Direct definition
What is the ISO 27001 terminology glossary?
It is an Aegentra-authored learning aid that translates common information security and management-system terms into plain English. It is designed to help a learner explain how the concepts relate; it is not an official vocabulary standard and does not replace the wording in ISO's published documents.
Purpose: build precise language before working with risks, controls, audits or corrective actions. If two people use “risk”, “issue” and “finding” for the same thing, their records and decisions will drift even when their templates look consistent.
Visible preview
Read the risk sentence from left to right
A useful risk statement connects the concepts instead of listing them in separate columns with no story. Start with value, describe a plausible path to consequence, then show the decision used to change and monitor the risk.
1 · Asset
Something valuable or a service dependency
2 · Threat
A possible cause of an unwanted event
3 · Vulnerability
A weakness that makes the event plausible
4 · Risk
Uncertainty and consequence for an objective
5 · Control
A measure selected to change the risk
Consequence and likelihood support analysis; a risk owner makes or escalates the treatment and acceptance decision; evidence helps show whether the chosen controls operate and change the risk as intended.
30 study terms
Plain-English ISO 27001 definitions
These definitions are intentionally explanatory rather than word-for-word reproductions. The source family on each card points to the place to verify the authoritative term.
Security outcome
What is valuable and which properties information security is trying to preserve.
Information
Security outcomeMeaning communicated or represented through data, records, conversations, images, code or another form.
- Why it matters
- The ISMS protects information across its lifecycle, not just files stored in an IT system.
- Do not confuse it with
- Do not reduce information to electronic data; spoken, printed and observed information can also need protection.
Source family · ISO/IEC 27000 family
Asset
Security outcomeSomething valuable to the organisation, or something on which valuable information and services depend.
- Why it matters
- Assets give risk scenarios a concrete object: information, people, applications, infrastructure, suppliers, facilities or reputation.
- Do not confuse it with
- An asset is not always a device. A customer dataset, service, relationship or specialist skill can be an asset.
Source family · ISO/IEC 27002:2022
Information security
Security outcomeProtecting the confidentiality, integrity and availability of information, with other properties considered where relevant.
- Why it matters
- It states the outcome the ISMS is designed to preserve.
- Do not confuse it with
- Information security is broader than cybersecurity and broader than preventing data breaches.
Source family · ISO/IEC 27000 family
Confidentiality
Security outcomeKeeping information from being made available or disclosed to people, systems or processes that are not authorised to receive it.
- Why it matters
- It helps teams consider access, disclosure, sharing, storage and disposal risks.
- Do not confuse it with
- Confidential does not mean secret from everyone; authorised access is part of the design.
Source family · ISO Online Browsing Platform
Integrity
Security outcomeKeeping information accurate and complete, and protecting it from unauthorised or unintended change.
- Why it matters
- It directs attention to correctness, approved changes, processing logic and trusted records.
- Do not confuse it with
- Integrity is not personal honesty in this context; it concerns the accuracy and completeness of information.
Source family · ISO Online Browsing Platform
Availability
Security outcomeEnsuring authorised users and processes can reach and use information or services when they need them.
- Why it matters
- It connects resilience, capacity, recovery, suppliers and continuity to information security.
- Do not confuse it with
- Availability does not require every system to run continuously; the required level comes from business and stakeholder needs.
Source family · ISO Online Browsing Platform
Risk relationship
How a plausible event moves from an asset and weakness to consequence, decision and control.
Threat
Risk relationshipA potential cause of an unwanted event that could harm an asset, service or security objective.
- Why it matters
- Threats help describe what might happen: phishing, fire, malicious action, human error or supplier failure.
- Do not confuse it with
- A threat is not the weakness it may exploit and is not the resulting business risk.
Source family · ISO/IEC 27002:2022
Vulnerability
Risk relationshipA weakness in an asset, control, process or environment that a threat can exploit or trigger.
- Why it matters
- Vulnerabilities explain why a threat could produce a consequence in this organisation.
- Do not confuse it with
- A vulnerability is not automatically a risk; combine it with a plausible threat, affected objective and consequence.
Source family · ISO/IEC 27002:2022
Event
Risk relationshipAn occurrence or change in circumstances. An event may be expected or unexpected and may include something failing to happen.
- Why it matters
- Events provide the trigger in a scenario, such as a credential being stolen or a backup job not completing.
- Do not confuse it with
- Not every event is an incident. Significance and impact determine how it is classified and handled.
Source family · ISO/IEC 27005 and ISO/IEC 27000 family
Consequence
Risk relationshipThe effect on objectives if an event occurs, such as service interruption, inaccurate records, disclosure, cost or loss of trust.
