Knowledge Hub
Cybersecurity, ISO 27001 & GRC glossary
The reference definitions you need to write your policies and prepare for audits — in plain language, no needless jargon.
- Acceptable Use Policy(AUP)Policies
- A policy defining how employees may use company systems, devices, networks and data, and what is prohibited. It is one of the most frequently requested documents in audits and onboarding. A typical AUP covers acceptable email and internet use, handling of confidential data, password and device hygiene, software installation, personal use, monitoring expectations and the consequences of violations. It maps directly to ISO 27002 control 5.10 (acceptable use of information and associated assets) and is usually acknowledged in writing by every employee and contractor before access is granted. Because staff sign it, the AUP also gives the organisation a defensible basis for disciplinary action and for any monitoring it performs. Kept short and readable, it is the policy users actually encounter most often.
- Read the full guide →See a related PDF template →
- Access Control PolicyPoliciesISO 27001
- A policy governing how identities are provisioned, authenticated, authorised, reviewed and revoked, typically enforcing least privilege and role-based access control. It defines the full identity lifecycle: how accounts are requested and approved at joining, changed when people move roles, and promptly disabled when they leave. It sets authentication requirements (including MFA for sensitive systems), rules for privileged and shared accounts, segregation of duties, and the cadence of periodic access reviews that confirm people still need what they hold. It corresponds to the ISO 27002 access-control family (notably 5.15–5.18) and underpins audit findings about orphaned accounts and excessive privilege. A clear access control policy is one of the highest-leverage documents an organisation can maintain, because weak access management is behind a large share of real breaches.
- Read the full guide →See a related PDF template →
- ANSSIRegulationGRC
- The Agence nationale de la sécurité des systèmes d’information — France’s national cybersecurity authority. It issues guidance and standards (such as the Guide d’hygiène informatique and the SecNumCloud qualification) widely used as a baseline by French organisations. Created in 2009 and attached to the Prime Minister’s office (SGDSN), ANSSI is a defensive agency: unlike some foreign counterparts it has no offensive or intelligence mandate. It protects the State and operators of vital importance (OIV) and essential services (OSE), runs the CERT-FR national response team, and qualifies trusted products and providers through schemes such as SecNumCloud (cloud), CSPN (product evaluation) and qualified PASSI security auditors. It is also the French authority steering the national implementation of EU rules such as NIS2. Its publications are free and frequently adopted as a practical security baseline well beyond the entities legally bound by them.
- Business Continuity Plan(BCP)PoliciesGRC
- A plan ensuring critical business functions can continue or be quickly restored during and after a disruption. It is underpinned by recovery objectives (RPO/RTO) and tested regularly. A BCP usually begins with a business impact analysis that ranks processes by criticality and sets their recovery objectives, then documents the strategies, resources, alternate sites and step-by-step procedures needed to keep them running. It is broader than a disaster recovery plan, which focuses specifically on restoring IT systems; the DR plan is one component of the wider BCP. ISO 22301 is the dedicated standard for business continuity management, and ISO 27002 control 5.30 addresses ICT readiness for continuity. A plan that is never exercised tends to fail when needed, so regular tabletop and failover tests are essential to keep it credible.
- Read the full guide →See a related PDF template →
- BYODPolicies
- Bring Your Own Device — the practice of allowing employees to use personal devices for work. A BYOD policy sets the security conditions (encryption, MFA, remote wipe, separation of data) under which this is permitted. The central tension is that the organisation must protect corporate data on hardware it does not own, while respecting the employee’s personal privacy. Modern policies resolve this with mobile device management or, increasingly, mobile application management and containerisation, which isolate work data so it can be wiped selectively without touching personal photos or messages. They also set rules for minimum OS versions, screen locks, jailbreak/root prohibition, lost-device reporting and what happens when someone leaves. NIST SP 800-124 provides detailed guidance for managing mobile devices in the enterprise. A clear BYOD policy and signed user agreement are what make personal-device use defensible.
- Read the full guide →See a related PDF template →
- CIS ControlsGRC
- A prioritised set of 18 safeguards published by the Center for Internet Security, designed to stop the most common attacks. Implementation Groups (IG1–IG3) scale the controls to an organisation’s size and risk: IG1 defines essential cyber hygiene for small organisations, while IG2 and IG3 add depth for those facing greater risk. The controls are ordered so the highest-impact, most foundational safeguards — inventory of assets and software, data protection, secure configuration, account and access management — come first. Version 8 reorganised them around activities rather than who owns the device, reflecting cloud and remote work. Each safeguard maps to other frameworks such as NIST CSF and ISO 27001, so teams can use the CIS Controls as a concrete starting point and still report against a broader standard.
