Glossary

Every term ISOSOC uses, explained without jargon. If a field in the app confuses you, it is probably defined here.

Risk
Core
The effect of uncertainty on your objectives. In practice: something that could happen, how likely it is, and how much it would hurt.
Threat
Core
The actor or event with the potential to cause harm — an attacker, a careless employee, a flood, a supplier failure.
Vulnerability
Core
The weakness that a threat can exploit. A threat without a matching vulnerability rarely produces a risk.
Asset
Core
Anything of value you need to protect: data, systems, people, suppliers, facilities, intellectual property.
Likelihood
Scoring
How probable it is that the risk occurs within your assessment horizon, scored 1 (rare) to 5 (almost certain).
Impact
Scoring
The severity of the consequence if the risk occurs, scored 1 (negligible) to 5 (severe).
Inherent risk
Scoring
The risk score before any additional treatment — what you are exposed to with only today's controls.
Residual risk
Scoring
The risk score you expect once your treatment plan is implemented. Residual risk must be formally accepted by the risk owner.
Risk appetite
Scoring
The level of risk leadership is willing to carry. Typically expressed as a threshold, e.g. 'no residual risk above 9 without executive sign-off'.
Risk treatment
Treatment
The decision and action taken on a risk: reduce, avoid, transfer, or accept.
Reduce (mitigate)
Treatment
Apply controls to lower likelihood, impact, or both. The most common option.
Avoid
Treatment
Stop or change the activity so the risk no longer applies — e.g. not storing a data type at all.
Transfer (share)
Treatment
Move part of the exposure to a third party, typically via insurance or contractual terms. Accountability stays with you.
Accept (retain)
Treatment
Consciously carry the risk, documented and approved by the risk owner. Not the same as ignoring it.
Annex A control
ISO 27001
One of the 93 controls listed in Annex A of ISO/IEC 27001:2022, grouped into Organizational, People, Physical and Technological themes.
Statement of Applicability (SoA)
ISO 27001
The document recording which Annex A controls apply, why, and their implementation status. Built directly from your risk assessment.
ISMS
ISO 27001
Information Security Management System — the whole set of policies, processes and controls you certify against ISO 27001.
Clause 6.1.2 / 6.1.3
ISO 27001
The clauses requiring a defined risk assessment process (6.1.2) and a risk treatment process producing the SoA (6.1.3).
Trust Services Criteria (TSC)
SOC 2
The AICPA criteria a SOC 2 report is assessed against: Security (Common Criteria), Availability, Confidentiality, Processing Integrity and Privacy.
Common Criteria (CC)
SOC 2
The security criteria all SOC 2 reports include — CC1 to CC9. Risk assessment sits in CC3.x and risk mitigation in CC9.x.
SOC 2 Type I
SOC 2
An auditor's opinion on whether controls are suitably designed at a single point in time.
SOC 2 Type II
SOC 2
An opinion on whether controls were suitably designed and operating effectively across a period, usually 3-12 months.
Complementary user entity control
SOC 2
A control your customer must operate for your controls to be effective — listed in the SOC 2 report.
Control owner
Governance
The person accountable for a control operating as designed. Often, but not always, the same as the risk owner.
Risk owner
Governance
The named individual accountable for managing a specific risk and accepting its residual level.
Register review
Governance
The periodic re-assessment of every entry: is it still valid, correctly scored, and progressing? Quarterly is a common cadence.
Change log
Governance
The versioned history of edits to the register. Auditors use it to confirm the register is live, not written the week before the audit.