Glossary
22 terms that come up in any certification project, defined without waffle. If something we explain does not make sense, that is on us: start here.
Management systems
- Information Security Management SystemISMS
The set of policies, processes, roles and controls through which an organisation deliberately manages the security of its information. It is what ISO/IEC 27001 certifies: not a technology or a product, but the systematic way the organisation identifies its risks, decides what to do about them, and verifies that what was decided actually works.
The most common confusion is expecting the ISMS to be a piece of software. Software can support the system —recording risks, versioning documents, scheduling tasks— but the system is the decision structure: who answers for what, on what basis, and with what evidence.
- Annex A
The reference list of security controls that accompanies ISO/IEC 27001. In the 2022 version it contains 93 controls grouped into four themes —organisational, people, physical and technological— compared with 114 across fourteen domains in the 2013 version.
Annex A is not a list of mandatory tasks: it is a catalogue against which the organisation compares the controls its risk analysis determined were necessary, to verify that nothing relevant was left out. Exclusions are legitimate if they are justified in the Statement of Applicability.
- Statement of ApplicabilitySoA
A mandatory ISO/IEC 27001 document that lists every Annex A control and states, for each one, whether it applies, how it is implemented and —where it does not apply— why it is excluded.
It is the document the external auditor reads first, because it shows at a glance the coherence between the risk analysis and the controls actually implemented. An SoA that declares all 93 controls applicable without distinction usually indicates the risk analysis was not done seriously.
- Management system scope
An explicit definition of which processes, services, departments, sites and assets fall inside the management system and, by difference, which fall outside. It is what appears on the certificate.
A narrower scope is not a trick: it is a legitimate prioritisation decision. What is not legitimate is leaving the interfaces with what was excluded untreated, because that is precisely where risk gets in.
- Management review
A formal, documented occasion on which top management evaluates the performance of the management system —indicators, incidents, audit findings, achievement of objectives, changes in context— and takes decisions on resources and improvement.
It is a requirement, not a formality: if management leaves no record of having reviewed and decided, the system does not comply. In practice it is also the moment the project stops belonging to IT and starts belonging to the organisation.
- Artificial Intelligence Management SystemAIMS
The management system defined by ISO/IEC 42001:2023 to govern the use of artificial intelligence in an organisation: an inventory of AI systems, accountable owners, assessment of risks and impacts on people, control of the life cycle and of the data, and transparency.
It is the first certifiable international standard on the subject. It does not regulate the technology: it regulates the decisions about the technology, with the same logic of management and continual improvement as ISO/IEC 27001.
- Maturity scale
A way of measuring a control not by whether it exists but by how far it has developed, on a scale of several levels running from non-existent through to managed, measured and optimised.
Replacing yes/no with a maturity scale changes the outcome of an assessment and, above all, changes the plan: instead of a list of missing items it produces an order of work, because it distinguishes what does not exist from what exists but is neither applied nor measured.
The 93 controls and the “we comply with almost everything” trap
Certification
- Stage 1 and stage 2 certification audits
The two phases of the initial certification audit. At stage 1 the body reviews documentation and readiness and determines whether the organisation can proceed. At stage 2 it verifies in the field that the system genuinely operates and produces the evidence it claims.
Four to eight weeks usually pass between the two, used to close the observations raised at stage 1. Certifying with no non-conformities at stage 2 is uncommon: the usual outcome is to close with some minor ones, resolved before the certificate is issued.
- Non-conformity
A failure to meet a requirement of the standard, identified during an audit. It is classified as major —when it compromises the system’s ability to achieve its objective, or when a requirement is simply not met— and minor, when it is an isolated deviation.
A major non-conformity blocks certification until it is resolved and verified. Minor ones are closed with a corrective action plan accepted by the auditor. Neither is a failure of the project: they are part of the normal process.
- Accreditation and certification
Certification is issued by a certification body to an organisation. Accreditation is the recognition a national accreditation body grants to that certification body, authorising it to issue certificates with international validity.
The distinction matters commercially: a certificate issued by a body not accredited for that standard carries far less weight with third parties. It is worth verifying accreditation before contracting the audit, not after.
- Internal audit
An audit the organisation carries out on its own management system ahead of the external audit. Every ISO management system standard requires it, and requires that it be performed by people independent of the area being audited.
