Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

7. Glossary

Every technical and governance term used across this guide, in one place, cross-referenced back to where it's taught in depth.

Accountability — Ultimate ownership of an outcome, held by exactly one role. See 2.1.3.

Annualized Loss Expectancy (ALE) — Single Loss Expectancy × Annualized Rate of Occurrence; a quantitative risk estimate. See 3.1.3.

Annualized Rate of Occurrence (ARO) — The expected frequency of a loss event per year. See 3.1.3.

Asset Value (AV) — The monetary value of an asset, one of the two inputs to Single Loss Expectancy (AV × Exposure Factor). See 3.1.3.

Business Continuity Plan (BCP) — A plan for keeping critical business functions operating during any significant disruption. See 5.1.3.

Business Impact Analysis (BIA) — Identifies critical business processes and quantifies acceptable downtime (RTO) and data loss (RPO) for each. See 5.1.2.

CIA Triad — Confidentiality, Integrity, Availability — the three core objectives of information security. See 1.1.

COBIT — A governance framework linking IT goals to enterprise goals. See 2.2.2.

Compensating Control — A control that achieves equivalent risk reduction through a different mechanism when the primary control genuinely can't be applied. See 4.3.1.

Control Owner — The role responsible for implementing and operating a specific control. See 3.2.2.

Corrective Control — A control that limits damage and restores operation after an event. See 4.3.1.

Detective Control — A control that identifies an event that is occurring or has occurred. See 4.3.1.

Disaster Recovery Plan (DRP) — A plan for restoring IT systems and data to defined RTO/RPO targets. See 5.1.3.

Exposure Factor (EF) — The percentage of an asset's value a single occurrence of a risk event would destroy, the second input to Single Loss Expectancy. See 3.1.3.

Incident Classification — A documented scheme for categorizing security events by severity. See 5.1.4.

Incident Response Plan (IR Plan) — A plan for detecting, containing, and eradicating a security incident. See 5.1.1.

ISO/IEC 27001 — A certifiable information security management system (ISMS) standard. See 2.2.2, 4.1.3.

Key Risk Indicator (KRI) — A measurable signal that a risk's likelihood or impact is changing. See 3.2.3.

Maximum Tolerable Downtime (MTD) — Also called Maximum Acceptable Outage (MAO); the longest a process can be down before the business suffers unacceptable harm. RTO must be ≤ MTD. See 5.1.2.

NIST Cybersecurity Framework (CSF) — A voluntary, outcomes-based framework organized by function (Govern, Identify, Protect, Detect, Respond, Recover). See 2.2.2.

Preventive Control — A control that stops an event before it happens. See 4.3.1.

Recovery Point Objective (RPO) — The maximum acceptable data loss, measured in time. See 5.1.2.

Recovery Time Objective (RTO) — The maximum acceptable downtime for a business process. See 5.1.2.

Residual Risk — The risk that remains after a treatment has been applied. See 3.2.3.

Responsibility — Execution of work toward an outcome; can be shared across multiple roles. See 2.1.3.

Risk Appetite — The amount and type of risk an organization is willing to accept in pursuit of its objectives. See 2.2.1.

Risk Owner — The role accountable for a risk's business outcome and authorized to treat it. See 3.2.2.

ROSI (Return on Security Investment) — Expected loss reduced by a control, minus the control's cost. See 2.2.3.

Security Culture — The shared values, attitudes, and behaviors that shape how personnel act on security responsibilities. See 2.1.1.

Single Loss Expectancy (SLE) — The expected monetary loss from a single occurrence of a risk event. See 3.1.3.

Three Lines of Defense — A governance model: operational management (first line), risk/compliance functions (second line), internal audit (third line). See 2.1.3.

Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications