Skip to main content
Guide · Updated

ISO 27001 terminology glossary

A plain-English guide to the words that connect assets, threats, vulnerabilities, risks, controls and the ISMS. Each entry gives a direct definition, explains why the term matters and separates it from the idea learners most often confuse it with.
Prepared by Aegentra Academy · Version 1.0 · Substantively reviewed by Harry Sidhu on 2 September 202614 min read

Direct definition

What is the ISO 27001 terminology glossary?

It is an Aegentra-authored learning aid that translates common information security and management-system terms into plain English. It is designed to help a learner explain how the concepts relate; it is not an official vocabulary standard and does not replace the wording in ISO's published documents.

Purpose: build precise language before working with risks, controls, audits or corrective actions. If two people use “risk”, “issue” and “finding” for the same thing, their records and decisions will drift even when their templates look consistent.

Visible preview

Read the risk sentence from left to right

A useful risk statement connects the concepts instead of listing them in separate columns with no story. Start with value, describe a plausible path to consequence, then show the decision used to change and monitor the risk.

1 · Asset

Something valuable or a service dependency

2 · Threat

A possible cause of an unwanted event

3 · Vulnerability

A weakness that makes the event plausible

4 · Risk

Uncertainty and consequence for an objective

5 · Control

A measure selected to change the risk

Consequence and likelihood support analysis; a risk owner makes or escalates the treatment and acceptance decision; evidence helps show whether the chosen controls operate and change the risk as intended.

30 study terms

Plain-English ISO 27001 definitions

Download the glossary CSV

These definitions are intentionally explanatory rather than word-for-word reproductions. The source family on each card points to the place to verify the authoritative term.

Security outcome

What is valuable and which properties information security is trying to preserve.

Information

Security outcome

Meaning communicated or represented through data, records, conversations, images, code or another form.

Why it matters
The ISMS protects information across its lifecycle, not just files stored in an IT system.
Do not confuse it with
Do not reduce information to electronic data; spoken, printed and observed information can also need protection.

Source family · ISO/IEC 27000 family

Asset

Security outcome

Something valuable to the organisation, or something on which valuable information and services depend.

Why it matters
Assets give risk scenarios a concrete object: information, people, applications, infrastructure, suppliers, facilities or reputation.
Do not confuse it with
An asset is not always a device. A customer dataset, service, relationship or specialist skill can be an asset.

Source family · ISO/IEC 27002:2022

Information security

Security outcome

Protecting the confidentiality, integrity and availability of information, with other properties considered where relevant.

Why it matters
It states the outcome the ISMS is designed to preserve.
Do not confuse it with
Information security is broader than cybersecurity and broader than preventing data breaches.

Source family · ISO/IEC 27000 family

Confidentiality

Security outcome

Keeping information from being made available or disclosed to people, systems or processes that are not authorised to receive it.

Why it matters
It helps teams consider access, disclosure, sharing, storage and disposal risks.
Do not confuse it with
Confidential does not mean secret from everyone; authorised access is part of the design.

Source family · ISO Online Browsing Platform

Integrity

Security outcome

Keeping information accurate and complete, and protecting it from unauthorised or unintended change.

Why it matters
It directs attention to correctness, approved changes, processing logic and trusted records.
Do not confuse it with
Integrity is not personal honesty in this context; it concerns the accuracy and completeness of information.

Source family · ISO Online Browsing Platform

Availability

Security outcome

Ensuring authorised users and processes can reach and use information or services when they need them.

Why it matters
It connects resilience, capacity, recovery, suppliers and continuity to information security.
Do not confuse it with
Availability does not require every system to run continuously; the required level comes from business and stakeholder needs.

Source family · ISO Online Browsing Platform

Risk relationship

How a plausible event moves from an asset and weakness to consequence, decision and control.

Threat

Risk relationship

A potential cause of an unwanted event that could harm an asset, service or security objective.

Why it matters
Threats help describe what might happen: phishing, fire, malicious action, human error or supplier failure.
Do not confuse it with
A threat is not the weakness it may exploit and is not the resulting business risk.

Source family · ISO/IEC 27002:2022

Vulnerability

Risk relationship

A weakness in an asset, control, process or environment that a threat can exploit or trigger.

Why it matters
Vulnerabilities explain why a threat could produce a consequence in this organisation.
Do not confuse it with
A vulnerability is not automatically a risk; combine it with a plausible threat, affected objective and consequence.

Source family · ISO/IEC 27002:2022

Event

Risk relationship

An occurrence or change in circumstances. An event may be expected or unexpected and may include something failing to happen.

Why it matters
Events provide the trigger in a scenario, such as a credential being stolen or a backup job not completing.
Do not confuse it with
Not every event is an incident. Significance and impact determine how it is classified and handled.

