Skip to main content

The GRC vocabulary, written by people who run it.

Honest, opinionated definitions for cybersecurity, privacy, risk and AI governance. Written from the seat of an active CISO, not copy-pasted from a standard. Each entry names what the term really means in practice, what it does not mean, and where to find the official text.

A glossary you can quote without sounding like a brochure.

GRC encyclopedia

Practitioner voice

Written from the audit room, not the academic library. What the term means and what people get wrong.

Sourced and dated

Entries include official sources where available and show their revision dates.

Linked across the site

Entries link to related terms, pillar pages and relevant training where those relationships exist.

Filter by topic
C

14 entries

CIS Controls

The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.

Cybersecurity operationsRead entry

COBIT

COBIT is the ISACA framework for the governance and management of enterprise IT. Current edition is COBIT 2019. The framework Big Four uses to assess IT governance maturity, and the reference for the CGEIT credential. More strategic than ISO 27001; less prescriptive than NIST.

Audit & complianceRead entry

CCAK · Certificate of Cloud Auditing Knowledge

CCAK is the joint ISACA / Cloud Security Alliance credential for cloud auditors. Covers cloud governance, CCM, the STAR programme and hyperscaler-specific audit considerations. The natural extension for a CISA-holder whose scope went cloud-first.

Certifications & credentialsRead entry

CCOA · Certified Cybersecurity Operations Analyst

CCOA is ISACA's hands-on cybersecurity operations credential, focused on SOC work: monitoring, detection, response, recovery. The technical companion to CISM. Best fit for analysts and incident responders rather than managers or auditors.

Certifications & credentialsRead entry

CDPSE · Certified Data Privacy Solutions Engineer

CDPSE is the ISACA technical-privacy credential. Three domains: privacy governance, privacy architecture, data lifecycle. The engineering-side companion to the policy-focused DPO/CDPO credentials. Strong fit for security teams owning privacy implementation and for architects working under the GDPR or the AI Act.

Certifications & credentialsRead entry

CISM · Certified Information Security Manager

CISM is the ISACA credential for information-security managers: governance, programme management, risk management, incident management. The gold standard for security-leadership roles, asked for in about 60% of CISO postings. Different lens from CISSP: management-focused, less technical.

Certifications & credentialsRead entry

CISA · Certified Information Systems Auditor

CISA is the reference IT-audit credential, awarded by ISACA since 1978. Five domains covering the audit process, governance, acquisition, operations and asset protection. The credential Big Four engagements default to. Recognised globally; mandatory for many internal-audit and compliance roles in regulated industries.

Certifications & credentialsRead entry

CRISC · Certified in Risk and Information Systems Control

CRISC is the ISACA risk credential for IT-risk practitioners. Identification, assessment, response, monitoring tied to information systems. Bridges business and IT risk. The natural complement to CISA for auditors moving into risk, and to ISO 27005 / 31000 for ISO-trained practitioners adding the ISACA vocabulary.

Certifications & credentialsRead entry

CGEIT · Certified in the Governance of Enterprise IT

CGEIT is the ISACA credential for senior practitioners advising on the governance of enterprise IT: strategic alignment, value delivery, risk and resource optimisation. Underpinned by COBIT. Smaller market than CISA / CISM, but the right credential for CIOs, board-level IT advisors and senior consultants.

Certifications & credentialsRead entry

CISO · Chief Information Security Officer

The CISO is the executive accountable for the information-security strategy. Owns the risk register, leads incident response, briefs the board, signs off on the residual risk. Under NIS 2 and DORA the accountability is now explicit and personal. The job is governance, not implementation; the hardest part is the boardroom translation.

Certifications & credentialsRead entry

CNIL · Commission nationale de l'informatique et des libertés

The CNIL is the French data-protection authority, founded in 1978. Enforces the GDPR in France, issues binding decisions and fines, publishes guidance (cookies, biometrics, AI), operates the PIA tool. One of the most active supervisory authorities in the EU; their decisions often set EU-wide precedent.

