Glossary
ISO 27001 glossary
ISO/IEC 27001:2022 comes with its own vocabulary, and much of it sounds more forbidding than it is. These are plain-English definitions of the terms you will meet during implementation, certification and ongoing ISMS management.
45 of 45 terms shown.
A
- Accredited certification body
- An independent organisation authorised by a national accreditation body to audit management systems and issue ISO/IEC 27001 certificates. Only a certification body can grant certification; a consultancy cannot.
- Annex A
- The reference set of information security controls in ISO/IEC 27001:2022, containing 93 controls grouped into organisational, people, physical and technological themes. Controls are selected on the basis of risk, not adopted wholesale.
- Asset
- Anything of value to the organisation in the context of information security — information itself, systems, services, people, premises and suppliers that support it.
- Audit evidence
- Records, statements of fact or other verifiable information used to demonstrate that a requirement or control is being met. Evidence that cannot be located during an audit is treated as evidence that does not exist.
- Availability
- One of the three core properties of information security: information and systems being accessible and usable when authorised users need them.
C
- Certification cycle
- The three-year period covered by an ISO/IEC 27001 certificate, comprising the initial certification audit, surveillance audits during the period and a recertification audit at the end.
- CISO
- Chief Information Security Officer — the senior role accountable for an organisation's information security strategy, governance and risk management.
- CISSP
- Certified Information Systems Security Professional. An internationally recognised certification for experienced information security practitioners, covering security and risk management, asset security, architecture, operations and more.
- Confidentiality
- Ensuring that information is not made available or disclosed to unauthorised individuals, entities or processes.
- Context of the organisation
- Clause 4 of the standard: the internal and external issues, and the needs of interested parties, that are relevant to the ISMS and shape its scope.
- Continual improvement
- The requirement to keep improving the suitability, adequacy and effectiveness of the ISMS over time, evidenced through audits, reviews, objectives and corrective action.
- Control
- A measure that modifies risk. Controls may be organisational, technical, physical or people-related, and each should have an owner and evidence that it operates.
- Control owner
- The person responsible for ensuring a specific control is implemented, operating and evidenced. Named ownership is one of the strongest predictors of a healthy ISMS.
- Corrective action
- Action taken to eliminate the cause of a nonconformity and prevent recurrence, as opposed to simply correcting the immediate problem.
D
- Documented information
- The standard's term for the documents and records an ISMS must create, control and retain — replacing the older distinction between 'documents' and 'records'.
G
- Gap analysis
- An assessment of an organisation's current position against the requirements of ISO/IEC 27001:2022, producing a prioritised plan of what must change before certification is realistic.
I
- Information security
- The preservation of confidentiality, integrity and availability of information, regardless of the form it takes or the technology used to handle it.
- Information security policy
- The top-level policy approved by senior management setting out the organisation's commitment to information security and the framework for objectives. Required by clause 5.2.
- Integrity
- Safeguarding the accuracy and completeness of information and the processing methods that act upon it.
- Interested party
- Any person or organisation that can affect, be affected by, or perceive itself to be affected by the organisation's information security — customers, regulators, employees, shareholders, suppliers and insurers among others.
- Internal audit
- A mandatory, planned programme of audits carried out by or on behalf of the organisation to determine whether the ISMS conforms to the standard and to the organisation's own requirements, and whether it is effectively implemented.
- ISMS
- Information Security Management System. The coordinated set of policies, processes, roles, resources and records through which an organisation manages information security risk.
- ISO/IEC 27001:2022
- The current version of the international standard specifying requirements for establishing, implementing, maintaining and continually improving an ISMS, including the Annex A control set.
- ISO/IEC 27002
- A companion standard providing detailed implementation guidance for the information security controls referenced in Annex A of ISO/IEC 27001. It is guidance, not a certifiable standard.
L
- Lead Auditor
- A certified role qualified to plan and lead audits of an Information Security Management System against ISO/IEC 27001.
- Lead Implementer
- A certified role qualified to plan and lead the establishment and implementation of an ISMS conforming to ISO/IEC 27001.
M
- Management review
- A mandatory review by top management, at planned intervals, of the ISMS's continuing suitability, adequacy and effectiveness, with defined inputs including audit results, risk status, objectives and improvement opportunities.
N
- Nonconformity
- A failure to meet a requirement of the standard or of the organisation's own ISMS. Classified as minor or major; major nonconformities must be resolved promptly and can affect certification.
R
- Recertification audit
- A full reassessment of the ISMS carried out at the end of the three-year certification cycle to determine whether certification should be renewed.
- Residual risk
- The level of risk remaining after treatment has been applied. Residual risk must be accepted by an appropriate risk owner.
- Risk acceptance
- An informed decision, made by someone with the authority to make it, to take or tolerate a particular risk without further treatment.
- Risk assessment
- The overall process of identifying, analysing and evaluating information security risks using a documented, repeatable methodology.
- Risk owner
- The person with the accountability and authority to manage a specific risk and to accept residual risk on the organisation's behalf.
- Risk register
- The record of identified risks, their analysis, owners, treatment decisions and review history. An unchanged register signals to an auditor that risk is not being managed.
- Risk treatment plan
- The documented plan setting out how selected risks will be modified, who is responsible, what resources are needed and by when the treatment will be complete.
S
- Scope
- The documented boundaries of the ISMS — the services, locations, business units, systems and people it covers. Scope determines what a certificate actually assures.
- Security objectives
- Measurable information security objectives set at relevant functions and levels, with plans showing what will be done, with what resources, by whom and how results will be evaluated.
- Stage 1 audit
- The first part of the certification audit, focused on readiness: reviewing scope, policy, risk assessment, Statement of Applicability, internal audit and management review, and identifying areas of concern for Stage 2.
- Stage 2 audit
- The main certification audit, assessing whether the ISMS is implemented and effective through interviews, observation and sampling of evidence across the scope.
- Statement of Applicability
- The mandatory document recording which Annex A controls are applicable, the justification for inclusion or exclusion, and their implementation status. Auditors use it as a map of the ISMS.
- Supplier risk
- Information security risk arising from third parties who process, store, access or support the organisation's information. Managed through assessment, contractual requirements and ongoing review.
- Surveillance audit
- A periodic audit during the certification cycle, usually annual, sampling parts of the ISMS to confirm it remains implemented, effective and improving.
T
- Threat
- A potential cause of an unwanted incident that may result in harm to a system, service or organisation.
V
- vCISO
- Virtual CISO. An experienced information security leader engaged on a part-time or retained basis to provide senior governance, risk and compliance oversight without a permanent appointment.
- Vulnerability
- A weakness in an asset, control or process that could be exploited by a threat.
Still translating the standard?
If the terminology is getting in the way of a decision, a short conversation will usually clear it up faster than any glossary.
Or email info@isosecurity.co.uk