• MSP Provider: An enterprise that provides services to other enterprises in a managed or as a service form.
  • K2 GRC Platform: The software, operating system, and database that hosts applications, services, workspaces, API's, etc. By default, hosted in Amazon Commercial Cloud.
  • User Seat License: A license that determines a user's level of access to K2 GRC's subscription services. The type of seat a user is assigned depends on the services they have access to.
  • User: Any individual with any amount of access to the K2 GRC Platform.
  • Services: Purpose-built solutions or use-cases which provide extra functionality inside the K2 GRC Platform. Each Service can be accessed on the Platform or Workspace level.
  • Content: Templated records produced by K2 GRC or a K2 GRC Partner (if specified) for the Customer to use.
  • Subject: An entity that has been enrolled in the corresponding Service, regardless of whether they utilize the Service or not.
  • Set-Up, User Training: Remote support that enables users access to the K2 Platform and Services procured, provides guidance on setup, and operations of the K2 Platform and Service to those initially assigned users by someone with Platform and Services expertise.
  • Service - Governance: A Service that is used to track and monitor a Customer's Governance posture.
  • Service - Risk: A Service that is used to track and monitor a Customer's Risk posture.
  • Service - Compliance: A Service that is used to track and monitor a Customer's Compliance posture.
  • Service - Third-Party Risk Management: A Service that is used to track and monitor a Customer's Third-Party posture.
  • Service - K2 Akademy: A learning management system (“LMS”) via Modules. The Modules selected by Customer will be accessible via a website URL.
  • Service - K2 Cyber: A comprehensive cybersecurity platform offered on a per user per month basis. Initially, it includes realistic phishing simulations, phishing activities, and dark web monitoring. Future offerings, rolled out sequentially and included automatically, will encompass cybersecurity policy templates, and software tutorial trainings. A user is defined as anyone who could receive training or phishing simulations, regardless of whether those features are utilized.
  • Service - K2 Exclude: A Service that monitors a Subject against a host of sources required by many different compliance standards. Includes searches of the following datasets (OIG-LEIE, SAM.gov, Federal, State Medicaid, and State Medical Board Action Search).
  • Content - SCORM Module: A finalized piece of material that is provided via the standardized SCORM format.
  • Content - K2 Akademy Basic Module(s): Are described [here](https://etactics.com/k2akademy/modules). Modules are broken down into "Basic Modules" and "Premium Modules." Additionally, Customer agrees that Company may update these at will.
  • Content - HIPAA Security Rule Modules: Includes Annual HIPAA Privacy Rule Training, Annual Password Management Training, Annual Malware Prevention Training, Annual Ransomware Prevention Training, Annual Cyber Security Awareness Training, and Annual HIPAA Security Rule Training.
  • Content - USP-800 Rule Modules: Includes Annual Fraud, Waste, and Abuse Training, Annual Cultural Competency Training, Annual USP-800 Training, Annual HIPAA Security Rule Training, and Annual HIPAA Privacy Rule Training.
  • Content - CEU Library Access: Provides access to a list containing information on certain free CEU available to the public by other organizations.
  • Content - Frameworks: Templated records produced by K2 GRC or a K2 GRC Partner (if specified) that provides intellectual property for the Customer to use. Frameworks are regulations or standards published from some Governing body.
  • Content - Task List - HIPAA Security Rule: Includes a distinct task list designed to get your company compliant with the HIPAA Security Rule via tasks using the K2 GRC software.
  • Content - Task List - K2 GRC USP-800 Rule: Includes a distinct task list designed to get your company compliant with the USP-800 Rule via tasks using the K2 GRC software.
  • Content - Task List - K2 GRC CMMC Level 2: Includes a distinct task list designed to get your company compliant with CMMC Level 2 via tasks using the K2 GRC software.
  • Content - Task List - K2 GRC CMMC Level 1: Includes a distinct task list designed to get your company compliant with CMMC Level 1 via tasks using the K2 GRC software.
  • Content - Policy Set - K2 GRC HIPAA Security Rule: Includes a distinct policy list designed to get your company compliant with HIPAA Security Rule policy requirements using the K2 GRC software.
  • Content - K2 Akademy One Time Enrollment Fee per Trainee for SafeHouse: Enrollment of a Trainee to access a selected SafeHouse Module(s) and be trained one time. Customer understands and acknowledges that in order to receive a CEU for the completed training, Company must share certain information with third parties for accreditation purposes. Customer agrees that Company has the right to share certain information, including but not limited to, the number of Trainees enrolled in the Offerings, the number of Trainees who have completed the training, and the name and contact information of those Trainees who have enrolled in and completed the training to the aforementioned third parties so that accreditation may be confirmed. In light of the foregoing, Customer agrees to supply Company with the number of Trainees enrolled in the Offerings upon the time of enrollment, the number of Trainees who have completed the training, and the names and contact information of the Trainees who have enrolled in the training.