The risk metrics in the second table are only useful together, so each entry says where it sits in the calculation rather than defining it alone. The agreement types in the third are tested by scenario - which document covers this situation - rather than by expansion.
Governance and continuity
| Acronym | Expands to | What it is | Worth knowing |
|---|---|---|---|
| GRC | Governance, Risk and Compliance | The three functions run as one | They overlap because the same evidence serves all three. Run separately, an organisation collects it three times and gives three answers about one control. |
| BIA | Business Impact Analysis | What the consequence is of a process stopping | The recovery objectives come out of it. An organisation that starts from what its backups can achieve has documented a capability rather than set a requirement. |
| BCP | Business Continuity Plan | How the organisation keeps functioning during disruption | Includes manual workarounds, premises and communications. Recovering every system correctly while nobody knows what to do for six hours is still a failure. |
| DRP | Disaster Recovery Plan | How the technology is restored | The subset of continuity that restores systems. Recovery order comes from dependencies, not from how important a system feels. |
| COOP | Continuity of Operations Plan | The continuity plan under its government name | |
| CISO | Chief Information Security Officer | The executive accountable for the security programme | Accountability does not transfer. A function can be outsourced and the answer for it cannot. |
| ISMS | Information Security Management System | The documented system of policy, roles, risk process and review | What ISO 27001 certifies. The certificate is for the system, not for any particular control being present. |
| ITIL | Information Technology Infrastructure Library | The service management framework change management comes from | Where the change advisory board, the request for change and the maintenance window originate. |
| COBIT | Control Objectives for Information and Related Technologies | A governance framework aimed at the board rather than the engineer | Answers whether IT serves the business, where NIST CSF and ISO 27001 answer whether it is secure. |
| CBT | Computer-Based Training | Self-paced training modules | Covers the syllabus and evidences completion. It changes behaviour far less than simulated phishing and role-based practice, which is the point most awareness questions turn on. |
Risk metrics
| Acronym | Expands to | What it is | Where it sits |
|---|---|---|---|
| AV | Asset Value | What the thing is worth | First term of the chain. |
| EF | Exposure Factor | The proportion destroyed by one event | AV x EF = SLE. |
| SLE | Single Loss Expectancy | What one occurrence costs | SLE x ARO = ALE. |
| ARO | Annual Rate of Occurrence | How many times a year it is expected | Often less than one, which is normal. It is the weakest input in the calculation and frequently a guess. |
| ALE | Annualised Loss Expectancy | The expected annual cost of the risk left untreated | What the cost of a control is compared against. A precise-looking figure can rest on three estimates. |
| RTO | Recovery Time Objective | How long the service may be down | Looks forward from the failure. Met by standby capacity and restore speed. |
| RPO | Recovery Point Objective | How much data may be lost, expressed as time | Looks backward from the failure. Met by copy frequency. A design can satisfy one of these and fail the other completely. |
| MTD | Maximum Tolerable Downtime | The point past which the damage cannot be recovered from | RTO is set below it deliberately, leaving margin. |
| MTTR | Mean Time To Repair | How long the fixing takes on average | Feeds the RTO the organisation can honestly commit to. |
| MTBF | Mean Time Between Failures | How often a repairable system fails | Between implies repair. A non-repairable item gets mean time to failure instead, which is what drive figures actually are. |
| KRI | Key Risk Indicator | Something measurable that moves before the risk does | What turns a register from a record into something that reacts between reviews. |
| ROI | Return on Investment | What the spending returns | Applied to a control it becomes ROSI, where the return is a loss that did not happen. |
| ROSI | Return on Security Investment | The reduction in ALE set against the cost of the control | A control costing more than the ALE it removes is not a security decision, it is a bad one - which is why the calculation is done before the purchase. |
Agreements and third parties
| Acronym | Expands to | What it is | Worth knowing |
|---|---|---|---|
| SLA | Service Level Agreement | Committed performance, and the credits owed when it is missed | Commits the provider to a number. It does not commit them to a security posture unless that is written in as well. |
| MOU | Memorandum of Understanding | A statement of intent | Not legally binding, which is the whole point of the distinction. |
| MOA | Memorandum of Agreement | A more formal commitment than an MOU | |
| MSA | Master Service Agreement | The umbrella terms for an ongoing relationship | Individual pieces of work are ordered under it by a statement of work, so the terms are negotiated once. |
| SOW | Statement of Work | What will be delivered, when, and for how much | |
| NDA | Non-Disclosure Agreement | An obligation not to reveal confidential information | |
| BPA | Business Partners Agreement | How partners divide revenue, liability and responsibility | |
| ISA | Interconnection Security Agreement | Governs a direct technical connection between two organisations | The clause most often left out is how the connection is terminated when the relationship ends. |
| CAIQ | Consensus Assessments Initiative Questionnaire | The standard cloud vendor security questionnaire | A self-assessment, so it is the weakest evidence in the hierarchy - useful as a filter rather than as assurance. |