- Data ClassificationPolicies
- The practice of labelling information by sensitivity (e.g. public, internal, confidential, restricted) so that handling, storage, sharing and retention rules can be applied consistently. Classification is the foundation for proportionate protection: once data carries a label, controls such as encryption, access restrictions, approved storage locations and retention periods can be tied to that label rather than decided case by case. ISO 27002 controls 5.12 (classification) and 5.13 (labelling) cover the discipline, and most schemes use three or four tiers to stay usable. The hard part is operational, not conceptual — labels must be applied at creation, survive copying and sharing, and be understood by staff. A scheme that is too granular gets ignored, so a small number of clearly defined levels, each with concrete handling rules, works best.
- Read the full guide →See a related PDF template →
- Data Processing Agreement(DPA)RegulationGRC
- A contract required by GDPR Article 28 between a data controller and a processor, setting out the scope, duration, security measures and obligations governing the processing of personal data. Article 28 specifies mandatory terms the DPA must contain: the processor acts only on documented instructions, ensures staff confidentiality, applies appropriate security under Article 32, engages sub-processors only with authorisation and equivalent terms, assists the controller with data-subject rights and breach notification, and deletes or returns the data at the end of the engagement. It also grants the controller audit rights. In practice a DPA is signed whenever an organisation entrusts personal data to a vendor — a cloud host, SaaS tool or payroll provider — and is one of the documents buyers most commonly request during vendor due diligence. For cross-border transfers it is often paired with Standard Contractual Clauses.
- DORARegulation
- The EU Digital Operational Resilience Act — regulation (2022/2554) harmonising ICT risk management, incident reporting, resilience testing and third-party oversight for the financial sector, applicable since January 2025. It covers a broad range of financial entities — banks, insurers, investment firms, payment institutions, crypto-asset providers and more — and rests on five pillars: ICT risk management, ICT-related incident classification and reporting, digital operational resilience testing (including threat-led penetration testing for major entities), management of ICT third-party risk, and information-sharing arrangements. A notable feature is an oversight regime for critical ICT third-party providers such as major cloud platforms, bringing them under direct supervision. Because it is a regulation rather than a directive, it applies uniformly across the EU without national transposition, giving the financial sector a single, directly binding resilience rulebook.
- EU AI ActRegulation
- The EU regulation on artificial intelligence (2024/1689) — a risk-based framework classifying AI systems (unacceptable, high, limited, minimal risk) and imposing obligations on providers and deployers, including governance, transparency and documentation. Systems posing unacceptable risk (such as social scoring and certain biometric practices) are banned; high-risk systems — used in areas like recruitment, credit, education or critical infrastructure — must meet strict requirements for risk management, data quality, logging, human oversight and conformity assessment before market entry. Limited-risk systems such as chatbots face transparency duties, and general-purpose AI models carry their own obligations. The Act applies extraterritorially and phases in over time, with prohibited-practice bans applying first and high-risk obligations later; fines can reach €35 million or 7% of global turnover. ISO/IEC 42001 is widely used as the management-system framework for demonstrating responsible AI governance under it.
- Read the full guide →See a related PDF template →
- GDPR(RGPD)Regulation
- The EU General Data Protection Regulation (2016/679) — the regulation governing how personal data of individuals in the EU is collected, processed, stored and transferred, backed by rights for data subjects and significant fines for non-compliance. In force since May 2018, it rests on principles in Article 5 (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability) and requires a lawful basis under Article 6 for any processing. It grants individuals rights including access, rectification, erasure, portability and objection, and obliges organisations to keep records, run data protection impact assessments for high-risk processing, and report qualifying breaches within 72 hours. It applies extraterritorially to any organisation targeting or monitoring people in the EU, and fines can reach €20 million or 4% of global annual turnover, whichever is higher. ISO 27701 helps evidence GDPR accountability.
- GRCGRC
- Governance, Risk and Compliance — the discipline of aligning security governance, risk management and regulatory compliance so they reinforce rather than duplicate each other. Governance sets the policies, roles and decision rights; risk management identifies and treats threats against the organisation’s appetite; compliance evidences that controls satisfy laws, standards and contracts. Treated separately they generate overlapping audits, conflicting controls and duplicated evidence. Treated as one programme — often supported by a shared control library and a GRC platform — a single control can be tested once and mapped to ISO 27001, SOC 2, GDPR and customer commitments simultaneously. For smaller teams GRC is less about tooling than about a consistent, documented way to decide what to protect, how much risk to accept and how to prove it.
