Glossary

Compliance and information security glossary

Plain-language definitions of the standards, controls and risk terms that come up in ISO 27001, NIS2, DORA, GDPR and EU AI Act work.

17 terms

C

Cloud Security

Cloud security covers every measure protecting data and applications in environments someone else operates. Its defining feature is shared responsibility: the provider secures the platform, while the customer owns configuration, identities, permissions and data. Outsourcing the operation does not move accountability to the provider.

ISMS

Compliance Risk

A compliance risk is the possibility that an organisation or its staff breach a binding obligation — a law, a supervisory requirement, a contract or a self-imposed rule — and that sanctions, liability, exclusion from public tenders or reputational damage follow. It is assessed against the obligations you have identified, not against instinct.

Risikomanagement

Concentration Risk

Concentration risk arises when dependencies bundle onto a few points — one provider, one technology, one site, one region. A single failure then does not stay local; it hits several processes at once. In the ICT context it is one of the reasons the EU put critical third-party providers under supervision at European level.

Risikomanagement

Critical Infrastructure (KRITIS)

Critical infrastructures — KRITIS in German usage — are organisations and facilities of essential importance to society whose failure would cause serious supply shortfalls or endanger public safety. In German law the concept is given shape by the BSI Act and the BSI-Kritisverordnung; what decides it is the sector and the threshold.

NIS2

Cryptography Policy

A cryptography policy sets out in writing where an organisation uses cryptographic methods, which methods are approved, and how keys are managed across their entire life cycle. The policy is the decision layer above any individual piece of encryption, and the document an auditor asks for before looking at a single system.

ISMS