GRC encyclopedia
The GRC vocabulary, written by people who run it.
Honest, opinionated definitions for cybersecurity, privacy, risk and AI governance. Written from the seat of an active CISO, not copy-pasted from a standard. Each entry names what the term really means in practice, what it does not mean, and where to find the official text.
A glossary you can quote without sounding like a brochure.
GRC encyclopedia
Practitioner voice
Written from the audit room, not the academic library. What the term means and what people get wrong.
Sourced and dated
Entries include official sources where available and show their revision dates.
Linked across the site
Entries link to related terms, pillar pages and relevant training where those relationships exist.
3 entries
AI Risk Manager
AI Risk Manager is the credential (PECB / ISACA emerging) for practitioners running AI-specific risk programmes: model risk, bias, drift, transparency, third-party model risk. Operational layer that complements ISO 42001 (system-level) and the AI Act (regulatory layer). Common companion to a CISO or Lead AI Auditor.
AAIA · Advanced in AI Audit
AAIA is the advanced ISACA credential for auditing AI systems, models and governance. Newer (2024 onwards). Requires existing CISA or equivalent. Built for senior auditors adding AI capability, mapped onto ISO 42001 and the EU AI Act high-risk obligations.
ANSSI · French National Cybersecurity Agency
ANSSI is the French national cybersecurity agency, reporting to the Prime Minister since 2009. National authority for cybersecurity policy in France, qualifies products and service providers, publishes EBIOS Risk Manager, acts as competent authority for NIS 2 transposition. Their qualifications (SecNumCloud, PVID, PASSI) are the gold standard in the French public sector.
3 entries
BCM · Business Continuity Management
BCM is the discipline that identifies threats to your critical operations, then designs the plans and procedures to keep them running through disruption. Not a one-off project. The BCM team that delivers under a real incident is the one that ran a tabletop exercise four months ago and wrote down what failed.
BEC · Business Email Compromise
BEC is the targeted social-engineering attack that impersonates an executive or supplier to redirect a payment or trick an employee into approving one. No malware required; pure pretexting. Average loss per incident dwarfs ransomware. Process controls (segregation of duties, callback verification) catch it; technology alone does not.
BIA · Business Impact Analysis
A BIA is the structured analysis that quantifies the impact of disruption on each critical activity over time. Outputs include the recovery time objective, recovery point objective and minimum business continuity objective. Mandatory input for ISO 22301 and DORA. Done well, it becomes the document the board actually reads.
14 entries
CIS Controls
The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.
COBIT
COBIT is the ISACA framework for the governance and management of enterprise IT. Current edition is COBIT 2019. The framework Big Four uses to assess IT governance maturity, and the reference for the CGEIT credential. More strategic than ISO 27001; less prescriptive than NIST.
CCAK · Certificate of Cloud Auditing Knowledge
CCAK is the joint ISACA / Cloud Security Alliance credential for cloud auditors. Covers cloud governance, CCM, the STAR programme and hyperscaler-specific audit considerations. The natural extension for a CISA-holder whose scope went cloud-first.
CCOA · Certified Cybersecurity Operations Analyst
CCOA is ISACA's hands-on cybersecurity operations credential, focused on SOC work: monitoring, detection, response, recovery. The technical companion to CISM. Best fit for analysts and incident responders rather than managers or auditors.
CDPSE · Certified Data Privacy Solutions Engineer
CDPSE is the ISACA technical-privacy credential. Three domains: privacy governance, privacy architecture, data lifecycle. The engineering-side companion to the policy-focused DPO/CDPO credentials. Strong fit for security teams owning privacy implementation and for architects working under the GDPR or the AI Act.
CISM · Certified Information Security Manager
CISM is the ISACA credential for information-security managers: governance, programme management, risk management, incident management. The gold standard for security-leadership roles, asked for in about 60% of CISO postings. Different lens from CISSP: management-focused, less technical.
CISA · Certified Information Systems Auditor
CISA is the reference IT-audit credential, awarded by ISACA since 1978. Five domains covering the audit process, governance, acquisition, operations and asset protection. The credential Big Four engagements default to. Recognised globally; mandatory for many internal-audit and compliance roles in regulated industries.
CRISC · Certified in Risk and Information Systems Control
CRISC is the ISACA risk credential for IT-risk practitioners. Identification, assessment, response, monitoring tied to information systems. Bridges business and IT risk. The natural complement to CISA for auditors moving into risk, and to ISO 27005 / 31000 for ISO-trained practitioners adding the ISACA vocabulary.