Standards bodiesRead entry

CRA · Cyber Resilience Act

The Cyber Resilience Act is the EU regulation that imposes baseline security obligations on hardware and software products with digital elements sold in Europe. Vendor obligations through the lifecycle: secure-by-design, vulnerability handling, SBOM, five years of patches. Adopted in late 2024, applies from December 2027. Pair with NIS 2 (organisational angle) and AI Act (model angle).

EU regulationsRead entry

CMMC · Cybersecurity Maturity Model Certification

CMMC is the cybersecurity maturity model the US Department of Defense imposes on its contractors handling federal contract information and controlled unclassified information. CMMC 2.0 collapsed to three levels (Foundational, Advanced, Expert) aligned with NIST SP 800-171 and 800-172. If you sell to the DoD or sit in their supply chain, you are in scope.

EU regulationsRead entry

CSX-P · Cybersecurity Practitioner Certification

CSX-P is the performance-based ISACA cybersecurity practitioner credential. Tested in a live cyber-range environment across the five NIST CSF functions. Less famous than CISM or CISA, but the rare credential where the exam tests what you actually do, not what you can write about.

Certifications & credentialsRead entry
D

6 entries

DPIA · Data Protection Impact Assessment

A DPIA is the structured analysis the GDPR requires before high-risk processing. Documents nature, scope, context, purposes; assesses necessity and proportionality; identifies mitigations. The CNIL ships a free PIA tool, use it. Skipping a DPIA when it was required is one of the cleaner ways to attract a regulator visit.

Privacy & data protectionRead entry

DPO · Data Protection Officer

The DPO is the GDPR-mandated role that monitors compliance, advises the controller, and acts as the contact point with the supervisory authority. Mandatory for public authorities and for processing that requires large-scale systematic monitoring or special-category data. Independence and management access are the two things auditors actually check.

Privacy & data protectionRead entry

Defense in depth

Defense in depth is the principle of layering controls so no single failure compromises the system. Network, endpoint, application, data, people, physical, each layer slows the attacker, raises the cost and buys you detection time. Foundational since the 1990s. Auditors expect to see it; vendors love to sell extra layers of it.

Cybersecurity operationsRead entry

DORA · Digital Operational Resilience Act

DORA is the EU regulation that imposes a unified resilience framework on financial entities and their critical ICT providers. Five pillars: ICT risk management, incident reporting, resilience testing including TLPT, third-party ICT risk, information-sharing. Applicable since 17 January 2025. It bites harder than NIS 2 on the ICT angle, and lex specialis means it wins for financial entities.

EU regulationsRead entry

DR · Disaster Recovery

Disaster recovery is the IT-focused subset of BCM: restoring infrastructure, applications and data after a disruption. The RPO, RTO and runbooks live here. The DR plan that has never been tested end-to-end is a fiction. ISO 24762 used to cover it; current practice points back to ISO 22301 plus the operational runbooks.

Resilience & continuityRead entry

DDoS · Distributed Denial of Service

DDoS is the attack that floods a service from many sources to exhaust capacity. Volumetric, protocol or application layer. Mitigation has commoditised (Cloudflare, Akamai, AWS Shield). The risk question is no longer "can we block it" but "are critical services routed through the protection, including the API ones we never see in dashboards".

Cybersecurity operationsRead entry
E

5 entries

EBIOS RM · EBIOS Risk Manager

EBIOS Risk Manager is ANSSI's cyber-risk method, focused on strategic attack scenarios. Maps business processes against attacker objectives, then derives the technical controls. Standard in French public-sector and operators of vital importance. Excellent for showing the board WHY a specific scenario matters; less common in private-sector multinational audits.

Risk managementRead entry

EU AI Act

The EU AI Act is the world's first comprehensive AI regulation. Four risk tiers: unacceptable (banned), high (the heavy obligations and conformity assessment), limited (transparency), minimal. Applies in phases until August 2027. Pair it with ISO 42001 if you want a management-system answer rather than a checklist. The GPAI model rules sit on top.