Source family · ISO/IEC 27005 and ISO/IEC 27000 family

Consequence

Risk relationship

The effect on objectives if an event occurs, such as service interruption, inaccurate records, disclosure, cost or loss of trust.

Why it matters
Consequences let the organisation compare security scenarios in business terms.
Do not confuse it with
Consequence is the outcome, not the event that causes it. One event can produce several consequences.

Source family · ISO/IEC 27005:2022

Likelihood

Risk relationship

How possible or probable an event is under the organisation’s defined assessment method.

Why it matters
Likelihood combines with consequence and the chosen method to support consistent prioritisation.
Do not confuse it with
Labels such as “possible” are meaningless until the organisation defines their frequency or probability ranges.

Source family · ISO/IEC 27005:2022

Information security risk

Risk relationship

Uncertainty that can affect information security objectives, described through scenarios, likelihood and consequences using the organisation’s chosen method.

Why it matters
Risk is the decision unit used to prioritise treatment, acceptance, communication and monitoring.
Do not confuse it with
A missing control is not a complete risk statement. State what might happen, why, what is affected and what the consequence would be.

Source family · ISO/IEC 27005:2022

Risk assessment

Risk relationship

The structured work of identifying risks, analysing their characteristics and evaluating them against defined criteria.

Why it matters
It produces prioritised, explainable decisions rather than an unranked list of security concerns.
Do not confuse it with
Assessment decides what the risk means; treatment decides what to do about it.

Source family · ISO/IEC 27005:2022

Risk treatment

Risk relationship

Selecting and implementing an approach that changes a risk, such as reducing, avoiding, sharing or knowingly retaining it.

Why it matters
Treatment turns a prioritised risk into an owned decision, controls, actions and a target result.
Do not confuse it with
Treatment is not always adding technology. Process, people, contracts and scope decisions may also change risk.

Source family · ISO/IEC 27005:2022

Risk owner

Risk relationship

The person or role with authority and accountability to manage a particular risk.

Why it matters
The owner makes or escalates treatment and acceptance decisions and tracks the risk over time.
Do not confuse it with
The risk owner is not automatically the person who operates a control or administers the risk register.

Source family · ISO/IEC 27005 and ISO 31000

Control

Risk relationship

A measure that changes risk, including a policy, process, practice, contract, technology or other action.

Why it matters
Controls are selected to help achieve treatment and information security objectives.
Do not confuse it with
A control can be designed well but operate poorly. Design, implementation and effectiveness are separate questions.

Source family · ISO/IEC 27000 family

Inherent risk

Risk relationship

A commonly used practitioner view of exposure before the controls being assessed are taken into account.

Why it matters
It can show the scale of the underlying scenario and support treatment prioritisation.
Do not confuse it with
Define the term in your method. Organisations calculate it differently, and ISO/IEC 27001 does not prescribe one universal formula.

Source family · Organisation-defined risk methodology

Residual risk

Risk relationship

The risk remaining after treatment and relevant controls are considered.

Why it matters
It supports acceptance, further treatment and monitoring decisions.
Do not confuse it with
Residual risk is rarely zero. Record who accepts it and under what criteria, rather than assuming controls remove all uncertainty.

Source family · ISO/IEC 27005:2022

Management system

The boundary, governance and controlled information that make security repeatable.

ISMS

Management system

The coordinated policies, roles, processes, resources and records an organisation uses to manage information security risk and improve outcomes.

Why it matters
An ISMS makes information security governable, repeatable, measurable and improvable.
Do not confuse it with
An ISMS is not a software product and is not the same as a collection of security tools.

Source family · ISO/IEC 27000:2026 and ISO/IEC 27001:2022

Context of the organisation

Management system

The internal and external conditions that can affect what the ISMS is expected to achieve.

Why it matters
Context explains why the scope, priorities, risks and management approach fit this organisation.
Do not confuse it with
It is not a generic company profile. Record issues that actually influence the ISMS and revisit them when circumstances change.

Source family · ISO/IEC 27001:2022 Clause 4

Interested party

Management system

A person or organisation that can affect, be affected by or consider itself affected by an ISMS decision or activity.

Why it matters
Interested parties help identify relevant legal, regulatory, contractual and business requirements.
Do not confuse it with
Listing every stakeholder is not the goal. Determine which parties and which requirements are relevant to the ISMS.

Source family · ISO/IEC 27001:2022 Clause 4

ISMS scope

Management system

The defined organisational and technical boundary to which the ISMS requirements and any certification claim apply.