| CCM | Cloud Controls Matrix | The control framework the CAIQ maps to | |
| CSA | Cloud Security Alliance | The body that publishes the CCM and the CAIQ | |
| QSA | Qualified Security Assessor | The assessor PCI DSS requires at higher merchant levels | |
| SAQ | Self-Assessment Questionnaire | How a smaller merchant validates PCI DSS compliance | The requirements are identical whichever route is used. Only the evidence differs. |
| CDE | Cardholder Data Environment | Everything that stores, processes or transmits card data | Scope is the whole game. Segmentation that genuinely isolates the CDE takes the rest of the network out of the audit. |
| PTES | Penetration Testing Execution Standard | A methodology for how an engagement is run and reported | What makes a test repeatable rather than dependent on the individual tester. OSSTMM and the OWASP Testing Guide serve the same purpose. |
Standards, regulations and privacy
| Acronym | Expands to | What it is | Worth knowing |
|---|---|---|---|
| SOC 2 | System and Organization Controls 2 | An audit report on a service provider's controls | Nothing to do with a security operations centre. Type I is a point in time; Type II covers a period, which is why customers ask for Type II. |
| ISO 27001 | International Organization for Standardization 27001 | The certifiable information security management standard | Certification requires a management system and a justified selection of controls, not every control applied. |
| CSF | Cybersecurity Framework | The NIST framework organising security activity into functions | Govern, Identify, Protect, Detect, Respond, Recover. Voluntary, and adopted far outside the US federal sector. |
| PCI DSS | Payment Card Industry Data Security Standard | Requirements for handling payment card data | Applies at any volume. Transaction count decides how compliance is validated, not whether it applies. Contractual rather than statutory, published by the PCI Security Standards Council (SSC) rather than by a legislature. |
| GDPR | General Data Protection Regulation | The EU data protection regulation | 72 hours to notify the supervisory authority of a qualifying breach, counted from becoming aware of it. |
| HIPAA | Health Insurance Portability and Accountability Act | US protection of health information | |
| SOX | Sarbanes-Oxley Act | US financial reporting controls | Why change management and separation of duties are audited in systems that never touch money directly. |
| GLBA | Gramm-Leach-Bliley Act | US financial institution customer data protection | |
| DPIA | Data Protection Impact Assessment | Required before high-risk processing begins | Assesses harm to the data subject, not cost to the organisation, which is the opposite direction from an ordinary risk assessment. Done beforehand, or it documents a decision already taken. |
| DPO | Data Protection Officer | The role accountable for privacy compliance | |
| PII | Personally Identifiable Information | Data that identifies a person on its own or combined | Combined is the hard part. Fields that identify nobody alone identify one person together, which is why removing the name is not anonymisation. |
| PHI | Protected Health Information | Health data tied to an identifiable person, under HIPAA | |
| SSN | Social Security Number | The US national identifier | A permanent identifier that cannot be reissued, which is why its exposure is treated more seriously than a card number that can be replaced. |
| CCPA | California Consumer Privacy Act | State privacy law with GDPR-like rights | Applies by where the consumer is, not by where the company is - which is how a business with no California presence ends up in scope. |
| HITECH | Health Information Technology for Economic and Clinical Health Act | Added breach notification and stronger penalties to HIPAA | |
| DPA | Data Processing Agreement | The contract binding a processor to the controller's instructions | The controller stays accountable for the processor's handling, so this is where that responsibility is written down. |
| PIA | Privacy Impact Assessment | The broader assessment a DPIA is the high-risk form of | |
| RTBF | Right To Be Forgotten | The data subject's right to erasure | Runs straight into backups and immutable storage, which is why the answer is usually a documented retention period rather than a deletion on demand. |
| PIMS | Privacy Information Management System | ISO 27701, the privacy extension to an ISMS | |
| FISMA | Federal Information Security Modernization Act | Security requirements for US federal systems | Where NIST SP 800-53 becomes mandatory rather than advisory. |
The bodies and the documents they publish
| Acronym | Expands to | What it is | Worth knowing |
|---|---|---|---|
| NIST | National Institute of Standards and Technology | The US body behind the CSF, the SP 800 series and FIPS | Publishes guidance, not law. It becomes binding through FISMA for federal systems and through contracts for everybody else. |
| SP | Special Publication | The NIST document series security guidance lives in | SP 800-53 is the federal control catalogue, 800-171 covers controlled information at contractors, 800-61 is incident handling and 800-37 is the risk management framework. |
| ISO | International Organization for Standardization | The international standards body | 27001 certifies the management system, 27002 is the guidance on controls, 27701 covers privacy and 22301 covers business continuity. |
| RFC | Request for Comments | The document series internet protocols are defined in | Despite the name these are the specifications themselves, not proposals. |
| DISA | Defense Information Systems Agency | The US defence body that publishes the STIGs | |
| CISA | Cybersecurity and Infrastructure Security Agency | The US agency that publishes the KEV catalogue and advisories | Collides with the CISA certification, which is Certified Information Systems Auditor. Unrelated. |