CGEIT · Certified in the Governance of Enterprise IT
CGEIT is the ISACA credential for senior practitioners advising on the governance of enterprise IT: strategic alignment, value delivery, risk and resource optimisation. Underpinned by COBIT. Smaller market than CISA / CISM, but the right credential for CIOs, board-level IT advisors and senior consultants.
CISO · Chief Information Security Officer
The CISO is the executive accountable for the information-security strategy. Owns the risk register, leads incident response, briefs the board, signs off on the residual risk. Under NIS 2 and DORA the accountability is now explicit and personal. The job is governance, not implementation; the hardest part is the boardroom translation.
CNIL · Commission nationale de l'informatique et des libertés
The CNIL is the French data-protection authority, founded in 1978. Enforces the GDPR in France, issues binding decisions and fines, publishes guidance (cookies, biometrics, AI), operates the PIA tool. One of the most active supervisory authorities in the EU; their decisions often set EU-wide precedent.
CRA · Cyber Resilience Act
The Cyber Resilience Act is the EU regulation that imposes baseline security obligations on hardware and software products with digital elements sold in Europe. Vendor obligations through the lifecycle: secure-by-design, vulnerability handling, SBOM, five years of patches. Adopted in late 2024, applies from December 2027. Pair with NIS 2 (organisational angle) and AI Act (model angle).
CMMC · Cybersecurity Maturity Model Certification
CMMC is the cybersecurity maturity model the US Department of Defense imposes on its contractors handling federal contract information and controlled unclassified information. CMMC 2.0 collapsed to three levels (Foundational, Advanced, Expert) aligned with NIST SP 800-171 and 800-172. If you sell to the DoD or sit in their supply chain, you are in scope.
CSX-P · Cybersecurity Practitioner Certification
CSX-P is the performance-based ISACA cybersecurity practitioner credential. Tested in a live cyber-range environment across the five NIST CSF functions. Less famous than CISM or CISA, but the rare credential where the exam tests what you actually do, not what you can write about.
6 entries
DPIA · Data Protection Impact Assessment
A DPIA is the structured analysis the GDPR requires before high-risk processing. Documents nature, scope, context, purposes; assesses necessity and proportionality; identifies mitigations. The CNIL ships a free PIA tool, use it. Skipping a DPIA when it was required is one of the cleaner ways to attract a regulator visit.
DPO · Data Protection Officer
The DPO is the GDPR-mandated role that monitors compliance, advises the controller, and acts as the contact point with the supervisory authority. Mandatory for public authorities and for processing that requires large-scale systematic monitoring or special-category data. Independence and management access are the two things auditors actually check.
Defense in depth
Defense in depth is the principle of layering controls so no single failure compromises the system. Network, endpoint, application, data, people, physical, each layer slows the attacker, raises the cost and buys you detection time. Foundational since the 1990s. Auditors expect to see it; vendors love to sell extra layers of it.
DORA · Digital Operational Resilience Act
DORA is the EU regulation that imposes a unified resilience framework on financial entities and their critical ICT providers. Five pillars: ICT risk management, incident reporting, resilience testing including TLPT, third-party ICT risk, information-sharing. Applicable since 17 January 2025. It bites harder than NIS 2 on the ICT angle, and lex specialis means it wins for financial entities.
DR · Disaster Recovery
Disaster recovery is the IT-focused subset of BCM: restoring infrastructure, applications and data after a disruption. The RPO, RTO and runbooks live here. The DR plan that has never been tested end-to-end is a fiction. ISO 24762 used to cover it; current practice points back to ISO 22301 plus the operational runbooks.
DDoS · Distributed Denial of Service
DDoS is the attack that floods a service from many sources to exhaust capacity. Volumetric, protocol or application layer. Mitigation has commoditised (Cloudflare, Akamai, AWS Shield). The risk question is no longer "can we block it" but "are critical services routed through the protection, including the API ones we never see in dashboards".
5 entries
EBIOS RM · EBIOS Risk Manager
EBIOS Risk Manager is ANSSI's cyber-risk method, focused on strategic attack scenarios. Maps business processes against attacker objectives, then derives the technical controls. Standard in French public-sector and operators of vital importance. Excellent for showing the board WHY a specific scenario matters; less common in private-sector multinational audits.
