Compliance and information security glossary
Plain-language definitions of the standards, controls and risk terms that come up in ISO 27001, NIS2, DORA, GDPR and EU AI Act work.
C
Cloud Security
Cloud security covers every measure protecting data and applications in environments someone else operates. Its defining feature is shared responsibility: the provider secures the platform, while the customer owns configuration, identities, permissions and data. Outsourcing the operation does not move accountability to the provider.
ISMSCompliance Risk
A compliance risk is the possibility that an organisation or its staff breach a binding obligation — a law, a supervisory requirement, a contract or a self-imposed rule — and that sanctions, liability, exclusion from public tenders or reputational damage follow. It is assessed against the obligations you have identified, not against instinct.
RisikomanagementConcentration Risk
Concentration risk arises when dependencies bundle onto a few points — one provider, one technology, one site, one region. A single failure then does not stay local; it hits several processes at once. In the ICT context it is one of the reasons the EU put critical third-party providers under supervision at European level.
RisikomanagementCritical Infrastructure (KRITIS)
Critical infrastructures — KRITIS in German usage — are organisations and facilities of essential importance to society whose failure would cause serious supply shortfalls or endanger public safety. In German law the concept is given shape by the BSI Act and the BSI-Kritisverordnung; what decides it is the sector and the threshold.
NIS2Cryptography Policy
A cryptography policy sets out in writing where an organisation uses cryptographic methods, which methods are approved, and how keys are managed across their entire life cycle. The policy is the decision layer above any individual piece of encryption, and the document an auditor asks for before looking at a single system.
ISMSD
Data Minimisation
Data minimisation is the principle of processing personal data only to the extent actually necessary for the specified purpose. It limits the volume of the data, their granularity, the circle of people with access to them, and how long they are kept. It applies even where a legal basis exists and the data are well protected.
DSGVOData Residency
Data residency is the geographic place where data is stored and processed. It is steered through the choice of region, through location commitments and through contractual terms. Three things have to be told apart: the place of storage, the place of access, and the legal orders the provider is subject to. Only together do they give a defensible picture.
ISMSI
Information Security Objectives
Information security objectives are the measurable intentions an organisation sets for what its ISMS is to achieve. ISO/IEC 27001 requires them in clause 6.2 at the relevant functions and levels: consistent with the policy, measurable where practicable, monitored, communicated, updated, and available as documented information.
ISMSInternal Audit
An internal audit is the systematic, independently conducted and documented examination of whether a management system meets the organisation’s own requirements and those of the underlying standard, and is effectively implemented. ISO/IEC 27001 requires it in clause 9.2 at planned intervals. The organisation itself is responsible for it, not the certification body.
ISO 27001M
Management System
A management system is the documented framework of policy, objectives, roles, processes and evidence with which an organisation steers and improves one subject deliberately. The ISO standards for information security, business continuity, compliance and quality share the same base structure, which is what makes running several systems together possible.
GRCMulti-Factor Authentication (MFA)
Multi-factor authentication requires at least two pieces of proof from different categories for a sign-in: knowledge, possession or a biometric trait. A stolen password alone is then no longer enough to get in. Two pieces of proof from the same category (a password and a security question, say) are not multi-factor authentication.
ISMSP
Phishing Simulation
A phishing simulation is a controlled campaign, run by the organisation itself, in which employees receive messages modelled on genuine phishing attempts. Its purpose is to practise recognising and, above all, reporting suspicious messages. In Germany the design has to be assessed under employment and data protection law before the first campaign.
ISMSPolicy and Procedure
A policy sets out bindingly what is to apply and who is responsible for it. A procedure describes how an activity runs in detail. Both sit in a hierarchy below the top-level policy issued by management and above the work instructions. Drawing the line cleanly determines how often a document has to be re-approved.
GRC