EU regulationsRead entry

EDR · Endpoint Detection and Response

EDR is the agent-based platform that records endpoint activity, detects suspicious behaviour and lets analysts isolate or remediate compromised hosts. XDR extends visibility across endpoints, network and cloud; MDR is the managed-service wrapper. The endpoint is still the most common entry point; EDR is now table stakes, not differentiation.

Cybersecurity operationsRead entry

ENISA · European Union Agency for Cybersecurity

ENISA is the EU cybersecurity agency, headquartered in Athens. Supports member states and EU institutions on cybersecurity policy, operational cooperation and the EU certification framework. Operationally involved in NIS 2 cooperation, DORA implementing standards, and the AI Act security baseline. Their threat-landscape report is the single most-cited yearly publication.

Standards bodiesRead entry

ePrivacy Directive

The ePrivacy Directive (2002/58/EC, amended in 2009) is the "cookie law" everyone half-implements. Governs confidentiality of electronic communications and tracking technologies on user devices. Older than GDPR and still in force; the ePrivacy Regulation that was supposed to replace it has been stuck in negotiation since 2017. National DPAs (CNIL, Garante, AEPD) enforce it on their patch.

EU regulationsRead entry
I

16 entries

ISO 19011

ISO 19011 is the guidelines standard for auditing management systems. Generic, applies to ISO 27001, 9001, 22301 audits alike. Defines audit principles, programme management, the audit cycle and auditor competence. The Lead Auditor course teaches it; the auditors you meet in the field were trained on it.

Audit & complianceRead entry

ISO 22301

ISO 22301 is the international standard for business continuity management systems (BCMS). Specifies the requirements to plan, operate, monitor and improve a BCMS that gets critical operations running again after disruption. Increasingly demanded by financial regulators since DORA, and by NIS 2 supervisors for operators of essential services.

Resilience & continuityRead entry

ISO 31000

ISO 31000 is the generic risk-management standard. Principles plus framework plus iterative process. NOT a certifiable management system, there is no ISO 31000 Lead Auditor, despite what some catalogues claim. The PECB path is Foundation → Risk Manager → Lead Risk Manager. Use it when risk is broader than information security alone.

Risk managementRead entry

ISO/IEC 27001

ISO 27001 is the certifiable framework auditors use to grade your information security. The 2022 revision tightened Annex A down to 93 controls across four themes (organisational, people, physical, technological). Your ISMS lives or dies on the Statement of Applicability and the operating evidence. Everyone references it; few run it well.

Information securityRead entry

ISO/IEC 27002

ISO 27002 is the implementation guidance for ISO 27001's Annex A controls. Not certifiable on its own. Auditors use it when they want to challenge HOW you operate a control, not just whether it is "in place". Treat it as the operational playbook beside the certification standard.

Information securityRead entry

ISO/IEC 27005

ISO 27005 is the information-security risk methodology that bolts onto ISO 27001. Identification, analysis, evaluation, treatment, acceptance. The 2022 revision aligns with ISO 31000's principles and clarifies the relationship with ISO 27001's Clause 6. Less prescriptive than EBIOS RM but the canonical lingua franca with auditors.

Risk managementRead entry

ISO/IEC 27017

ISO 27017 is the cloud-security control extension to ISO 27001. Adds cloud-specific controls and clarifies the shared-responsibility split between provider and customer. If your ISMS scope includes hyperscaler workloads (AWS, Azure, GCP, OVH), expect auditors to ask which 27017 controls you map onto.

Information securityRead entry

ISO/IEC 27018

ISO 27018 is the privacy control extension to ISO 27001 for cloud providers acting as processors of personally identifiable information. Bridges ISO 27001 with GDPR processor obligations. Mostly held by hyperscalers, used by their customers as a vendor-due-diligence input.

Privacy & data protectionRead entry

ISO/IEC 27034

ISO 27034 is the application security standard. Multi-part. Covers the secure software lifecycle: requirements, design, build, test, deploy, maintain. Less famous than 27001 because it lives inside the SDLC, but the only ISO standard that speaks the language of dev teams. Pairs naturally with OWASP and SBOM practice.