Why it matters
Scope tells readers which services, teams, locations, systems and interfaces are included and how dependencies are handled.
Do not confuse it with
Scope is not permission to ignore an important dependency. Exclusions and boundaries need defensible reasoning.

Source family · ISO/IEC 27001:2022 Clause 4

Documented information

Management system

Information the organisation controls and maintains, together with the medium that carries it.

Why it matters
It covers instructions used to operate the ISMS and records retained as evidence of results.
Do not confuse it with
It is not limited to PDFs. A ticket, dashboard, database record, recording or approved workflow may be documented information.

Source family · ISO management-system common terms

Statement of Applicability (SoA)

Management system

The required record of all necessary controls, including any designed outside Annex A, why they are necessary, whether they are implemented and why any Annex A reference control is not necessary.

Why it matters
It connects the risk treatment decision to the organisation’s actual control set and checks that Annex A has been considered.
Do not confuse it with
The SoA is not a claim that every Annex A control applies and is not a control catalogue copied without organisation-specific rationale.

Source family · ISO/IEC 27001:2022 Clause 6.1.3

Assurance and improvement

How the organisation checks performance, handles failures and makes the system better.

Nonconformity

Assurance and improvement

A requirement has not been fulfilled.

Why it matters
Naming a nonconformity precisely lets the organisation correct the issue and decide how to prevent recurrence.
Do not confuse it with
A concern or improvement idea is not automatically a nonconformity; identify the requirement and objective evidence.

Source family · ISO management-system common terms

Correction

Assurance and improvement

Action taken to remove or resolve a detected nonconformity or its immediate effect.

Why it matters
Correction contains the present problem, such as disabling an account that should already have been removed.
Do not confuse it with
Correction fixes what was found. It does not necessarily address why the problem occurred.

Source family · ISO management-system common terms

Corrective action

Assurance and improvement

Action taken against the cause of a nonconformity so that it is less likely to happen again.

Why it matters
Corrective action turns a finding into a durable process or system improvement.
Do not confuse it with
Changing one record may be a correction; changing the failed workflow and checking effectiveness is corrective action.

Source family · ISO management-system common terms

Internal audit

Assurance and improvement

A planned, systematic and evidence-based evaluation performed by or for the organisation to determine whether the ISMS meets selected criteria and operates effectively.

Why it matters
Internal audit gives management an objective view before or between external certification audits.
Do not confuse it with
It is not the certification audit, a vulnerability scan or an informal self-check by the process owner.

Source family · ISO/IEC 27001:2022 Clause 9 and ISO 19011

Management review

Assurance and improvement

Top management’s structured evaluation of whether the ISMS remains suitable, adequate and effective, using required inputs and recording decisions and actions.

Why it matters
It connects performance, changes, risks, audit results and resource needs to accountable management decisions.
Do not confuse it with
It is not simply a project status meeting or approval of the internal audit report.

Source family · ISO/IEC 27001:2022 Clause 9

Continual improvement

Assurance and improvement

Recurring work to improve performance over time.

Why it matters
It keeps the ISMS responsive to changed context, risk, results, findings and opportunities.
Do not confuse it with
Continual means recurring, not uninterrupted. Improvement can be targeted and prioritised rather than happening everywhere at once.

Source family · ISO management-system common terms

Worked example · fictional

Describe one privileged-access risk without collapsing the terms

Paperbark Payroll is a fictional Australian SaaS provider. This example is a language exercise, not a reusable risk assessment or a prescribed control design.

Fictional ISO 27001 terminology worked example
TermPaperbark example
AssetCustomer payroll export and the service that produces it
Security objectiveKeep the export confidential, accurate and available to authorised payroll staff
ThreatAn attacker uses a stolen administrator password
VulnerabilityA legacy administration route does not require phishing-resistant MFA
EventThe attacker signs in and requests a payroll export
ConsequencePayroll information is disclosed; customers face privacy, contractual and trust impacts
RiskUnauthorised export through compromised privileged access affects confidentiality and customer obligations
Risk ownerHead of Engineering, with authority to fund and accept treatment decisions
TreatmentReduce the risk by retiring the legacy route and enforcing stronger authentication
ControlPhishing-resistant MFA, privileged-access restriction, access review and monitored export activity
EvidenceConfiguration output, enrolment report, review approval and alert test result
Residual riskRemaining credential, insider and service-failure exposure assessed against approved criteria

Adaptation instructions

Build a controlled glossary your teams can use

  1. Choose the authoritative standards and regulatory sources that apply to your ISMS; keep links, edition numbers and access dates.
  2. Replace every example with language already used by your business, while preserving the important distinctions between the concepts.
  3. Define ambiguous scoring words such as rare, possible, major and unacceptable in the risk method rather than in conversation.
  4. Add organisation-specific examples, owners and evidence for each term. A definition becomes useful when a reader can recognise it in work.
  5. Record approved abbreviations and forbidden shortcuts, especially where one word is commonly used for several different things.
  6. Place the glossary under document control and update dependent training, procedures and registers when a definition changes.

