Join our Newsletter — 33% off our NHI Course

Business Dictionary

A governed collection of business terms used to define shared operational language. It captures the organization’s own meaning for concepts such as customers, invoices, or delivery dates, then links those terms to data assets and processes. This reduces ambiguity and supports consistent governance across teams and systems.

Expanded Definition

A business dictionary is more than a glossary of approved labels. It is a governed reference that defines how an organisation uses core business concepts, what each term means in context, and how those meanings map to data elements, processes, and control decisions. Unlike a data catalog, which focuses on technical metadata, or a glossary entry that may be purely descriptive, a business dictionary establishes the authoritative business meaning that teams should apply consistently across reporting, workflows, and governance reviews.

In mature governance programmes, the business dictionary becomes a shared control point for data quality, privacy classification, and operational consistency. It helps resolve disputes such as whether a “customer” includes prospects, inactive accounts, or only paying entities. When aligned with control expectations from NIST SP 800-53 Rev 5 Security and Privacy Controls, it can also support traceability by tying business meaning to handling rules, retention logic, and access decisions. Definitions vary across vendors and governance programmes, so the real value lies in documented ownership and approved usage rather than the label itself.

The most common misapplication is treating the business dictionary as a static terminology list, which occurs when teams publish definitions without linking them to actual systems, data owners, or decision processes.

Examples and Use Cases

Implementing a business dictionary rigorously often introduces governance overhead, requiring organisations to weigh consistency and auditability against the time needed to review and approve changes.

  • A finance team defines “invoice date” as the date the invoice is issued, while operations initially use the date it is received. The business dictionary removes that ambiguity and sets the approved meaning for reporting.
  • A customer data programme distinguishes “customer”, “prospect”, and “active subscriber” so that analytics, CRM workflows, and privacy notices all use the same business logic.
  • A supply chain group maps “delivery date” to the committed date in the order management system, then links that term to the underlying field used in dashboards and service-level reporting.
  • A security and compliance team uses the dictionary to classify “personal data” consistently and connect it to handling rules, retention, and controls informed by NIST SP 800-53 Rev 5 Security and Privacy Controls.
  • An enterprise data office uses the dictionary to reconcile conflicting terminology across business units before data is exposed in self-service analytics or shared with partners.

Why It Matters for Security Teams

Security teams depend on shared business meaning to make access, classification, and monitoring decisions that are defensible. If a business dictionary is incomplete or outdated, controls can be applied to the wrong data, retention schedules can be misaligned, and incident response can start with false assumptions about system ownership or record sensitivity. That risk becomes more pronounced in environments with automation, where workflows, AI agents, and integrations may act on business terms without human interpretation.

A governed dictionary also strengthens identity and entitlement governance when business concepts determine who should access what. For example, if “supplier” or “employee” is defined inconsistently, role design and approval workflows can drift away from actual business need. When paired with the control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls, the dictionary helps translate policy into operational rules that teams can apply consistently. Organisations typically encounter the cost of weak definitions only after a reporting dispute, audit finding, or misrouted access request, at which point the business dictionary becomes operationally unavoidable to fix.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 Shared terminology supports governance oversight and consistent security decision-making.
NIST SP 800-53 Rev 5 PM-23 Defines and governs an enterprise-wide data management capability that includes business terminology.
ISO/IEC 27001:2022 A.5.12 Information classification depends on agreed business definitions and consistent use of terms.
NIST SP 800-63 Identity governance relies on clear business definitions for subjects, roles, and account types.
OWASP Non-Human Identity Top 10 NHI programmes need shared definitions for service identities, secrets, and ownership boundaries.

Maintain authoritative business terms so governance, reporting, and risk decisions use the same meanings.