- Software, platforms, or tools used within an organization without formal IT or management approval β a risk that a comprehensive systems register helps identify and remediate.
- SOP (Standard Operating Procedure)
- A step-by-step written instruction that governs how a business system or process is executed consistently each time it is triggered.