- HDSRegulationGRC
- Hébergeur de Données de Santé — the French certification required to host personal health data. It builds on ISO 27001 with additional health-specific requirements and is mandatory for providers handling French patient data. Established under the French Public Health Code, the HDS certification replaced the older accreditation scheme and is awarded by accredited certification bodies after audit. It layers ISO 20000-1 (IT service management) and sector-specific controls on top of ISO 27001, and is granted for defined activities — from hosting physical infrastructure and virtual machines up to application hosting and backup. Any organisation that stores or processes identifying health data on behalf of others in France, including cloud providers serving health-tech companies and hospitals, must hold it. For health-tech startups, choosing an HDS-certified host is often the simplest route to meeting the requirement without certifying their own infrastructure.
- HIPAARegulation
- The US Health Insurance Portability and Accountability Act — legislation setting standards for protecting sensitive patient health information (PHI), including the Security Rule and Privacy Rule that govern safeguards and disclosures. Enacted in 1996, it applies to “covered entities” (health plans, healthcare providers and clearinghouses) and their “business associates” — vendors that handle PHI on their behalf, who must sign a Business Associate Agreement. The Privacy Rule governs how protected health information may be used and disclosed and gives patients rights over their records; the Security Rule requires administrative, physical and technical safeguards for electronic PHI; and the Breach Notification Rule sets disclosure duties after a breach. It is enforced by the HHS Office for Civil Rights, with penalties scaling by culpability. For software vendors serving US healthcare, signing BAAs and implementing the Security Rule safeguards are the practical entry requirements.
- Incident Response PolicyPolicies
- A policy and procedure defining how security incidents are detected, triaged, contained, eradicated, recovered from and reviewed, including roles, escalation paths and breach-notification timelines. It typically follows recognised lifecycles such as NIST SP 800-61 (preparation; detection and analysis; containment, eradication and recovery; post-incident activity) and names a response team with clear authority to act. Critically, it ties technical response to legal duties: GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a personal-data breach, and other regimes (NIS2, DORA, sector rules) impose their own deadlines. A good policy is paired with contact lists, severity definitions and runbooks, and is rehearsed through tabletop exercises so that the first time the team follows it is not during a real incident.
- Read the full guide →See a related PDF template →
- Information security policyPoliciesISO 27001
- The top-level, management-approved document that states an organisation’s commitment to protecting information and sets the direction for all subordinate security policies. Required by ISO 27001 clause 5.2. It must be appropriate to the organisation’s purpose, include or frame the information security objectives, commit to satisfying applicable requirements and to continual improvement, be documented, communicated within the organisation and made available to interested parties where relevant. Deliberately short and stable, it sits above the more detailed topic-specific policies (access control, acceptable use, incident response and so on), which translate its intent into concrete rules. Top management owns it — signalling that security is a leadership responsibility, not just IT’s — and reviews it at planned intervals so it keeps pace with changes in the business, technology and threat landscape.
- ISMS(SMSI)ISO 27001GRC
- Information Security Management System — the set of policies, processes, roles and controls an organisation uses to manage information security risk in a systematic, auditable way. ISO/IEC 27001 defines the requirements for an ISMS. Rather than a one-off project, it runs as a continual cycle: management sets objectives, risks are assessed and treated, controls are operated and monitored, and the system is improved through internal audits and management reviews. It applies to organisations of any size or sector, and its scope can be limited to specific products, teams or locations. A well-run ISMS turns scattered security practices into documented, repeatable evidence — the foundation auditors look for during certification.
- ISO/IEC 27001ISO 27001Regulation
- The international standard specifying the requirements for establishing, operating and continually improving an ISMS. Certification is granted by an accredited body after a two-stage audit. The 2022 revision aligns controls with ISO/IEC 27002:2022. It is split into mandatory management-system clauses (4–10, covering context, leadership, planning, support, operation, performance evaluation and improvement) and Annex A, which lists 93 reference controls. A certificate is valid for three years, with annual surveillance audits in between. It is the most widely recognised information-security certification worldwide and is frequently required in enterprise procurement and vendor due diligence. Organisations of any size can certify; the effort scales with the chosen scope and the number of applicable controls.