Information securityRead entry

ISO/IEC 27037

ISO 27037 is the digital forensics standard for identifying, collecting, acquiring and preserving digital evidence. The reference an internal forensic team, a CERT or a litigation-support consultant uses to keep chain-of-custody clean. Treat it as the playbook auditors and lawyers will compare your actions to after an incident.

Cybersecurity operationsRead entry

ISO/IEC 27701

ISO 27701 is the privacy-information-management extension to ISO 27001. Adds controller and processor obligations on top of the ISMS. Useful for organisations that want a single certifiable management system covering both security and privacy. Maps onto the GDPR but does not "replace" GDPR compliance work.

Privacy & data protectionRead entry

ISO/IEC 42001

ISO 42001 is the first international standard for AI management systems, published end of 2023. The AIMS equivalent of ISO 27001's ISMS. Built for organisations that need to govern AI design, deployment and operation: risk, accountability, transparency, continuous improvement. Maps cleanly onto the AI Act's high-risk obligations.

AI governanceRead entry

IAM · Identity and Access Management

IAM is the discipline that manages who can access what, when, how and under which conditions. Provisioning, authentication, authorisation, deprovisioning. Identity is the new perimeter. Every Zero Trust architecture is, at the core, a hard IAM problem disguised as a network one.

Cybersecurity operationsRead entry

ISMS · Information Security Management System

An ISMS is the documented system you run to protect information assets, risk-based, evidence-backed, under management review. It is not a binder of policies. Auditors do not grade your policies; they grade your operating evidence. Plan-Do-Check-Act cycle, certified under ISO 27001, with the SoA as the central artefact.

Information securityRead entry

ISACA · Information Systems Audit and Control Association

ISACA is the global association for IT audit, security, risk and governance professionals. Founded 1969, headquartered Schaumburg IL, 165,000+ members in 188 countries. Awards CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, CCOA. Publishes COBIT. Cyber Academy is an ISACA Accredited Premium Partner.

Standards bodiesRead entry

Inherent vs residual risk

Inherent risk is the exposure before controls. Residual risk is what remains after the controls operate. Auditors look at the gap: it must be justified, accepted (or treated further) by a named owner, and consistent with the risk appetite. Showing "residual = zero" anywhere in the register is a red flag, not a win.

Risk managementRead entry
N

5 entries

NIS 1 Directive

NIS 1 (Directive 2016/1148) was the EU's first cross-sector cybersecurity directive, covering operators of essential services and digital service providers. Replaced by NIS 2 in October 2024 because scope was too narrow, enforcement uneven and incident reporting toothless. Cited here mainly so you know what the "old regime" your colleagues still half-remember actually was.

EU regulationsRead entry

NIS 2 Directive

NIS 2 is the EU directive that puts cybersecurity boards on the hook. Mid-sized or larger, in any of 18 listed sectors, you are in scope. The clock starts on the first significant incident: 24-hour early warning, 72-hour notification, full report at one month. Penalties bite (10 million euros or 2% of worldwide turnover). Transposition state varies country to country.

EU regulationsRead entry

NIST CSF · NIST Cybersecurity Framework

NIST CSF is the cybersecurity framework published by the US National Institute of Standards and Technology. The 2.0 revision (2024) added "Govern" to the existing five functions (Identify, Protect, Detect, Respond, Recover). Not certifiable; used as a maturity reference. Common companion to ISO 27001 in transatlantic organisations.

Information securityRead entry

NIST SP 800-171

NIST SP 800-171 is the US standard that defines security requirements for protecting controlled unclassified information in non-federal systems. The technical backbone of CMMC for defence contractors. Revision 3 (2024) tightened the controls. If you sell to the US DoD, this is mandatory; if you sell only in Europe, it is informational.

