Glossary
A glossary so security, IT and leadership mean the same thing.
Around 150 terms from information security, business continuity, data protection and AI governance, each with the standard it comes from and what it means in daily work.
153 of 153 terms
Foundations
Acceptable Use Policy
A policy that defines how employees may use an organization's systems, devices, and data, and what behavior is prohibited.
Accreditation
Formal recognition that a certification body is competent to carry out audits and issue certificates against a given standard.
Audit Evidence
Records, statements, and other verifiable information that an auditor uses to determine whether requirements are met.
Certification Body
An independent organization, accredited for the purpose, that audits a management system and issues a certificate when it conforms to a standard.
Context of the Organization
The internal and external issues, and the needs of interested parties, that shape what a management system must achieve.
Continual Improvement
The ongoing effort to raise the effectiveness of a management system over time, a core requirement of every ISO standard.
Corrective Action
Action taken to eliminate the root cause of a nonconformity so that it does not happen again.
Documented Information
The records and documents an ISO management system requires to be created, controlled, and maintained as evidence.
GRC (Governance, Risk, and Compliance)
An integrated approach that aligns governance, risk management, and regulatory compliance so an organization can pursue objectives while staying within its risk appetite and the law.
Information Security Objectives
Measurable targets an organization sets to improve information security, consistent with its security policy.
Inherent Risk
The level of risk before any control is applied. Compared against residual risk, it shows how much a set of controls actually removes.
Interested Parties
The stakeholders whose needs and expectations a management system must consider, such as customers, regulators, employees, and suppliers.
Internal Audit
A planned, independent review that checks whether a management system conforms to its own requirements and to the relevant standard, and whether it is effective.
KPI (Key Performance Indicator)
A metric that shows how well a process or control is performing against its goal.
KRI (Key Risk Indicator)
A metric used to monitor whether an identified risk is changing or approaching the organization's risk-tolerance threshold.
Lead Auditor
The qualified auditor who plans and directs an audit, leads the audit team, and is responsible for its conclusions.
Management Review
A regular review by top management of whether the management system remains suitable, adequate, and effective, with decisions on changes and resources.
Management System
A structured set of policies, processes, and controls an organization uses to direct and improve a specific discipline, such as information security or business continuity.
Nonconformity
A failure to meet a requirement, whether from the standard, a policy, or a legal obligation, identified through audits or operations.
PDCA Cycle
Plan, Do, Check, Act: the iterative four-step model behind continual improvement in every ISO management system.
Recertification Audit
A full audit at the end of a certificate's cycle, usually every three years, to renew certification for another period.
Residual Risk
The risk that remains after controls have been applied to treat it, and that the risk owner has to accept, transfer or treat further.
Risk Appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
Risk Assessment
The process of identifying risks, then analyzing and evaluating them by their likelihood and impact to decide which need treatment.
Risk Matrix
A grid that plots risks by likelihood and impact to help rank and compare them.
Risk Owner
The person accountable for a specific risk and the decisions about how it is treated.
Risk Register
The central record of identified risks, their assessment, owners, and treatment status.
Risk Treatment
The step where an organization decides how to handle each assessed risk: reduce it, accept it, avoid the activity, or share it.
Scope
The boundaries of a management system: the parts of the organization, locations, assets, and activities it covers.
Security Policy
A high-level document approved by top management that states an organization's intentions and direction for protecting information.
Stage 1 Audit
The first part of an initial certification audit, a readiness review that checks whether the management system is documented and ready for the main audit.
Stage 2 Audit
The main certification audit, where an auditor gathers evidence that the management system is implemented and operating effectively.
Surveillance Audit
A periodic audit during a certificate's validity period that confirms the management system continues to operate and improve.
Top Management
The person or group that directs and controls an organization at the highest level, accountable for the management system under ISO standards.
Information security
Access Control
The selective restriction of who can view or use resources, enforced through identification, authentication, and authorization.
Annex A Controls
The catalogue of information security controls in ISO/IEC 27001, grouped into organizational, people, physical, and technological themes.
Asset
Anything of value to an organization that needs protection, such as data, systems, people, or facilities.
Attack Surface
The sum of all points where an attacker could try to enter or extract data from a system or organization.
Availability
The property that information and systems are accessible and usable when authorized users need them.
Backup
A protected, recoverable copy of data or system state used to restore information and services after loss, corruption, failure, or attack.