- ISO/IEC 27002ISO 27001
- A companion guidance standard that describes the 93 information security controls referenced by ISO 27001 Annex A, organised into four themes: organisational, people, physical and technological. Unlike ISO 27001 it is not certifiable — it provides implementation guidance, explaining the purpose of each control and how to apply it. The 2022 edition consolidated the previous 114 controls into 93, introduced 11 new ones (such as threat intelligence, secure coding and data masking) and added five attributes (control type, security property, cybersecurity concept, operational capability and security domain) to help organisations filter and map controls. Teams typically use 27002 as the practical handbook while certifying against 27001.
- ISO/IEC 27701ISO 27001Regulation
- The international standard for privacy information management (a PIMS). It helps organisations manage personal data and demonstrate GDPR-aligned accountability. First published in 2019 as an extension of ISO 27001/27002, its 2025 edition became a standalone, certifiable management-system standard: a PIMS can now be certified on its own or integrated with an existing ISMS, and organisations certified against the 2019 edition have until October 2028 to transition. It assigns privacy-specific requirements and controls to the roles of PII controller and PII processor, and is designed to be mapped to data-protection laws such as the GDPR — giving controllers and processors a recognised, auditable way to evidence their privacy obligations to customers and regulators.
- ISO/IEC 42001ISO 27001Regulation
- The international standard for an Artificial Intelligence Management System (AIMS). It mirrors the ISO 27001 structure to help organisations govern AI responsibly — covering risk, transparency, data quality and lifecycle management. Published in 2023 as the first certifiable AI management-system standard, it follows the same high-level structure as ISO 27001 and ISO 9001, so organisations already running a management system can integrate it rather than build a parallel one. It introduces AI-specific concepts such as an AI impact assessment (considering effects on individuals and society, not just on the organisation) and controls spanning the full AI lifecycle, from data and model development to deployment and monitoring. Because it is certifiable, it lets an organisation demonstrate responsible AI governance to customers and regulators — and is increasingly cited as a practical way to evidence the governance obligations introduced by the EU AI Act.
- Read the full guide →See a related PDF template →
- Least PrivilegePoliciesGRC
- The principle that every user, process or system is granted only the minimum access required to perform its function, reducing the blast radius of compromised credentials. If an account that can only read one folder is phished, the attacker gains only that folder; an over-privileged account hands them far more. In practice least privilege is implemented through role-based access, regular access reviews that strip unused rights, removal of standing administrator access, and just-in-time elevation that grants higher privileges only for the moment they are needed and then revokes them. It is a core tenet of Zero Trust and a recurring theme in ISO 27001 and the CIS Controls. The discipline counters “privilege creep”, where people accumulate access as they change roles but rarely lose what they no longer need.
- Multi-Factor Authentication(MFA)Policies
- An authentication method requiring two or more independent factors (something you know, have or are). It is one of the single most effective controls against account takeover. The factors come from distinct categories — a password (knowledge), a phone or hardware key (possession), a fingerprint or face (inherence) — so a stolen password alone is not enough to log in. Not all methods are equal: app-based authenticator codes and push prompts are stronger than SMS one-time codes, which can be intercepted via SIM swapping, while phishing-resistant FIDO2/WebAuthn hardware keys and passkeys are the strongest, because they cannot be replayed on a fake site. MFA is increasingly mandated by cyber-insurance and regulators, and applying it to email, remote access and privileged accounts blocks the large majority of credential-based attacks.
- NIS2Regulation
- An EU directive (2022/2555) expanding cybersecurity obligations across more sectors, with stricter risk-management measures, incident reporting and management accountability than its predecessor. NIS2 replaces the original 2016 NIS Directive and sharply widens scope, classifying organisations as “essential” or “important” entities across sectors such as energy, transport, health, digital infrastructure, public administration, manufacturing and ICT service management. It mandates baseline risk-management measures (Article 21), a layered incident-reporting timeline — an early warning within 24 hours and a fuller notification within 72 hours — and makes senior management personally accountable for compliance, with the power to impose significant fines. As a directive it must be transposed into each member state’s national law, so exact thresholds and penalties vary by country. Many organisations use ISO 27001 as a practical baseline for meeting its requirements.
- NIST CSFGRC
- The NIST Cybersecurity Framework — a voluntary, risk-based framework organised around core functions (Govern, Identify, Protect, Detect, Respond, Recover) used to assess and improve cybersecurity posture. Govern was added in version 2.0 (2024), which also broadened the framework beyond critical infrastructure to organisations of every size and sector. Each function breaks down into categories and subcategories of outcomes that can be mapped to controls from other standards such as ISO 27001 or the CIS Controls. Organisations use it to express a current and a target profile and to communicate risk to non-technical leadership in a common language. It is guidance, not a certifiable standard.
