Glossary
The language of cybersecurity governance, in clear terms.
Key concepts we use in the CGF cycle, our solutions and Complyze.
14 terms
- Asset
- A resource of value to the organization that must be protected.
- BIA
- Business impact analysis.
- Business continuity
- The organization’s ability to keep operating and recover from an interruption.
- Control
- A measure that modifies a risk.
- Evidence
- A record that demonstrates a control is operating.
- Gap
- The difference between the current and the desired state.
- Governance
- A framework of decisions, roles and accountability.
- ISMS
- Information security management system.
- KPI / KRI
- Performance (KPI) and risk (KRI) indicators.
- Maturity
- The degree of consolidation of a capability.
- Risk
- The effect of uncertainty on objectives.
- Risk appetite
- The level of risk the organization is willing to accept.
- RTO / RPO
- Recovery time and recovery point objectives after an interruption.
- Statement of applicability (SoA)
- A document that justifies which ISO/IEC 27001 Annex A controls apply and why.
Missing a term?
If you’re looking for a concept that isn’t here yet, write to us and we’ll add it to the glossary.
Suggest a term