Open glossary
The CIO glossary, in plain language.
Precise, sourced definitions you can paste into a board paper. Free for everyone and updated as the field changes.
24 terms
A
- Agentic AI
AI Agentic AI refers to AI systems that pursue a goal by planning and taking multi-step actions, such as calling tools, querying systems or triggering workflows, with limited human intervention. For CIOs the governance question shifts from “is the output accurate?” to “what is the agent allowed to do, and who approves it?”
- AI governance
AI AI governance is the set of decision rights, policies, controls and oversight an organization uses to make sure AI systems are valuable, safe, lawful and accountable across their life cycle. In practice it starts with an inventory of AI use cases and a risk-tiering rule. See the AI Governance Playbook.
C
- Chatham House Rule
Community The Chatham House Rule lets participants use the information they receive in a meeting but not reveal the identity or affiliation of the speaker or any other participant. It originated at Chatham House (the Royal Institute of International Affairs) in London in 1927. Every CIO Cafe table runs under it.
- Chief information officer (CIO)
Roles A chief information officer (CIO) is the executive accountable for an organization’s information technology strategy, systems, operations and, increasingly, the business value of data and AI. The scope varies. Some CIOs also own digital products, data or security, while others share those with a CTO, CDO or CISO.
- CIO vs CTO
Roles The CIO typically owns internal technology: enterprise systems, infrastructure, operations and IT’s contribution to business performance. The CTO typically owns the technology in the products a company sells. In smaller or digital-native organizations one person may hold both roles.
- Clean core
Modernization Clean core is an ERP strategy, popularized by SAP, of keeping the core system as close to standard as possible. Customizations move into extensions on a separate platform, connected through stable, supported interfaces. The goal is faster, cheaper upgrades and less technical debt.
- Cloud repatriation
Cloud Cloud repatriation is moving workloads from public cloud back to on-premises or private infrastructure, usually for cost predictability, performance, data-sovereignty or regulatory reasons. It is typically selective, covering specific steady-state workloads rather than a wholesale exit.
- Cyber resilience
Security Cyber resilience is an organization’s ability to anticipate, withstand, recover from and adapt to cyber incidents while continuing to deliver critical services. Prevention asks “how do we stop it?” Resilience assumes it will happen and asks “how fast can we recover, and can we prove it?”
D
- DORA (EU Digital Operational Resilience Act)
Regulation The Digital Operational Resilience Act (DORA) is an EU regulation that has applied since 17 January 2025. It sets ICT risk-management, incident-reporting, resilience-testing and third-party-risk requirements for financial entities and their critical ICT providers.
E
- EU AI Act
Regulation The EU AI Act is the European Union’s risk-based law on artificial intelligence, in force since 1 August 2024. It sorts AI systems into prohibited, high-risk, limited-risk (transparency) and minimal-risk categories, and its obligations phase in over several years. Check current application dates with counsel, because amendments to the timetable have been proposed.
F
- FinOps
Cloud FinOps is an operating practice that brings engineering, finance and business teams together to manage variable cloud spending. It makes cost visible, allocates it to owners and optimizes it against business value. The FinOps Foundation describes its phases as Inform, Optimize and Operate.
I
- ISO/IEC 42001
AI ISO/IEC 42001:2023 is the international standard for an AI management system. It specifies how an organization establishes, operates and continually improves the policies, roles, risk processes and controls that govern its AI. Organizations can be certified against it.
M
- Model risk management
AI Model risk management is the discipline of identifying, validating, monitoring and controlling the risk that a model, whether statistical, machine-learning or generative, produces wrong or misused outputs that cause harm. It began in banking and is now applied to AI generally.
N
- NIST AI RMF
AI The NIST AI Risk Management Framework (AI RMF 1.0), published by the US National Institute of Standards and Technology in January 2023, is a voluntary framework organized around four functions: Govern, Map, Measure and Manage. NIST added a Generative AI Profile (NIST AI 600-1) in July 2024.
- NIST CSF 2.0
Security The NIST Cybersecurity Framework 2.0, released in February 2024, organizes cybersecurity outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. The new Govern function puts cyber-risk strategy and oversight explicitly at the executive level.
P
- Platform engineering
Operating model Platform engineering is the practice of building internal platforms, such as self-service infrastructure, paved paths, tooling and guardrails, that product teams use to ship software safely without rebuilding the same foundations each time.
- Product operating model
Operating model A product operating model organizes technology work around long-lived teams that own a product or capability and are funded persistently against outcomes. The alternative is temporary projects funded against scope. For IT it usually changes funding, roles and metrics before it changes the org chart.
R
- Retrieval-augmented generation (RAG)
AI Retrieval-augmented generation (RAG) is a pattern in which a language model first retrieves relevant passages from a trusted source, such as a document store or search index, and then generates an answer grounded in them. It reduces hallucination and makes answers traceable to sources.
- RTO and RPO
Security Recovery time objective (RTO) is the maximum acceptable time to restore a service after disruption. Recovery point objective (RPO) is the maximum acceptable amount of data loss, measured in time. Both should be proven by exercises, not just stated in policy.
S
- SBOM (software bill of materials)
Security A software bill of materials (SBOM) is a machine-readable inventory of the components and dependencies inside a piece of software. It lets organizations quickly find where a newly disclosed vulnerability affects them. Common formats are SPDX and CycloneDX.
- Shadow AI
AI Shadow AI is the use of AI tools, such as public chatbots, browser extensions or embedded assistants, by employees without the organization’s approval or oversight. The main risks are data leakage, compliance exposure and unmanaged decisions. Blocking alone rarely works. Offering sanctioned alternatives usually does.
T
- Technical debt
Modernization Technical debt is the future cost created by choosing an expedient technical solution today. It shows up as slower change, higher run costs and higher risk. CIOs make it fundable by expressing it in business terms: time-to-change, outage exposure and cost to maintain.
- Third-party concentration risk
Security Third-party concentration risk is the exposure created when many critical services depend on the same external provider, such as a single cloud region, SaaS platform or managed-service firm. One failure there disrupts many functions at once.
Z
- Zero trust
Security Zero trust is a security model that grants no implicit trust based on network location. Every access request is authenticated, authorized and continuously evaluated. NIST SP 800-207 (2020) defines the reference architecture.
Missing a term? Suggest one. Definitions last reviewed .