- Why it matters
- Consequences let the organisation compare security scenarios in business terms.
- Do not confuse it with
- Consequence is the outcome, not the event that causes it. One event can produce several consequences.
Source family · ISO/IEC 27005:2022
Likelihood
Risk relationshipHow possible or probable an event is under the organisation’s defined assessment method.
- Why it matters
- Likelihood combines with consequence and the chosen method to support consistent prioritisation.
- Do not confuse it with
- Labels such as “possible” are meaningless until the organisation defines their frequency or probability ranges.
Source family · ISO/IEC 27005:2022
Information security risk
Risk relationshipUncertainty that can affect information security objectives, described through scenarios, likelihood and consequences using the organisation’s chosen method.
- Why it matters
- Risk is the decision unit used to prioritise treatment, acceptance, communication and monitoring.
- Do not confuse it with
- A missing control is not a complete risk statement. State what might happen, why, what is affected and what the consequence would be.
Source family · ISO/IEC 27005:2022
Risk assessment
Risk relationshipThe structured work of identifying risks, analysing their characteristics and evaluating them against defined criteria.
- Why it matters
- It produces prioritised, explainable decisions rather than an unranked list of security concerns.
- Do not confuse it with
- Assessment decides what the risk means; treatment decides what to do about it.
Source family · ISO/IEC 27005:2022
Risk treatment
Risk relationshipSelecting and implementing an approach that changes a risk, such as reducing, avoiding, sharing or knowingly retaining it.
- Why it matters
- Treatment turns a prioritised risk into an owned decision, controls, actions and a target result.
- Do not confuse it with
- Treatment is not always adding technology. Process, people, contracts and scope decisions may also change risk.
Source family · ISO/IEC 27005:2022
Risk owner
Risk relationshipThe person or role with authority and accountability to manage a particular risk.
- Why it matters
- The owner makes or escalates treatment and acceptance decisions and tracks the risk over time.
- Do not confuse it with
- The risk owner is not automatically the person who operates a control or administers the risk register.
Source family · ISO/IEC 27005 and ISO 31000
Control
Risk relationshipA measure that changes risk, including a policy, process, practice, contract, technology or other action.
- Why it matters
- Controls are selected to help achieve treatment and information security objectives.
- Do not confuse it with
- A control can be designed well but operate poorly. Design, implementation and effectiveness are separate questions.
Source family · ISO/IEC 27000 family
Inherent risk
Risk relationshipA commonly used practitioner view of exposure before the controls being assessed are taken into account.
- Why it matters
- It can show the scale of the underlying scenario and support treatment prioritisation.
- Do not confuse it with
- Define the term in your method. Organisations calculate it differently, and ISO/IEC 27001 does not prescribe one universal formula.
Source family · Organisation-defined risk methodology
Residual risk
Risk relationshipThe risk remaining after treatment and relevant controls are considered.
- Why it matters
- It supports acceptance, further treatment and monitoring decisions.
- Do not confuse it with
- Residual risk is rarely zero. Record who accepts it and under what criteria, rather than assuming controls remove all uncertainty.
Source family · ISO/IEC 27005:2022
Management system
The boundary, governance and controlled information that make security repeatable.
ISMS
Management systemThe coordinated policies, roles, processes, resources and records an organisation uses to manage information security risk and improve outcomes.
- Why it matters
- An ISMS makes information security governable, repeatable, measurable and improvable.
- Do not confuse it with
- An ISMS is not a software product and is not the same as a collection of security tools.
Source family · ISO/IEC 27000:2026 and ISO/IEC 27001:2022
Context of the organisation
Management systemThe internal and external conditions that can affect what the ISMS is expected to achieve.
- Why it matters
- Context explains why the scope, priorities, risks and management approach fit this organisation.
- Do not confuse it with
- It is not a generic company profile. Record issues that actually influence the ISMS and revisit them when circumstances change.
Source family · ISO/IEC 27001:2022 Clause 4
Interested party
Management systemA person or organisation that can affect, be affected by or consider itself affected by an ISMS decision or activity.
- Why it matters
- Interested parties help identify relevant legal, regulatory, contractual and business requirements.
- Do not confuse it with
- Listing every stakeholder is not the goal. Determine which parties and which requirements are relevant to the ISMS.
Source family · ISO/IEC 27001:2022 Clause 4
ISMS scope
Management systemThe defined organisational and technical boundary to which the ISMS requirements and any certification claim apply.
- Why it matters
- Scope tells readers which services, teams, locations, systems and interfaces are included and how dependencies are handled.