EU AI Act
The EU AI Act is the world's first comprehensive AI regulation. Four risk tiers: unacceptable (banned), high (the heavy obligations and conformity assessment), limited (transparency), minimal. Applies in phases until August 2027. Pair it with ISO 42001 if you want a management-system answer rather than a checklist. The GPAI model rules sit on top.
EDR · Endpoint Detection and Response
EDR is the agent-based platform that records endpoint activity, detects suspicious behaviour and lets analysts isolate or remediate compromised hosts. XDR extends visibility across endpoints, network and cloud; MDR is the managed-service wrapper. The endpoint is still the most common entry point; EDR is now table stakes, not differentiation.
ENISA · European Union Agency for Cybersecurity
ENISA is the EU cybersecurity agency, headquartered in Athens. Supports member states and EU institutions on cybersecurity policy, operational cooperation and the EU certification framework. Operationally involved in NIS 2 cooperation, DORA implementing standards, and the AI Act security baseline. Their threat-landscape report is the single most-cited yearly publication.
ePrivacy Directive
The ePrivacy Directive (2002/58/EC, amended in 2009) is the "cookie law" everyone half-implements. Governs confidentiality of electronic communications and tracking technologies on user devices. Older than GDPR and still in force; the ePrivacy Regulation that was supposed to replace it has been stuck in negotiation since 2017. National DPAs (CNIL, Garante, AEPD) enforce it on their patch.
16 entries
ISO 19011
ISO 19011 is the guidelines standard for auditing management systems. Generic, applies to ISO 27001, 9001, 22301 audits alike. Defines audit principles, programme management, the audit cycle and auditor competence. The Lead Auditor course teaches it; the auditors you meet in the field were trained on it.
ISO 22301
ISO 22301 is the international standard for business continuity management systems (BCMS). Specifies the requirements to plan, operate, monitor and improve a BCMS that gets critical operations running again after disruption. Increasingly demanded by financial regulators since DORA, and by NIS 2 supervisors for operators of essential services.
ISO 31000
ISO 31000 is the generic risk-management standard. Principles plus framework plus iterative process. NOT a certifiable management system, there is no ISO 31000 Lead Auditor, despite what some catalogues claim. The PECB path is Foundation → Risk Manager → Lead Risk Manager. Use it when risk is broader than information security alone.
ISO/IEC 27001
ISO 27001 is the certifiable framework auditors use to grade your information security. The 2022 revision tightened Annex A down to 93 controls across four themes (organisational, people, physical, technological). Your ISMS lives or dies on the Statement of Applicability and the operating evidence. Everyone references it; few run it well.
ISO/IEC 27002
ISO 27002 is the implementation guidance for ISO 27001's Annex A controls. Not certifiable on its own. Auditors use it when they want to challenge HOW you operate a control, not just whether it is "in place". Treat it as the operational playbook beside the certification standard.
ISO/IEC 27005
ISO 27005 is the information-security risk methodology that bolts onto ISO 27001. Identification, analysis, evaluation, treatment, acceptance. The 2022 revision aligns with ISO 31000's principles and clarifies the relationship with ISO 27001's Clause 6. Less prescriptive than EBIOS RM but the canonical lingua franca with auditors.
ISO/IEC 27017
ISO 27017 is the cloud-security control extension to ISO 27001. Adds cloud-specific controls and clarifies the shared-responsibility split between provider and customer. If your ISMS scope includes hyperscaler workloads (AWS, Azure, GCP, OVH), expect auditors to ask which 27017 controls you map onto.
ISO/IEC 27018
ISO 27018 is the privacy control extension to ISO 27001 for cloud providers acting as processors of personally identifiable information. Bridges ISO 27001 with GDPR processor obligations. Mostly held by hyperscalers, used by their customers as a vendor-due-diligence input.
ISO/IEC 27034
ISO 27034 is the application security standard. Multi-part. Covers the secure software lifecycle: requirements, design, build, test, deploy, maintain. Less famous than 27001 because it lives inside the SDLC, but the only ISO standard that speaks the language of dev teams. Pairs naturally with OWASP and SBOM practice.
ISO/IEC 27037
ISO 27037 is the digital forensics standard for identifying, collecting, acquiring and preserving digital evidence. The reference an internal forensic team, a CERT or a litigation-support consultant uses to keep chain-of-custody clean. Treat it as the playbook auditors and lawyers will compare your actions to after an incident.
ISO/IEC 27701
ISO 27701 is the privacy-information-management extension to ISO 27001. Adds controller and processor obligations on top of the ISMS. Useful for organisations that want a single certifiable management system covering both security and privacy. Maps onto the GDPR but does not "replace" GDPR compliance work.
