7. Glossary
Every technical and governance term used across this guide, in one place, cross-referenced back to where it's taught in depth.
Accountability — Ultimate ownership of an outcome, held by exactly one role. See 2.1.3.
Annualized Loss Expectancy (ALE) — Single Loss Expectancy × Annualized Rate of Occurrence; a quantitative risk estimate. See 3.1.3.
Annualized Rate of Occurrence (ARO) — The expected frequency of a loss event per year. See 3.1.3.
Asset Value (AV) — The monetary value of an asset, one of the two inputs to Single Loss Expectancy (AV × Exposure Factor). See 3.1.3.
Business Continuity Plan (BCP) — A plan for keeping critical business functions operating during any significant disruption. See 5.1.3.
Business Impact Analysis (BIA) — Identifies critical business processes and quantifies acceptable downtime (RTO) and data loss (RPO) for each. See 5.1.2.
CIA Triad — Confidentiality, Integrity, Availability — the three core objectives of information security. See 1.1.
COBIT — A governance framework linking IT goals to enterprise goals. See 2.2.2.
Compensating Control — A control that achieves equivalent risk reduction through a different mechanism when the primary control genuinely can't be applied. See 4.3.1.
Control Owner — The role responsible for implementing and operating a specific control. See 3.2.2.
Corrective Control — A control that limits damage and restores operation after an event. See 4.3.1.
Detective Control — A control that identifies an event that is occurring or has occurred. See 4.3.1.
Disaster Recovery Plan (DRP) — A plan for restoring IT systems and data to defined RTO/RPO targets. See 5.1.3.
Exposure Factor (EF) — The percentage of an asset's value a single occurrence of a risk event would destroy, the second input to Single Loss Expectancy. See 3.1.3.
Incident Classification — A documented scheme for categorizing security events by severity. See 5.1.4.
Incident Response Plan (IR Plan) — A plan for detecting, containing, and eradicating a security incident. See 5.1.1.
ISO/IEC 27001 — A certifiable information security management system (ISMS) standard. See 2.2.2, 4.1.3.
Key Risk Indicator (KRI) — A measurable signal that a risk's likelihood or impact is changing. See 3.2.3.
Maximum Tolerable Downtime (MTD) — Also called Maximum Acceptable Outage (MAO); the longest a process can be down before the business suffers unacceptable harm. RTO must be ≤ MTD. See 5.1.2.
NIST Cybersecurity Framework (CSF) — A voluntary, outcomes-based framework organized by function (Govern, Identify, Protect, Detect, Respond, Recover). See 2.2.2.
Preventive Control — A control that stops an event before it happens. See 4.3.1.
Recovery Point Objective (RPO) — The maximum acceptable data loss, measured in time. See 5.1.2.
Recovery Time Objective (RTO) — The maximum acceptable downtime for a business process. See 5.1.2.
Residual Risk — The risk that remains after a treatment has been applied. See 3.2.3.
Responsibility — Execution of work toward an outcome; can be shared across multiple roles. See 2.1.3.
Risk Appetite — The amount and type of risk an organization is willing to accept in pursuit of its objectives. See 2.2.1.
Risk Owner — The role accountable for a risk's business outcome and authorized to treat it. See 3.2.2.
ROSI (Return on Security Investment) — Expected loss reduced by a control, minus the control's cost. See 2.2.3.
Security Culture — The shared values, attitudes, and behaviors that shape how personnel act on security responsibilities. See 2.1.1.
Single Loss Expectancy (SLE) — The expected monetary loss from a single occurrence of a risk event. See 3.1.3.
Three Lines of Defense — A governance model: operational management (first line), risk/compliance functions (second line), internal audit (third line). See 2.1.3.