Information securityRead entry

Non-conformity (NC)

A non-conformity is the auditor finding that a requirement is not met. Major NCs threaten the certificate; minor NCs require a corrective action plan with a deadline. Repeated minor NCs in the same area can escalate to major at the next surveillance audit. The goal is not zero NCs, it is honest, traceable corrective action.

Audit & complianceRead entry
P

8 entries

PCI DSS

PCI DSS is the Payment Card Industry Data Security Standard. Mandatory for anyone storing, processing or transmitting cardholder data. Version 4.0.1 is the current revision, fully mandatory since 31 March 2025. Scope-reduction (tokenisation, segmentation) is where the smart money goes; "compliant" is binary, but how small you make the scope is everything.

Audit & complianceRead entry

Patch management

Patch management is the operational process that takes a published fix and applies it across the estate, on a defined SLA, with verification. Often the weakest link: emergency patches collide with change windows, vendor compatibility, third-party dependencies. The audit always asks for the SLA, the exception list and the metrics.

Cybersecurity operationsRead entry

Penetration testing

A penetration test is an authorised, scoped attack simulation to find exploitable weaknesses before real attackers do. Black box / grey box / white box, internal / external, application / infrastructure. Distinguish from a vulnerability scan (automated, breadth) and from a red team (multi-month, objective-based). Reports drive the remediation backlog.

Cybersecurity operationsRead entry

Phishing

Phishing is the social-engineering attack that tricks a user into clicking a malicious link, opening a malicious file or revealing credentials. Variants: spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice), BEC (business email compromise). Training matters; phishing-resistant MFA matters more.

Cybersecurity operationsRead entry

Privacy by design and by default

Privacy by design (GDPR Article 25) is the obligation to bake privacy controls into systems from the requirements stage. Privacy by default is the obligation to make the highest-protection option the standard. Auditors look for documented evidence (DPIA, design review, retention defaults) rather than a slogan in a policy.

Privacy & data protectionRead entry

PAM · Privileged Access Management

PAM is the subset of IAM focused on privileged accounts: admins, root, service accounts, break-glass. Vaults credentials, brokers sessions, records activity. The first thing the attacker goes for after the initial foothold, and the control auditors test hardest under NIS 2 and DORA.

Cybersecurity operationsRead entry

PECB · Professional Evaluation and Certification Board

PECB is the Montreal-based accredited certification body that issues professional credentials on 30+ ISO standards across 150+ countries. Information security, risk, BCM, AI governance, privacy, quality. Cyber Academy is a PECB Gold Partner. The credentials carry PECB branding; the cohorts run through accredited partners.

Standards bodiesRead entry

Pseudonymisation

Pseudonymisation is the GDPR Article 4(5) technique of replacing direct identifiers with reversible tokens, with the key stored separately. Reduces risk and earns regulatory goodwill, but the data is still personal data. Anonymisation is the version that escapes GDPR entirely; pseudonymisation does not. Watch the conflation.

Privacy & data protectionRead entry
R

6 entries

Ransomware

Ransomware is the malware class that encrypts data and demands payment for the key, often paired with data theft and extortion (double extortion). Attack vectors: phishing, internet-facing exposure, supply chain. Insurance pays less, regulators scrutinise more. Pre-event work (backups, segmentation, IR plan) determines the outcome, not the negotiation.

Cybersecurity operationsRead entry

ROPA · Record of Processing Activities

The ROPA is the documented inventory of processing activities required by GDPR Article 30. Controllers list purpose, categories, recipients, retention, transfers; processors list controllers served, categories, transfers. Most organisations underestimate the maintenance work. The supervisory authority asks for the ROPA first when an investigation starts.

Privacy & data protectionRead entry

RTO / RPO · Recovery Time and Recovery Point Objectives

RTO is the maximum acceptable duration a business process can stay down before unacceptable harm. RPO is the maximum data loss measured in time before the disruption. Both come out of the BIA. The numbers your CIO writes in the BCP without consulting the business are the numbers that fail under pressure.