BSI C5
The BSI's Cloud Computing Compliance Criteria Catalogue, a German standard for assessing the security of cloud service providers.
BSI IT-Grundschutz
BSI IT-Grundschutz explained: the BSI's methodology and module catalogue, the 200-series standards and the route to ISO 27001 certification on that basis.
CIA Triad
The three core goals of information security: confidentiality, integrity, and availability.
Confidentiality
The property that information is accessible only to those authorized to have it.
Control
A measure that reduces risk, by modifying a threat, a vulnerability, or the impact of an incident.
CVE (Common Vulnerabilities and Exposures)
A public, standardized identifier assigned to a specific known security vulnerability.
CVSS (Common Vulnerability Scoring System)
An open framework that rates the severity of a vulnerability on a scale from 0 to 10.
Cyber Resilience Act (CRA)
An EU regulation that sets cybersecurity requirements for products with digital elements across their entire lifecycle.
Data Classification
The practice of labelling information by sensitivity so that the right level of protection is applied to each category.
Defense in Depth
A strategy of layering multiple, independent security controls so that if one fails, others still protect the asset.
DLP (Data Loss Prevention)
Technology and rules that detect and block sensitive data from leaving an organization through email, uploads, or removable media.
DORA (Digital Operational Resilience Act)
An EU regulation that sets uniform requirements for the digital operational resilience of the financial sector, including ICT risk management and third-party oversight.
EDR (Endpoint Detection and Response)
Software on laptops, servers, and devices that continuously monitors for malicious activity and helps responders investigate and contain it.
Encryption
The process of converting information into a coded form so that only authorized parties holding the key can read it.
Firewall
A network security control that filters traffic between networks based on defined rules, allowing legitimate connections and blocking unwanted ones.
Identity and Access Management (IAM)
The framework of policies and technology that manages digital identities and controls their access to resources.
Impact
The magnitude of harm if a risk scenario occurs, assessed against defined operational, financial, legal, safety, and reputational criteria.
Incident Response
The organized approach to detecting, containing, eradicating, and recovering from security incidents, and learning from them.
Integrity
The property that information remains accurate, complete, and unaltered except by authorized means.
ISMS (Information Security Management System)
The management system that governs how an organization identifies, treats, and monitors information security risks, defined primarily by ISO/IEC 27001.
ISO/IEC 27001
The international standard that specifies the requirements for an information security management system (ISMS) and is the most widely recognized security certification.
ISO/IEC 27002
The companion guidance to ISO/IEC 27001 that explains how to implement each information security control in detail.
ISO/IEC 27017
A guidance standard that adds cloud-specific information security controls on top of ISO/IEC 27002.
IT-Grundschutz Modeling
The assignment of suitable IT-Grundschutz Compendium modules to the target objects identified during structural analysis.
KRITIS (Critical Infrastructure)
The German term for critical infrastructure: sectors whose failure would seriously threaten public supply and safety.
Least Privilege
The principle of granting each user or process only the access rights it needs to do its job, and no more.
Likelihood
The chance that a given risk scenario will actually occur, used together with impact to rate a risk.
Logging and Monitoring
The recording of system and security events and their ongoing review to detect anomalies and support investigations.
Malware
Malicious software designed to damage, disrupt, or gain unauthorized access to systems and data.
Multi-Factor Authentication (MFA)
An authentication method that requires two or more independent factors to verify a user's identity.
NIS2 Directive
The EU directive that expands cybersecurity obligations for essential and important entities, including risk management measures and incident reporting.
NIST Cybersecurity Framework (CSF)
A voluntary US framework that organizes cybersecurity activities into a set of high-level functions to help organizations manage risk.
Patch Management
The process of acquiring, testing, and applying software updates to fix vulnerabilities and keep systems current.
PCI DSS
The Payment Card Industry Data Security Standard, a mandatory standard for organizations that store, process, or transmit cardholder data.
Penetration Test
An authorized, simulated attack on systems or applications to find and demonstrate exploitable security weaknesses.
Phishing
A social engineering attack that tricks people into revealing credentials or sensitive data, usually through deceptive messages.
Protection Needs Assessment (Schutzbedarfsfeststellung)
The IT-Grundschutz step that determines how strongly an information domain and its target objects need confidentiality, integrity and availability to be protected.
Ransomware
Malicious software that encrypts or blocks access to data and demands payment to restore it.