ISO/IEC 42001
ISO 42001 is the first international standard for AI management systems, published end of 2023. The AIMS equivalent of ISO 27001's ISMS. Built for organisations that need to govern AI design, deployment and operation: risk, accountability, transparency, continuous improvement. Maps cleanly onto the AI Act's high-risk obligations.
IAM · Identity and Access Management
IAM is the discipline that manages who can access what, when, how and under which conditions. Provisioning, authentication, authorisation, deprovisioning. Identity is the new perimeter. Every Zero Trust architecture is, at the core, a hard IAM problem disguised as a network one.
ISMS · Information Security Management System
An ISMS is the documented system you run to protect information assets, risk-based, evidence-backed, under management review. It is not a binder of policies. Auditors do not grade your policies; they grade your operating evidence. Plan-Do-Check-Act cycle, certified under ISO 27001, with the SoA as the central artefact.
ISACA · Information Systems Audit and Control Association
ISACA is the global association for IT audit, security, risk and governance professionals. Founded 1969, headquartered Schaumburg IL, 165,000+ members in 188 countries. Awards CISA, CISM, CRISC, CGEIT, CDPSE, AAIA, CCOA. Publishes COBIT. Cyber Academy is an ISACA Accredited Premium Partner.
Inherent vs residual risk
Inherent risk is the exposure before controls. Residual risk is what remains after the controls operate. Auditors look at the gap: it must be justified, accepted (or treated further) by a named owner, and consistent with the risk appetite. Showing "residual = zero" anywhere in the register is a red flag, not a win.
4 entries
Lead Auditor
Lead Auditor is the PECB credential for practitioners who can plan and lead third-party or internal audits of a management system. Five-day course built on ISO 19011. Entry point to becoming an accredited certification-body auditor. Different mindset from Lead Implementer: evidence, sampling, reporting, interview technique.
Lead Ethical Hacker
Lead Ethical Hacker is the PECB-certified credential for offensive-security practitioners. Covers methodology, scoping, reconnaissance, exploitation, reporting and ethics. The accreditation companion to hands-on credentials like OSCP and CRTO. Pairs with Lead Penetration Testing Professional for engagement leadership.
Lead Implementer
Lead Implementer is the PECB credential for practitioners who can plan, build and run a management system based on a specific ISO standard (most often ISO 27001, ISO 42001, ISO 22301). Five-day course, exam, certificate. The implementation half of the ISO discipline; complements Lead Auditor on the audit side.
Least privilege
Least privilege is the principle that every identity (human or machine) gets the minimum permissions needed for the job, and no more. Sounds obvious; rarely applied. Most data-exfiltration incidents start with an over-permissioned service account that nobody could justify when asked. Pair with regular access reviews.
3 entries
MITRE ATT&CK
MITRE ATT&CK is the open knowledge base of adversary tactics, techniques and procedures (TTPs) observed in the wild. Standard vocabulary for threat-informed defence: detection rules, red-team scenarios, SOC analyst training. Updated continuously, free to use. If your SIEM rules do not reference ATT&CK technique IDs, you are working harder than needed.
MTTD / MTTR · Mean Time to Detect / Recover
MTTD is the average time from incident start to detection. MTTR is the average time from detection to recovery. Together they are the headline operational metrics for a SOC and an incident response programme. Industry benchmarks float in the days/weeks; mature programmes target hours.
MFA · Multi-Factor Authentication
MFA is the requirement that authentication uses two or more factors from different categories (knowledge, possession, inherence). Not all MFA is equal: SMS and email codes are phishable, push notifications get fatigued, hardware tokens and passkeys are the strong forms. NIS 2 and DORA both mandate "strong" MFA on critical access.
5 entries
NIS 1 Directive
NIS 1 (Directive 2016/1148) was the EU's first cross-sector cybersecurity directive, covering operators of essential services and digital service providers. Replaced by NIS 2 in October 2024 because scope was too narrow, enforcement uneven and incident reporting toothless. Cited here mainly so you know what the "old regime" your colleagues still half-remember actually was.
NIS 2 Directive
NIS 2 is the EU directive that puts cybersecurity boards on the hook. Mid-sized or larger, in any of 18 listed sectors, you are in scope. The clock starts on the first significant incident: 24-hour early warning, 72-hour notification, full report at one month. Penalties bite (10 million euros or 2% of worldwide turnover). Transposition state varies country to country.