Resilience & continuityRead entry

Risk appetite

Risk appetite is the amount and type of risk the organisation is willing to take to meet its objectives. Set at executive or board level, in writing. Without it, every risk-treatment decision is a personal judgement call by the risk team, and the audit will tear it apart. Pair with risk tolerance (the deviation tolerated around the appetite).

Risk managementRead entry

Risk register

The risk register is the canonical, living list of identified risks with their analysis, evaluation, treatment and ownership. Not a one-time spreadsheet. Auditors expect dated entries, named owners, traceable changes and review cycles tied to management review. The board version is shorter; the operational version has everything.

Risk managementRead entry

Risk treatment

Risk treatment is what you do once you know the risk: avoid, reduce, transfer, accept. Each decision is documented, justified by the risk appetite, and traced through the SoA to the controls and the operating evidence. Most failed audits boil down to one thing: the treatment plan and reality drifted, nobody updated the SoA.

Risk managementRead entry
S

8 entries

SOC 2

SOC 2 is the AICPA attestation report on a service organisation's controls covering five trust criteria (security, availability, processing integrity, confidentiality, privacy). North-American canonical for SaaS vendors; ISO 27001 is the European equivalent. Type I = point-in-time; Type II = operating effectiveness over 6–12 months. Often demanded by enterprise procurement.

Audit & complianceRead entry

Schrems II

Schrems II is the 2020 CJEU judgement that struck down the EU-US Privacy Shield and added the Transfer Impact Assessment requirement. Every transfer to a third country now needs a documented analysis of local surveillance law and supplementary measures. Replaced in practice by the EU-US Data Privacy Framework (2023), but the TIA discipline stuck.

Privacy & data protectionRead entry

SIEM · Security Information and Event Management

A SIEM aggregates logs, normalises events and runs detection rules across your stack. The visibility layer the SOC depends on. Modern SIEM vendors (Splunk, Sentinel, Elastic, Sumo) increasingly bundle SOAR and UEBA. The hard work is not buying the SIEM; it is the data engineering and the detection-as-code pipeline that follows.

Cybersecurity operationsRead entry

SOC · Security Operations Center

A SOC is the team and toolset that monitors, detects, analyses and responds to security events in real time. Tiered analysts (T1 detection, T2 investigation, T3 threat hunting), 8x5 or 24x7. Internal, outsourced (MSSP) or hybrid. Without a SOC the SIEM is a log archive; with one it is an early-warning system.

Cybersecurity operationsRead entry

SOAR · Security Orchestration, Automation and Response

SOAR is the layer that takes SIEM alerts and runs playbooks: enrichment, triage, containment, ticketing. Goal: reduce MTTR and free analysts from copy-paste work. Watch for vendor over-promise: a SOAR is only as good as the playbooks you write and maintain. Most failed SOAR projects ran out of playbook authors.

Cybersecurity operationsRead entry

Stage 1 / Stage 2 audit

Initial ISO certification splits into stage 1 (documentation and readiness review, usually 1–2 days) and stage 2 (operational evidence audit, 2–5 days). Stage 1 confirms the management system exists on paper; stage 2 verifies it actually operates. Most "failed" stage 2 audits are stage 1 problems that nobody fixed in between.

Audit & complianceRead entry

SCC · Standard Contractual Clauses

SCCs are the European Commission-approved template clauses for transferring personal data to third countries without an adequacy decision. The 2021 SCCs replaced the older versions and require a Transfer Impact Assessment (TIA) since Schrems II. Mandatory paperwork for anyone using non-EU SaaS providers.

Privacy & data protectionRead entry

SoA · Statement of Applicability

The SoA is the controlled document that tells the auditor which Annex A controls apply to you, why, where the evidence lives. Mandatory under ISO 27001. Inconsistency between SoA, risk treatment plan and actual operations is the most common cause of non-conformities at stage 2 audit.

Information securityRead entry

Need the practical training?

A definition is the start. A certification is the proof.

Where a matching course exists, the entry links to training on the concept. Browse current options or ask us to map the closest path.