Security Awareness Training
Education that helps staff recognize and respond correctly to security risks such as phishing and social engineering.
Security Incident
An event, or series of events, that compromises or threatens the confidentiality, integrity, or availability of information.
Security Operations Center (SOC)
A team and facility that continuously monitors, detects, and responds to security threats across an organization.
Segregation of Duties
The control of splitting a sensitive task across more than one person so that no single individual can complete it alone.
SIEM (Security Information and Event Management)
A system that collects and correlates log and event data across an organization to detect and investigate security incidents.
SOC 2
A US attestation report on a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy.
Social Engineering
Manipulating people into revealing information or taking actions that compromise security, rather than attacking technology directly.
Statement of Applicability (SoA)
The document that lists every ISO/IEC 27001 Annex A control, states whether it applies, and justifies each inclusion or exclusion.
Supply Chain Attack
An attack that compromises an organization indirectly by targeting a trusted supplier, vendor, or software component it relies on.
Third-Party Risk Management
The process of assessing and controlling the security and continuity risks that suppliers and service providers introduce.
Threat
A potential cause of an unwanted incident that could harm an asset, such as malware, human error, or a natural event.
Threat Modeling
A structured exercise to identify potential threats to a system early, so they can be designed out or mitigated.
TISAX
An assessment and exchange mechanism for information security in the automotive industry, based on the VDA ISA catalogue.
Vulnerability
A weakness in an asset or control that a threat can exploit to cause harm.
Vulnerability Disclosure
A defined process for receiving, assessing, and acting on reports of security weaknesses from researchers or the public.
Vulnerability Scan
An automated check of systems against a database of known weaknesses to identify missing patches and misconfigurations.
Zero Trust
A security model that trusts no user or device by default and verifies every access request, regardless of network location.
Business continuity
BCMS (Business Continuity Management System)
The management system that prepares an organization to keep critical operations running during disruptions and to recover quickly, defined by ISO 22301.
Business Continuity Plan (BCP)
The documented procedures that guide an organization in responding to a disruption and continuing or recovering critical activities.
Business Impact Analysis (BIA)
The analysis that identifies an organization's critical activities and the effect over time of their disruption, setting the basis for recovery priorities.
Crisis Management
The capability to lead, decide, and communicate during a major disruptive event that exceeds normal response.
Disaster Recovery
The technology-focused part of continuity that restores IT systems, data, and infrastructure after a disruptive event.
ISO 22301
The international standard for a business continuity management system (BCMS), specifying how to prepare for, respond to, and recover from disruptions.
Maximum Tolerable Period of Disruption (MTPD)
The longest time an activity can be unavailable before the resulting harm to the organization becomes unacceptable.
Recovery Point Objective (RPO)
The maximum amount of data, measured as time, that an organization can afford to lose in a disruption.
Recovery Test (Wiederanlauftest)
The test that measures whether a process is workable again within its RTO after an outage, and how much data is actually lost on the way there.
Recovery Time Objective (RTO)
The target time within which a disrupted activity or system must be restored after an incident.
Tabletop Exercise
A discussion-based rehearsal in which a team walks through its response to a simulated scenario to test plans and roles.
Data protection
Adequacy Decision
A formal decision by the European Commission that a non-EU country provides a level of data protection essentially equivalent to the EU, allowing free data transfers there.
Anonymization
Irreversibly processing data so that individuals can no longer be identified, which takes it outside the scope of the GDPR.
Automated Decision-Making
Decisions made solely by automated means, without meaningful human involvement, which the GDPR restricts when they have legal or similarly significant effects.
Consent
A freely given, specific, informed, and unambiguous agreement by a data subject to the processing of their personal data.
Data Controller
The party that determines the purposes and means of processing personal data, and bears primary responsibility under the GDPR.
Data Minimization
The GDPR principle that personal data collected must be adequate, relevant, and limited to what is necessary for the purpose.
Data Processing Agreement (DPA)
The contract required between a controller and processor that governs how the processor may handle personal data.
Data Processor
A party that processes personal data on behalf of a controller, bound by the controller's instructions and a contract.
Data Protection Impact Assessment (DPIA)
An assessment of the privacy risks of a processing activity that is likely to result in a high risk to individuals.
Data Protection Officer (DPO)
An independent expert who advises an organization on data protection obligations and monitors compliance with the GDPR.