- Do not confuse it with
- Scope is not permission to ignore an important dependency. Exclusions and boundaries need defensible reasoning.
Source family · ISO/IEC 27001:2022 Clause 4
Documented information
Management systemInformation the organisation controls and maintains, together with the medium that carries it.
- Why it matters
- It covers instructions used to operate the ISMS and records retained as evidence of results.
- Do not confuse it with
- It is not limited to PDFs. A ticket, dashboard, database record, recording or approved workflow may be documented information.
Source family · ISO management-system common terms
Statement of Applicability (SoA)
Management systemThe required record of all necessary controls, including any designed outside Annex A, why they are necessary, whether they are implemented and why any Annex A reference control is not necessary.
- Why it matters
- It connects the risk treatment decision to the organisation’s actual control set and checks that Annex A has been considered.
- Do not confuse it with
- The SoA is not a claim that every Annex A control applies and is not a control catalogue copied without organisation-specific rationale.
Source family · ISO/IEC 27001:2022 Clause 6.1.3
Assurance and improvement
How the organisation checks performance, handles failures and makes the system better.
Nonconformity
Assurance and improvementA requirement has not been fulfilled.
- Why it matters
- Naming a nonconformity precisely lets the organisation correct the issue and decide how to prevent recurrence.
- Do not confuse it with
- A concern or improvement idea is not automatically a nonconformity; identify the requirement and objective evidence.
Source family · ISO management-system common terms
Correction
Assurance and improvementAction taken to remove or resolve a detected nonconformity or its immediate effect.
- Why it matters
- Correction contains the present problem, such as disabling an account that should already have been removed.
- Do not confuse it with
- Correction fixes what was found. It does not necessarily address why the problem occurred.
Source family · ISO management-system common terms
Corrective action
Assurance and improvementAction taken against the cause of a nonconformity so that it is less likely to happen again.
- Why it matters
- Corrective action turns a finding into a durable process or system improvement.
- Do not confuse it with
- Changing one record may be a correction; changing the failed workflow and checking effectiveness is corrective action.
Source family · ISO management-system common terms
Internal audit
Assurance and improvementA planned, systematic and evidence-based evaluation performed by or for the organisation to determine whether the ISMS meets selected criteria and operates effectively.
- Why it matters
- Internal audit gives management an objective view before or between external certification audits.
- Do not confuse it with
- It is not the certification audit, a vulnerability scan or an informal self-check by the process owner.
Source family · ISO/IEC 27001:2022 Clause 9 and ISO 19011
Management review
Assurance and improvementTop management’s structured evaluation of whether the ISMS remains suitable, adequate and effective, using required inputs and recording decisions and actions.
- Why it matters
- It connects performance, changes, risks, audit results and resource needs to accountable management decisions.
- Do not confuse it with
- It is not simply a project status meeting or approval of the internal audit report.
Source family · ISO/IEC 27001:2022 Clause 9
Continual improvement
Assurance and improvementRecurring work to improve performance over time.
- Why it matters
- It keeps the ISMS responsive to changed context, risk, results, findings and opportunities.
- Do not confuse it with
- Continual means recurring, not uninterrupted. Improvement can be targeted and prioritised rather than happening everywhere at once.
Source family · ISO management-system common terms
Worked example · fictional
Describe one privileged-access risk without collapsing the terms
Paperbark Payroll is a fictional Australian SaaS provider. This example is a language exercise, not a reusable risk assessment or a prescribed control design.
| Term | Paperbark example |
|---|---|
| Asset | Customer payroll export and the service that produces it |
| Security objective | Keep the export confidential, accurate and available to authorised payroll staff |
| Threat | An attacker uses a stolen administrator password |
| Vulnerability | A legacy administration route does not require phishing-resistant MFA |
| Event | The attacker signs in and requests a payroll export |
| Consequence | Payroll information is disclosed; customers face privacy, contractual and trust impacts |
| Risk | Unauthorised export through compromised privileged access affects confidentiality and customer obligations |
| Risk owner | Head of Engineering, with authority to fund and accept treatment decisions |
| Treatment | Reduce the risk by retiring the legacy route and enforcing stronger authentication |
| Control | Phishing-resistant MFA, privileged-access restriction, access review and monitored export activity |
| Evidence | Configuration output, enrolment report, review approval and alert test result |
| Residual risk | Remaining credential, insider and service-failure exposure assessed against approved criteria |
Adaptation instructions
Build a controlled glossary your teams can use
- Choose the authoritative standards and regulatory sources that apply to your ISMS; keep links, edition numbers and access dates.
