Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

ISO 27001 terms: an ISMS and Essential Eight glossary

Short answer

Forty-three terms buyers meet when preparing for ISO 27001 certification or an Essential Eight assessment, each in one to three sentences. Terms that come from a standard link to the publisher's page.

A

Accreditation
Formal recognition that a certification body is competent to certify against a standard. Buyers usually expect an ISO 27001 certificate from an accredited certification body.
Annex A
The annex of ISO/IEC 27001 that lists the reference set of information security controls. Organisations compare their chosen controls with it and record the result in the Statement of Applicability.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

Application control
An Essential Eight strategy that allows only approved applications to run on systems.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

B

Bring your own auditor (BYOA)
A platform option that lets you use an auditor you choose rather than one from the vendor's network. Sprinto lists it on its Foundation plan.

Source: Sprinto pricing · Read 29 Sep 2026

C

Certification body
The organisation that audits an ISMS and issues the ISO 27001 certificate. ISO publishes the standard but does not certify organisations.
Context of the organization (clause 4)
The ISO 27001 clause on understanding the organisation, its interested parties and their requirements, and setting the ISMS scope.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

Control
A measure that modifies risk, such as a policy, a process or a technical setting. In a compliance platform, a control is the unit that evidence attaches to.
Corrective action
Action to remove the cause of a nonconformity and prevent it from recurring, required by clause 10 of ISO 27001.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

CPS 234
APRA's prudential standard on information security for regulated entities in Australia. Vanta lists it among its frameworks.

Source: Vanta additional frameworks · Read 29 Sep 2026

Cross-mapping
Linking one control to the matching requirements in several frameworks so that one piece of evidence counts for all of them. Scytale states control cross-mapping across 80+ frameworks.

Source: Scytale all frameworks · Read 29 Sep 2026

D

Dedicated compliance expert
A named person on the vendor side who works with the customer through readiness and the audit. Scytale describes this model, with weekly meetings.

Source: Scytale compliance experts · Read 29 Sep 2026

E

Essential Eight
The eight mitigation strategies the Australian Signals Directorate describes as the most effective of its Strategies to mitigate cyber security incidents, with a maturity model first published in June 2017.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Essential Eight assessment process guide
ASD's guide that assessors use to assess implementation of the Essential Eight against the maturity model.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Essential Eight maturity model
ASD's model for describing how far each Essential Eight strategy is implemented. First published in June 2017 and updated regularly, with changes in the November 2023 release.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Evidence collection
Gathering proof that controls operate, such as configuration exports, access reviews and training records. Platforms automate much of it through integrations.

I

Information security goals
Measurable goals for information security that ISO 27001 clause 6 asks you to set and plan for. An Essential Eight maturity target can be one of them.
Information security management system (ISMS)
The policies, processes, roles and records an organisation uses to manage information security risk and improve over time. ISO/IEC 27001 sets the requirements for one.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

Information Security Manual (ISM)
ASD's cyber security framework of controls for Australian organisations. ASD maps the Essential Eight to ISM controls.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Internal audit
A planned check, required by clause 9 of ISO 27001, that the ISMS meets the standard and your own requirements, carried out by someone who does not audit their own work.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

ISO/IEC 27001:2022
The current edition of the ISMS requirements standard: Edition 3, published October 2022, 19 pages, with one amendment, maintained by ISO/IEC JTC 1/SC 27.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

ISO/IEC 27701
An ISO standard that extends an ISMS to privacy information management. Scytale lists it in its framework library.

Source: Scytale all frameworks · Read 29 Sep 2026

ISO/IEC 42001
The ISO management system standard for artificial intelligence. Scytale, Vanta and Drata list it among their frameworks.
ISO/IEC JTC 1/SC 27
The joint ISO and IEC committee responsible for ISO/IEC 27001 and related information security standards.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

M

Management review
A planned review by top management, required by clause 9, of how the ISMS is performing and what needs to change.
Multi-factor authentication
An Essential Eight strategy that requires more than one proof of identity before access is granted.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

N

Nonconformity
Failure to meet a requirement of the standard or of your own ISMS. Certification bodies grade them, and generally expect major nonconformities to be closed before certification.

P

Patch applications
An Essential Eight strategy covering the prompt application of security fixes to applications. A separate strategy covers operating systems.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

R

Regular backups
An Essential Eight strategy covering backups of important data, software and settings, with restores that are tested.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Residual risk
The risk that remains after treatment. Risk owners approve it as part of the risk treatment plan.
Restrict administrative privileges
An Essential Eight strategy that limits who holds administrative rights and what those accounts can do.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

Risk assessment
The ISO 27001 process of identifying, analysing and evaluating information security risks with a method that gives consistent, comparable results.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

Risk owner
The person accountable for managing a particular risk and approving its treatment.
Risk register
A record of identified risks with their owners, ratings and treatments. ISO 27001 does not name it, but most organisations keep one to evidence clause 6 and clause 8.
Risk treatment plan
The plan that sets out how each risk will be treated (reduce, avoid, share or accept), with controls, owners and dates.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

S

Scope statement
The documented boundary of the ISMS: which products, locations, teams and systems the certificate covers.
SOC 2
An examination performed by a licensed CPA firm under AICPA standards, reporting on controls relevant to security, availability, processing integrity, confidentiality or privacy.

Source: AICPA SOC suite of services · Read 29 Sep 2026

Stage 1 audit
A term certification bodies commonly use for the first part of an initial ISO 27001 certification audit, which reviews the ISMS design, documentation and readiness.
Stage 2 audit
A term certification bodies commonly use for the main part of an initial certification audit, which tests whether the ISMS operates as documented by interviewing staff and sampling evidence.
Statement of Applicability (SoA)
The document listing every Annex A control, whether it applies, the justification, and whether it is implemented.

Source: ISO/IEC 27001:2022 on iso.org · Read 29 Sep 2026

Surveillance audit
A periodic audit a certification body carries out after certification, sampling part of the ISMS to confirm it still conforms. The schedule is set by the certification body.

T

Trust center
A public or gated page where a company shares its certificates, policies and security answers with customers. All six vendors except Scrut describe one on the pages reviewed.

U

Unified or common control framework
A single control set mapped to many frameworks so that controls are set up once and reused. Sprinto calls its version a common control framework and Scrut a Unified Control Framework.

V

vCISO
A virtual chief information security officer: an outside security leader engaged part time. Vanta and Drata list vCISOs among their partners.