Data Retention
The defined periods for which data is kept before it is deleted or anonymized, balancing legal duties against minimization.
Data Subject
The identified or identifiable individual to whom personal data relates and who holds rights over that data.
DSMS (Data Protection Management System)
The management system that organizes how an organization meets data protection obligations such as the GDPR, covering lawful processing, data subject rights, and accountability.
GDPR
The EU General Data Protection Regulation, the comprehensive law governing how personal data of individuals in the EU may be processed.
International Data Transfer
The transfer of personal data to a country outside the EU or EEA, which the GDPR permits only under specific safeguards.
ISO/IEC 27701
An extension to ISO/IEC 27001 and 27002 that adds requirements for a privacy information management system (PIMS).
Joint Controller
Two or more controllers that jointly determine the purposes and means of processing personal data, sharing responsibility under the GDPR.
Legitimate Interest
A legal basis under the GDPR that allows processing of personal data when an organization's interests are not overridden by the rights of the individual.
Personal Data
Any information relating to an identified or identifiable natural person, the central concept the GDPR protects.
Personal Data Breach
A breach of security leading to the destruction, loss, alteration, or unauthorized disclosure of or access to personal data.
Privacy by Design and by Default
The GDPR requirement to build data protection into systems from the outset and to apply the most protective settings by default.
Pseudonymization
Processing personal data so it can no longer be attributed to a person without separately kept additional information.
Records of Processing Activities (RoPA)
The documented inventory of an organization's personal data processing activities, required by the GDPR.
Right to Data Portability
The GDPR right of individuals to receive their personal data in a structured, common format and to transmit it to another provider.
Right to Erasure
The GDPR right of individuals to have their personal data deleted in certain circumstances, also known as the right to be forgotten.
Special Category Data
Sensitive personal data under the GDPR, such as health, biometrics, or beliefs, that receives stronger protection and stricter processing conditions.
Standard Contractual Clauses (SCCs)
Pre-approved contract terms issued by the European Commission that provide a lawful basis for transferring personal data outside the EEA.
Sub-processor
A third party engaged by a processor to carry out specific processing of personal data on behalf of the controller.
Supervisory Authority
An independent public authority established under the GDPR to monitor and enforce its application, handle complaints, and exercise corrective powers.
AI governance
AI Bias
Systematic, unfair skew in an AI system's outputs that can disadvantage certain groups or individuals.
AI Literacy
The skills and understanding that let people deploy and use AI systems responsibly and recognize their opportunities and risks.
AI Risk
The risks specific to artificial intelligence systems, including bias, opacity, unsafe outputs, and loss of human control.
AIMS (AI Management System)
The management system that governs the responsible development and use of artificial intelligence, defined by ISO/IEC 42001.
CE Marking
A mark a manufacturer applies to declare that a product meets EU requirements, extended by the AI Act to certain high-risk AI systems.
Conformity Assessment
The process of demonstrating that a product or system, such as a high-risk AI system, meets the legal requirements before it is placed on the market.
EU AI Act
The EU regulation that governs artificial intelligence using a risk-based approach, with the strictest obligations for high-risk AI systems.
Explainability
The degree to which the reasoning behind an AI system's outputs can be understood and explained to people.
General-Purpose AI (GPAI)
An AI model that can perform a wide range of tasks and be integrated into many different systems, regulated under specific provisions of the EU AI Act.
Generative AI
AI systems that create new content such as text, images, audio, or code, often built on large foundation models.
High-Risk AI System
Under the EU AI Act, an AI system whose use poses significant risk to health, safety, or fundamental rights, subject to strict requirements.
Human Oversight
Measures that keep people able to monitor, intervene in, and override the operation of an AI system.
ISO/IEC 42001
The first international management system standard for artificial intelligence, specifying requirements for an AI management system (AIMS).
Model Card
A short, structured document that describes an AI model's purpose, performance, limitations, and intended use.
Notified Body
An independent organization designated by an EU country to assess the conformity of certain high-risk products before they reach the market.
Post-Market Monitoring
The ongoing duty to track how an AI system performs after deployment and to act on problems that emerge in real use.
Prohibited AI Practices
Uses of AI that the EU AI Act bans outright because they pose an unacceptable risk to fundamental rights.
Training Data
The data used to teach a machine learning model, whose quality and representativeness strongly shape the model's behavior.