Common mistakes

Shortcuts that change the meaning

Threat = vulnerability

A threat is a potential cause; a vulnerability is a weakness it may exploit.

Risk = missing control

Describe the uncertain event, affected objective and consequence before proposing treatment.

Integrity = confidentiality

Accurate, complete payroll data can have strong confidentiality and still lose integrity through an incorrect change.

Document = evidence

A policy states intent; an approval, log, result or completed record may demonstrate operation.

SoA = all 93 controls are mandatory

Every Annex A control must be considered, but applicability follows necessary controls, scope and risk.

Correction = corrective action

Correction handles the detected issue; corrective action handles its cause and recurrence.

Internal audit = certification audit

Internal audit is the organisation’s own assurance process; certification is separate third-party conformity assessment.

Residual risk = zero

Controls change risk; they rarely remove all uncertainty. Residual exposure still needs an owned decision.

Version, author and review status

Resource version
1.0
Published
2 September 2026
Author
Aegentra Academy
Standards basis
ISO/IEC 27001:2022, ISO/IEC 27000:2026 and ISO/IEC 27005:2022
Substantive reviewer
Harry Sidhu · Director and Principal Consultant, Aegentra
Substantive review date
2 September 2026

Substantively reviewed for source accuracy, terminology, limitations and learner-facing presentation. ISO/IEC 27000:2026 is now an overview focused on ISMS concepts and relationships; use ISO's Online Browsing Platform and the applicable current standards to verify authoritative terminology.

Limitations and use boundary

  • This is Aegentra-authored educational material, not official PECB course material, legal advice or a reproduction of an ISO standard.
  • Plain-English paraphrases trade some precision for readability. Use the authoritative standard or ISO terminology database when exact wording affects a decision.
  • Your organisation must define its own risk criteria, scoring terms, owners, scope, applicability decisions and evidence expectations.
  • The worked example is fictional and does not establish that the named controls are sufficient or applicable in another environment.
  • An individual course or glossary does not certify a person to perform every implementation or audit and does not certify an organisation’s ISMS.

Sources and further study

Source pages were checked when version 1.0 was prepared. The official standards and ISO terminology records remain authoritative if a plain-English explanation differs.

  1. [1]
    ISO/IEC 27000:2026 — Information security management systems — Overview

    Current overview of ISMS concepts, principles and relationships within the ISO/IEC 27000 family.

  2. [2]
    ISO Online Browsing Platform — ISO/IEC 27000 terms

    ISO’s public terminology interface for authoritative definitions available for browsing.

  3. [3]
    ISO/IEC 27001:2022 — Information security management systems — Requirements

    Current ISMS requirements edition, including scope, risk treatment, performance evaluation and improvement.

  4. [4]
    ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes

    Current amendment to context and interested-party considerations.

  5. [5]
    ISO/IEC 27005:2022 — Guidance on managing information security risks

    Information security risk assessment, treatment, communication, monitoring and review.

  6. [6]
    ISO/IEC 27002:2022 — Information security controls

    Current source standard for asset, threat and vulnerability terminology used in this guide.

  7. [7]
    ISO 9000:2026 — Quality management — Fundamentals and vocabulary

    Current source for common management-system terms including nonconformity, correction and corrective action.

  8. [8]
    ISO/IEC 27001 Auditing Practices Group — Statement of Applicability note

    An educational practices note hosted in the SC 27 resource library on custom controls, Annex A comparison and SoA completeness. The note states that it has not been endorsed by ISO or SC 27.

  9. [9]
    ISO management system standards

    Common management-system concepts, including leadership, evaluation and recurring improvement.

FAQs

No. It is an Aegentra-authored plain-English learning resource. The definitions are paraphrases designed to explain relationships without reproducing the standard. Use ISO’s published standards and Online Browsing Platform for authoritative wording.

Start with something valuable. A threat is a possible cause of harm; a vulnerability is a weakness the threat can exploit; risk expresses the uncertainty and consequence for an objective; a control is a measure selected to change that risk.

No. Software may support tasks and evidence, but the ISMS is the organisation’s coordinated management system: scope, leadership, policies, risk decisions, resources, processes, records, evaluation and improvement.

Use the vocabulary in context

Build the foundation before choosing an implementation or audit pathway

Foundation teaches the core concepts and ISMS structure. Lead Implementer and Lead Auditor are separate role-focused courses with different learning and assessment pathways.