GLOSSARY
The vocabulary of cyber governance, defined the way practitioners use it.
Each entry opens with a definition you can quote, then says what the term changes in practice and where it meets the regulations. Written by the team that builds the platform, kept current with the texts.
Governance
-
Cyber risk appetite
Cyber risk appetite is the level of cyber risk a board agrees to carry, written as thresholds a risk can be measured against and breach.
-
Cyber-GRC
Cyber-GRC is the discipline that runs cybersecurity governance, risk and compliance as one system: one set of facts, verified, behind every decision.
-
GRCOps
GRCOps runs governance, risk and compliance as a continuous operation: gaps caught as they open, owned actions, closure verified by evidence.
-
Security by Design
Security by Design builds security requirements into a project from its first decision, proportionate to its risk, instead of auditing it at the end.
-
Security exception (derogation)
A security exception, or derogation, is a formal, time-boxed acceptance of a gap against policy, with an owner, compensating controls and an expiry.
Risk
-
Business Impact Analysis (BIA)
A BIA rates what the loss of each business activity would cost over time, giving the recovery objectives and the criticality every cyber risk inherits.
-
Cyber risk register
A cyber risk register lists an organization’s cyber risks with their owner, scores, controls and treatment, so they can be compared, decided and tracked.
-
EBIOS Risk Manager
EBIOS Risk Manager is ANSSI’s cyber risk analysis method: five workshops from the feared events to the treatment plan, built around the ecosystem.
-
Inherent, residual and target risk
Inherent risk is the exposure before controls, residual risk what remains with the controls that operate, target risk what the treatment plan aims for.
-
Key Risk Indicator (KRI)
A KRI is a measurable signal that a cyber risk is growing, read against a threshold set by the risk appetite, so leadership acts before the loss.
Compliance
-
Continuous compliance
Continuous compliance verifies controls against fresh evidence all year, across frameworks mapped once: the audit reads the state instead of rebuilding it.
-
Continuous Controls Monitoring (CCM)
CCM tests controls on a set cadence against evidence, automated where a source exists and reviewed otherwise; each failure becomes an owned finding.
-
ISO/IEC 27001
ISO/IEC 27001 is the international standard for an information security management system, certified by audit on a three-year cycle, 93 reference controls.
-
SOC 2
SOC 2 is an attestation report by an independent CPA on a service provider’s controls against the Trust Services Criteria, over a period for Type II.
Third parties
-
Register of information (DORA)
The DORA register of information is the inventory of every ICT service contract a financial entity holds, kept current and reported to its supervisor.
-
Third-Party Risk Management (TPRM)
TPRM is the program that inventories, tiers, assesses, monitors and remediates the cyber risk an organization inherits from its suppliers and partners.
-
Trust Grade (Mindlapse)
The Mindlapse Trust Grade blends a supplier’s assessments, the business impact of its service and external ratings into one letter, computed in the open.
Regulations
-
Cyber Resilience Act (CRA)
The CRA is the EU regulation that imposes security-by-design, vulnerability handling and reporting duties on products with digital elements sold in the EU.
-
DORA (Digital Operational Resilience Act)
DORA is the EU regulation on the digital operational resilience of financial entities: ICT risk, incidents, testing, third-party risk, information sharing.
-
EU AI Act
The EU AI Act is the regulation that classifies AI systems by risk and sets the obligations of providers and deployers, up to the high-risk duties.
-
NIS2 Directive
NIS2 is the EU directive that sets cybersecurity risk-management and incident-reporting duties for essential and important entities in 18 sectors.
SEE IT VERIFIED
Definitions are the easy part. Proving them is the product.
Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.