NIST CSF · NIST Cybersecurity Framework
NIST CSF is the cybersecurity framework published by the US National Institute of Standards and Technology. The 2.0 revision (2024) added "Govern" to the existing five functions (Identify, Protect, Detect, Respond, Recover). Not certifiable; used as a maturity reference. Common companion to ISO 27001 in transatlantic organisations.
NIST SP 800-171
NIST SP 800-171 is the US standard that defines security requirements for protecting controlled unclassified information in non-federal systems. The technical backbone of CMMC for defence contractors. Revision 3 (2024) tightened the controls. If you sell to the US DoD, this is mandatory; if you sell only in Europe, it is informational.
Non-conformity (NC)
A non-conformity is the auditor finding that a requirement is not met. Major NCs threaten the certificate; minor NCs require a corrective action plan with a deadline. Repeated minor NCs in the same area can escalate to major at the next surveillance audit. The goal is not zero NCs, it is honest, traceable corrective action.
8 entries
PCI DSS
PCI DSS is the Payment Card Industry Data Security Standard. Mandatory for anyone storing, processing or transmitting cardholder data. Version 4.0.1 is the current revision, fully mandatory since 31 March 2025. Scope-reduction (tokenisation, segmentation) is where the smart money goes; "compliant" is binary, but how small you make the scope is everything.
Patch management
Patch management is the operational process that takes a published fix and applies it across the estate, on a defined SLA, with verification. Often the weakest link: emergency patches collide with change windows, vendor compatibility, third-party dependencies. The audit always asks for the SLA, the exception list and the metrics.
Penetration testing
A penetration test is an authorised, scoped attack simulation to find exploitable weaknesses before real attackers do. Black box / grey box / white box, internal / external, application / infrastructure. Distinguish from a vulnerability scan (automated, breadth) and from a red team (multi-month, objective-based). Reports drive the remediation backlog.
Phishing
Phishing is the social-engineering attack that tricks a user into clicking a malicious link, opening a malicious file or revealing credentials. Variants: spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice), BEC (business email compromise). Training matters; phishing-resistant MFA matters more.
Privacy by design and by default
Privacy by design (GDPR Article 25) is the obligation to bake privacy controls into systems from the requirements stage. Privacy by default is the obligation to make the highest-protection option the standard. Auditors look for documented evidence (DPIA, design review, retention defaults) rather than a slogan in a policy.
PAM · Privileged Access Management
PAM is the subset of IAM focused on privileged accounts: admins, root, service accounts, break-glass. Vaults credentials, brokers sessions, records activity. The first thing the attacker goes for after the initial foothold, and the control auditors test hardest under NIS 2 and DORA.
PECB · Professional Evaluation and Certification Board
PECB is the Montreal-based accredited certification body that issues professional credentials on 30+ ISO standards across 150+ countries. Information security, risk, BCM, AI governance, privacy, quality. Cyber Academy is a PECB Gold Partner. The credentials carry PECB branding; the cohorts run through accredited partners.
Pseudonymisation
Pseudonymisation is the GDPR Article 4(5) technique of replacing direct identifiers with reversible tokens, with the key stored separately. Reduces risk and earns regulatory goodwill, but the data is still personal data. Anonymisation is the version that escapes GDPR entirely; pseudonymisation does not. Watch the conflation.
6 entries
Ransomware
Ransomware is the malware class that encrypts data and demands payment for the key, often paired with data theft and extortion (double extortion). Attack vectors: phishing, internet-facing exposure, supply chain. Insurance pays less, regulators scrutinise more. Pre-event work (backups, segmentation, IR plan) determines the outcome, not the negotiation.
ROPA · Record of Processing Activities
The ROPA is the documented inventory of processing activities required by GDPR Article 30. Controllers list purpose, categories, recipients, retention, transfers; processors list controllers served, categories, transfers. Most organisations underestimate the maintenance work. The supervisory authority asks for the ROPA first when an investigation starts.
RTO / RPO · Recovery Time and Recovery Point Objectives
RTO is the maximum acceptable duration a business process can stay down before unacceptable harm. RPO is the maximum data loss measured in time before the disruption. Both come out of the BIA. The numbers your CIO writes in the BCP without consulting the business are the numbers that fail under pressure.
Risk appetite
Risk appetite is the amount and type of risk the organisation is willing to take to meet its objectives. Set at executive or board level, in writing. Without it, every risk-treatment decision is a personal judgement call by the risk team, and the audit will tear it apart. Pair with risk tolerance (the deviation tolerated around the appetite).
