ISO 27001 terms: an ISMS and Essential Eight glossary
Forty-three terms buyers meet when preparing for ISO 27001 certification or an Essential Eight assessment, each in one to three sentences. Terms that come from a standard link to the publisher's page.
A
- Accreditation
- Formal recognition that a certification body is competent to certify against a standard. Buyers usually expect an ISO 27001 certificate from an accredited certification body.
- Annex A
- The annex of ISO/IEC 27001 that lists the reference set of information security controls. Organisations compare their chosen controls with it and record the result in the Statement of Applicability.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- Application control
- An Essential Eight strategy that allows only approved applications to run on systems.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
B
- Bring your own auditor (BYOA)
- A platform option that lets you use an auditor you choose rather than one from the vendor's network. Sprinto lists it on its Foundation plan.
Source: Sprinto pricing · Read 29 Sep 2026
C
- Certification body
- The organisation that audits an ISMS and issues the ISO 27001 certificate. ISO publishes the standard but does not certify organisations.
- Context of the organization (clause 4)
- The ISO 27001 clause on understanding the organisation, its interested parties and their requirements, and setting the ISMS scope.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- Control
- A measure that modifies risk, such as a policy, a process or a technical setting. In a compliance platform, a control is the unit that evidence attaches to.
- Corrective action
- Action to remove the cause of a nonconformity and prevent it from recurring, required by clause 10 of ISO 27001.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- CPS 234
- APRA's prudential standard on information security for regulated entities in Australia. Vanta lists it among its frameworks.
Source: Vanta additional frameworks · Read 29 Sep 2026
- Cross-mapping
- Linking one control to the matching requirements in several frameworks so that one piece of evidence counts for all of them. Scytale states control cross-mapping across 80+ frameworks.
Source: Scytale all frameworks · Read 29 Sep 2026
D
- Dedicated compliance expert
- A named person on the vendor side who works with the customer through readiness and the audit. Scytale describes this model, with weekly meetings.
Source: Scytale compliance experts · Read 29 Sep 2026
E
- Essential Eight
- The eight mitigation strategies the Australian Signals Directorate describes as the most effective of its Strategies to mitigate cyber security incidents, with a maturity model first published in June 2017.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Essential Eight assessment process guide
- ASD's guide that assessors use to assess implementation of the Essential Eight against the maturity model.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Essential Eight maturity model
- ASD's model for describing how far each Essential Eight strategy is implemented. First published in June 2017 and updated regularly, with changes in the November 2023 release.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Evidence collection
- Gathering proof that controls operate, such as configuration exports, access reviews and training records. Platforms automate much of it through integrations.
I
- Information security goals
- Measurable goals for information security that ISO 27001 clause 6 asks you to set and plan for. An Essential Eight maturity target can be one of them.
- Information security management system (ISMS)
- The policies, processes, roles and records an organisation uses to manage information security risk and improve over time. ISO/IEC 27001 sets the requirements for one.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- Information Security Manual (ISM)
- ASD's cyber security framework of controls for Australian organisations. ASD maps the Essential Eight to ISM controls.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Internal audit
- A planned check, required by clause 9 of ISO 27001, that the ISMS meets the standard and your own requirements, carried out by someone who does not audit their own work.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- ISO/IEC 27001:2022
- The current edition of the ISMS requirements standard: Edition 3, published October 2022, 19 pages, with one amendment, maintained by ISO/IEC JTC 1/SC 27.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- ISO/IEC 27701
- An ISO standard that extends an ISMS to privacy information management. Scytale lists it in its framework library.
Source: Scytale all frameworks · Read 29 Sep 2026
- ISO/IEC 42001
- The ISO management system standard for artificial intelligence. Scytale, Vanta and Drata list it among their frameworks.
- ISO/IEC JTC 1/SC 27
- The joint ISO and IEC committee responsible for ISO/IEC 27001 and related information security standards.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
M
- Management review
- A planned review by top management, required by clause 9, of how the ISMS is performing and what needs to change.
- Multi-factor authentication
- An Essential Eight strategy that requires more than one proof of identity before access is granted.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
N
- Nonconformity
- Failure to meet a requirement of the standard or of your own ISMS. Certification bodies grade them, and generally expect major nonconformities to be closed before certification.
P
- Patch applications
- An Essential Eight strategy covering the prompt application of security fixes to applications. A separate strategy covers operating systems.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
R
- Regular backups
- An Essential Eight strategy covering backups of important data, software and settings, with restores that are tested.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Residual risk
- The risk that remains after treatment. Risk owners approve it as part of the risk treatment plan.
- Restrict administrative privileges
- An Essential Eight strategy that limits who holds administrative rights and what those accounts can do.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
- Risk assessment
- The ISO 27001 process of identifying, analysing and evaluating information security risks with a method that gives consistent, comparable results.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- Risk owner
- The person accountable for managing a particular risk and approving its treatment.
- Risk register
- A record of identified risks with their owners, ratings and treatments. ISO 27001 does not name it, but most organisations keep one to evidence clause 6 and clause 8.
- Risk treatment plan
- The plan that sets out how each risk will be treated (reduce, avoid, share or accept), with controls, owners and dates.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
S
- Scope statement
- The documented boundary of the ISMS: which products, locations, teams and systems the certificate covers.
- SOC 2
- An examination performed by a licensed CPA firm under AICPA standards, reporting on controls relevant to security, availability, processing integrity, confidentiality or privacy.
Source: AICPA SOC suite of services · Read 29 Sep 2026
- Stage 1 audit
- A term certification bodies commonly use for the first part of an initial ISO 27001 certification audit, which reviews the ISMS design, documentation and readiness.
- Stage 2 audit
- A term certification bodies commonly use for the main part of an initial certification audit, which tests whether the ISMS operates as documented by interviewing staff and sampling evidence.
- Statement of Applicability (SoA)
- The document listing every Annex A control, whether it applies, the justification, and whether it is implemented.
Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026
- Surveillance audit
- A periodic audit a certification body carries out after certification, sampling part of the ISMS to confirm it still conforms. The schedule is set by the certification body.
T
- Trust center
- A public or gated page where a company shares its certificates, policies and security answers with customers. All six vendors except Scrut describe one on the pages reviewed.
U
- Unified or common control framework
- A single control set mapped to many frameworks so that controls are set up once and reused. Sprinto calls its version a common control framework and Scrut a Unified Control Framework.
V
- vCISO
- A virtual chief information security officer: an outside security leader engaged part time. Vanta and Drata list vCISOs among their partners.