Glossary
Every term ISOSOC uses, explained without jargon. If a field in the app confuses you, it is probably defined here.
- Risk
- The effect of uncertainty on your objectives. In practice: something that could happen, how likely it is, and how much it would hurt.
- Threat
- The actor or event with the potential to cause harm — an attacker, a careless employee, a flood, a supplier failure.
- Vulnerability
- The weakness that a threat can exploit. A threat without a matching vulnerability rarely produces a risk.
- Asset
- Anything of value you need to protect: data, systems, people, suppliers, facilities, intellectual property.
- Likelihood
- How probable it is that the risk occurs within your assessment horizon, scored 1 (rare) to 5 (almost certain).
- Impact
- The severity of the consequence if the risk occurs, scored 1 (negligible) to 5 (severe).
- Inherent risk
- The risk score before any additional treatment — what you are exposed to with only today's controls.
- Residual risk
- The risk score you expect once your treatment plan is implemented. Residual risk must be formally accepted by the risk owner.
- Risk appetite
- The level of risk leadership is willing to carry. Typically expressed as a threshold, e.g. 'no residual risk above 9 without executive sign-off'.
- Risk treatment
- The decision and action taken on a risk: reduce, avoid, transfer, or accept.
- Reduce (mitigate)
- Apply controls to lower likelihood, impact, or both. The most common option.
- Avoid
- Stop or change the activity so the risk no longer applies — e.g. not storing a data type at all.
- Transfer (share)
- Move part of the exposure to a third party, typically via insurance or contractual terms. Accountability stays with you.
- Accept (retain)
- Consciously carry the risk, documented and approved by the risk owner. Not the same as ignoring it.
- Annex A control
- One of the 93 controls listed in Annex A of ISO/IEC 27001:2022, grouped into Organizational, People, Physical and Technological themes.
- Statement of Applicability (SoA)
- The document recording which Annex A controls apply, why, and their implementation status. Built directly from your risk assessment.
- ISMS
- Information Security Management System — the whole set of policies, processes and controls you certify against ISO 27001.
- Clause 6.1.2 / 6.1.3
- The clauses requiring a defined risk assessment process (6.1.2) and a risk treatment process producing the SoA (6.1.3).
- Trust Services Criteria (TSC)
- The AICPA criteria a SOC 2 report is assessed against: Security (Common Criteria), Availability, Confidentiality, Processing Integrity and Privacy.
- Common Criteria (CC)
- The security criteria all SOC 2 reports include — CC1 to CC9. Risk assessment sits in CC3.x and risk mitigation in CC9.x.
- SOC 2 Type I
- An auditor's opinion on whether controls are suitably designed at a single point in time.
- SOC 2 Type II
- An opinion on whether controls were suitably designed and operating effectively across a period, usually 3-12 months.
- Complementary user entity control
- A control your customer must operate for your controls to be effective — listed in the SOC 2 report.
- Control owner
- The person accountable for a control operating as designed. Often, but not always, the same as the risk owner.
- Risk owner
- The named individual accountable for managing a specific risk and accepting its residual level.
- Register review
- The periodic re-assessment of every entry: is it still valid, correctly scored, and progressing? Quarterly is a common cadence.
- Change log
- The versioned history of edits to the register. Auditors use it to confirm the register is live, not written the week before the audit.
Core
Core
Core
Core
Scoring
Scoring
Scoring
Scoring
Scoring
Treatment
Treatment
Treatment
Treatment
Treatment
ISO 27001
ISO 27001
ISO 27001
ISO 27001
SOC 2
SOC 2
SOC 2
SOC 2
SOC 2
Governance
Governance
Governance
Governance