Risk register
The risk register is the canonical, living list of identified risks with their analysis, evaluation, treatment and ownership. Not a one-time spreadsheet. Auditors expect dated entries, named owners, traceable changes and review cycles tied to management review. The board version is shorter; the operational version has everything.
Risk treatment
Risk treatment is what you do once you know the risk: avoid, reduce, transfer, accept. Each decision is documented, justified by the risk appetite, and traced through the SoA to the controls and the operating evidence. Most failed audits boil down to one thing: the treatment plan and reality drifted, nobody updated the SoA.
8 entries
SOC 2
SOC 2 is the AICPA attestation report on a service organisation's controls covering five trust criteria (security, availability, processing integrity, confidentiality, privacy). North-American canonical for SaaS vendors; ISO 27001 is the European equivalent. Type I = point-in-time; Type II = operating effectiveness over 6–12 months. Often demanded by enterprise procurement.
Schrems II
Schrems II is the 2020 CJEU judgement that struck down the EU-US Privacy Shield and added the Transfer Impact Assessment requirement. Every transfer to a third country now needs a documented analysis of local surveillance law and supplementary measures. Replaced in practice by the EU-US Data Privacy Framework (2023), but the TIA discipline stuck.
SIEM · Security Information and Event Management
A SIEM aggregates logs, normalises events and runs detection rules across your stack. The visibility layer the SOC depends on. Modern SIEM vendors (Splunk, Sentinel, Elastic, Sumo) increasingly bundle SOAR and UEBA. The hard work is not buying the SIEM; it is the data engineering and the detection-as-code pipeline that follows.
SOC · Security Operations Center
A SOC is the team and toolset that monitors, detects, analyses and responds to security events in real time. Tiered analysts (T1 detection, T2 investigation, T3 threat hunting), 8x5 or 24x7. Internal, outsourced (MSSP) or hybrid. Without a SOC the SIEM is a log archive; with one it is an early-warning system.
SOAR · Security Orchestration, Automation and Response
SOAR is the layer that takes SIEM alerts and runs playbooks: enrichment, triage, containment, ticketing. Goal: reduce MTTR and free analysts from copy-paste work. Watch for vendor over-promise: a SOAR is only as good as the playbooks you write and maintain. Most failed SOAR projects ran out of playbook authors.
Stage 1 / Stage 2 audit
Initial ISO certification splits into stage 1 (documentation and readiness review, usually 1–2 days) and stage 2 (operational evidence audit, 2–5 days). Stage 1 confirms the management system exists on paper; stage 2 verifies it actually operates. Most "failed" stage 2 audits are stage 1 problems that nobody fixed in between.
SCC · Standard Contractual Clauses
SCCs are the European Commission-approved template clauses for transferring personal data to third countries without an adequacy decision. The 2021 SCCs replaced the older versions and require a Transfer Impact Assessment (TIA) since Schrems II. Mandatory paperwork for anyone using non-EU SaaS providers.
SoA · Statement of Applicability
The SoA is the controlled document that tells the auditor which Annex A controls apply to you, why, where the evidence lives. Mandatory under ISO 27001. Inconsistency between SoA, risk treatment plan and actual operations is the most common cause of non-conformities at stage 2 audit.
3 entries
Tabletop exercise
A tabletop exercise is a discussion-based simulation of a disruptive scenario with the response team around a table. Cheap, fast, exposes the gaps no document review will. Required practice under ISO 22301, NIS 2 and DORA, and the single highest-ROI activity in a BCM programme. Schedule them quarterly, not annually.
TPRM · Third-Party Risk Management
TPRM is the discipline that governs the risk introduced by suppliers, subcontractors and service providers. Onboarding due diligence, contract clauses, ongoing assurance, off-boarding. Mandated by NIS 2 (supply chain security) and DORA (ICT third-party risk). The Crowdstrike outage, the SolarWinds incident, both made TPRM a board-level conversation.
TLPT · Threat-Led Penetration Testing
TLPT is the regulator-supervised red-team exercise required by DORA for significant financial entities. Built on the TIBER-EU framework (Threat Intelligence-Based Ethical Red Teaming). Multi-month, intelligence-driven, supervised by the national authority. The most rigorous test a CISO will face, and the one that exposes the SOC for what it really is.
Need the practical training?
A definition is the start. A certification is the proof.
Where a matching course exists, the entry links to training on the concept. Browse current options or ask us to map the closest path.