That independence is the point most often neglected: whoever implemented the system cannot audit it. It can be resolved with properly trained internal staff from another area, or with external auditors outside the advisory team.
Risk and continuity
- Risk assessment
The process of identifying the risks that threaten the organisation’s information, estimating their likelihood and impact, comparing them against the defined acceptance criteria, and deciding how to treat each one: mitigate, transfer, avoid or accept.
It is the heart of ISO/IEC 27001 and what determines which controls apply. An assessment copied from a generic template produces a system that does not protect what this particular organisation actually has to protect.
- Business impact analysisBIA
A study that determines which processes are critical to the organisation, how long they can be disrupted before the damage becomes unacceptable, and what resources they need to resume operating.
The BIA comes before the continuity plan: without it, the plan protects what seems important rather than what actually is. The recovery time and recovery point objectives come out of it.
- RTO and RPO
RTO (Recovery Time Objective) is the maximum acceptable time a process can remain disrupted. RPO (Recovery Point Objective) is the maximum amount of data, measured in time, the organisation accepts losing in a disruption.
An RPO of four hours means the backup has to run at least every four hours. Both values are set by the business, not by technology: technology then says what it costs to meet them.
- BCP and DRP
The business continuity plan (BCP) describes how the organisation keeps operating during a serious disruption, including manual workarounds. The disaster recovery plan (DRP) describes how systems and technology infrastructure are restored.
The BCP belongs to the organisation; the DRP belongs to IT and sits inside it. A plan that has never been tested is not a plan: the documented test is part of the deliverable.
Technical
- Attack Surface ManagementASM
Continuous discovery and monitoring of everything an organisation exposes on the internet: domains, subdomains, IP addresses, open services, certificates and reachable panels. It starts from the known domains and finds what the declared inventory does not record.
It is not a penetration test. ASM is broad and continuous but does not exploit what it finds; a pentest is narrow and deep but happens once. They are usually used together: ASM shows where a pentest is worth aiming.
- Subdomain takeover
A situation in which one of the organisation’s DNS records still points at an external service that has been decommissioned, so a third party can claim that resource and serve content under the legitimate domain.
It is one of the most frequent and most underestimated findings of attack surface monitoring. The damage is not technical but reputational: the attacker’s content appears under the organisation’s trusted domain.
- Threat intelligence
The collection and analysis of information about vulnerabilities, attack campaigns and active actors, filtered and prioritised by relevance to the specific technology the organisation uses.
ISO/IEC 27001:2022 introduced it as a new Annex A control, and requires that the information collected be analysed and used: accumulating bulletins without processing them does not satisfy the control.
- Controlled phishing
A simulated exercise in which staff are sent an email that looks fraudulent, agreed beforehand with management, to measure the organisation’s real exposure to deception before designing the awareness programme.
Its value lies in measuring before training. To avoid damaging trust within the team, individual results are not published and the exercise is communicated along with its conclusions once it is over.
Regulation
- Authorised Economic OperatorAEO
A status granted by the customs authority to companies that demonstrate compliance, financial solvency and security across their supply chain. It unlocks operational facilitation: fewer physical inspections, priority clearance and mutual recognition with the customs administrations of other countries.
It is not an ISO certification, although ISO 28000 provides the management system that organises and evidences much of what customs verifies. The international reference framework is the World Customs Organization’s SAFE Framework.
- Uruguay’s Law 18.331
Uruguay’s Personal Data Protection and Habeas Data Act. It establishes the principles of processing —purpose, prior and informed consent, security, confidentiality— the rights individuals hold over their data, and the obligations of those who process it, supervised by the Personal Data Regulatory and Control Unit.
It treats data relating to health, ethnic origin, beliefs and sexual life as sensitive data, with reinforced requirements. An ISO/IEC 27001 ISMS does not on its own guarantee legal compliance, but it provides most of the controls and the evidence the law requires.
- Third-party due diligence
The process of evaluating the risk a partner, supplier, agent or intermediary represents before contracting them and periodically thereafter, considering their track record, their ownership structure, their exposure to corruption and their ability to meet the obligations passed on to them.
It is a central requirement of ISO 37001 and a growing part of ISO/IEC 27001, where the supplier chain concentrates much of the organisation’s real risk.