- Replace every example with language already used by your business, while preserving the important distinctions between the concepts.
- Define ambiguous scoring words such as rare, possible, major and unacceptable in the risk method rather than in conversation.
- Add organisation-specific examples, owners and evidence for each term. A definition becomes useful when a reader can recognise it in work.
- Record approved abbreviations and forbidden shortcuts, especially where one word is commonly used for several different things.
- Place the glossary under document control and update dependent training, procedures and registers when a definition changes.
Common mistakes
Shortcuts that change the meaning
Threat = vulnerability
A threat is a potential cause; a vulnerability is a weakness it may exploit.
Risk = missing control
Describe the uncertain event, affected objective and consequence before proposing treatment.
Integrity = confidentiality
Accurate, complete payroll data can have strong confidentiality and still lose integrity through an incorrect change.
Document = evidence
A policy states intent; an approval, log, result or completed record may demonstrate operation.
SoA = all 93 controls are mandatory
Every Annex A control must be considered, but applicability follows necessary controls, scope and risk.
Correction = corrective action
Correction handles the detected issue; corrective action handles its cause and recurrence.
Internal audit = certification audit
Internal audit is the organisation’s own assurance process; certification is separate third-party conformity assessment.
Residual risk = zero
Controls change risk; they rarely remove all uncertainty. Residual exposure still needs an owned decision.
Version, author and review status
- Resource version
- 1.0
- Published
- 2 September 2026
- Author
- Aegentra Academy
- Standards basis
- ISO/IEC 27001:2022, ISO/IEC 27000:2026 and ISO/IEC 27005:2022
- Substantive reviewer
- Harry Sidhu · Director and Principal Consultant, Aegentra
- Substantive review date
- 2 September 2026
Substantively reviewed for source accuracy, terminology, limitations and learner-facing presentation. ISO/IEC 27000:2026 is now an overview focused on ISMS concepts and relationships; use ISO's Online Browsing Platform and the applicable current standards to verify authoritative terminology.
Limitations and use boundary
- This is Aegentra-authored educational material, not official PECB course material, legal advice or a reproduction of an ISO standard.
- Plain-English paraphrases trade some precision for readability. Use the authoritative standard or ISO terminology database when exact wording affects a decision.
- Your organisation must define its own risk criteria, scoring terms, owners, scope, applicability decisions and evidence expectations.
- The worked example is fictional and does not establish that the named controls are sufficient or applicable in another environment.
- An individual course or glossary does not certify a person to perform every implementation or audit and does not certify an organisation’s ISMS.
Sources and further study
Source pages were checked when version 1.0 was prepared. The official standards and ISO terminology records remain authoritative if a plain-English explanation differs.
- [1]ISO/IEC 27000:2026 — Information security management systems — Overview
Current overview of ISMS concepts, principles and relationships within the ISO/IEC 27000 family.
- [2]ISO Online Browsing Platform — ISO/IEC 27000 terms
ISO’s public terminology interface for authoritative definitions available for browsing.
- [3]ISO/IEC 27001:2022 — Information security management systems — Requirements
Current ISMS requirements edition, including scope, risk treatment, performance evaluation and improvement.
- [4]ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes
Current amendment to context and interested-party considerations.
- [5]ISO/IEC 27005:2022 — Guidance on managing information security risks
Information security risk assessment, treatment, communication, monitoring and review.
- [6]ISO/IEC 27002:2022 — Information security controls
Current source standard for asset, threat and vulnerability terminology used in this guide.
- [7]ISO 9000:2026 — Quality management — Fundamentals and vocabulary
Current source for common management-system terms including nonconformity, correction and corrective action.
- [8]ISO/IEC 27001 Auditing Practices Group — Statement of Applicability note
An educational practices note hosted in the SC 27 resource library on custom controls, Annex A comparison and SoA completeness. The note states that it has not been endorsed by ISO or SC 27.
- [9]ISO management system standards
Common management-system concepts, including leadership, evaluation and recurring improvement.
FAQs
No. It is an Aegentra-authored plain-English learning resource. The definitions are paraphrases designed to explain relationships without reproducing the standard. Use ISO’s published standards and Online Browsing Platform for authoritative wording.
Start with something valuable. A threat is a possible cause of harm; a vulnerability is a weakness the threat can exploit; risk expresses the uncertainty and consequence for an objective; a control is a measure selected to change that risk.
No. Software may support tasks and evidence, but the ISMS is the organisation’s coordinated management system: scope, leadership, policies, risk decisions, resources, processes, records, evaluation and improvement.