- PCI DSSRegulation
- The Payment Card Industry Data Security Standard — a contractual security standard for any organisation that stores, processes or transmits cardholder data, defining requirements across network security, encryption, access control and monitoring. Maintained by the PCI Security Standards Council (founded by the major card brands), the current version 4.0.1 organises its requirements into twelve groups under six control objectives. How an organisation validates compliance depends on transaction volume and how it handles card data: larger merchants undergo an annual on-site assessment by a Qualified Security Assessor producing a Report on Compliance, while smaller ones complete a Self-Assessment Questionnaire. A key risk-reduction strategy is to minimise scope — for example by outsourcing payment pages or using tokenisation so raw card numbers never touch your systems. It is enforced contractually by acquiring banks and card networks rather than by law, but non-compliance can mean fines or loss of card-processing ability.
- Risk assessmentGRCISO 27001
- The process of identifying assets, threats and vulnerabilities, then estimating the likelihood and impact of risks so they can be prioritised. ISO 27001 requires a documented, repeatable risk assessment method. The standard (clause 6.1.2) insists the method produce consistent, comparable and valid results — so two assessors using it should reach similar conclusions — and that the organisation define its risk acceptance criteria up front. Risks are typically scored on likelihood and impact, ranked, and assigned an owner. The method can be asset-based (start from what you hold) or scenario-based (start from how things could go wrong); ISO 27005 offers detailed guidance. The output is a prioritised risk register that drives risk treatment and, ultimately, the controls recorded in the Statement of Applicability. It must be repeated at planned intervals and after significant change.
- Risk treatmentGRCISO 27001
- Deciding how to handle each identified risk — mitigate, accept, transfer or avoid — and recording the choice in a risk treatment plan. Selected controls feed the Statement of Applicability. Mitigation reduces likelihood or impact by applying controls; acceptance means the residual risk is tolerated and signed off by the risk owner; transfer shares it with a third party such as an insurer or supplier; avoidance stops the activity that creates the risk. ISO 27001 (clause 6.1.3) requires the plan to be approved by risk owners, who also accept the residual risk that remains after controls are applied. The plan names owners, target dates and the controls chosen, and is reviewed as risks and the business change — making risk treatment the bridge between the risk assessment and day-to-day security operations.
- RPO / RTOGRC
- Recovery Point Objective and Recovery Time Objective — RPO is the maximum acceptable data loss measured in time; RTO is the maximum acceptable time to restore a service after an incident. The two answer different questions: RPO drives how often you back up or replicate (an RPO of one hour means you can lose at most an hour of data, so you must capture it at least hourly), while RTO drives how fast and how redundantly you must be able to recover (a four-hour RTO rules out restoring from cold offsite tape). They are set per business process during a business impact analysis and balanced against cost — near-zero objectives demand expensive real-time replication and standby infrastructure. Together they turn vague continuity ambitions into measurable targets that backup, disaster recovery and continuity plans must meet.
- SOC 2GRCRegulation
- An attestation report (AICPA) evaluating a service organisation’s controls against five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I assesses design at a point in time; Type II assesses operating effectiveness over a period. Security (the “common criteria”) is always in scope; the other four are optional and chosen to match the commitments made to customers. A SOC 2 is an attestation by a licensed CPA firm, not a certification, and the resulting report is typically shared under NDA with prospects and customers. Type II reports usually cover a 3–12 month observation window and are the version enterprise buyers most often request during vendor reviews.
- Statement of Applicability(SoA / DdA)ISO 27001
- A mandatory ISO 27001 document listing every Annex A control, whether it is applicable, the justification, and its implementation status. It is the central map auditors use to navigate an ISMS. Required by clause 6.1.3(d), the SoA links the results of risk treatment to concrete controls: for each of the 93 Annex A controls it records the decision to include or exclude it, the reason (for example a risk it addresses, or why it is not relevant), and whether it is already implemented. Crucially, every exclusion must be justified — auditors scrutinise omitted controls closely. Because it ties risks, controls and status together in one place, the SoA is usually the first document a certification auditor requests and the reference point for the entire Stage 2 audit.
- Vulnerability ManagementPoliciesGRC
- The continuous process of identifying, evaluating, prioritising and remediating security weaknesses across systems and software, typically driven by regular scanning, severity scoring and defined remediation timelines. Vulnerabilities are commonly catalogued as CVEs and scored with CVSS, but mature programmes prioritise by real-world risk — combining severity with exposure, asset criticality and whether exploitation is actually being observed (for example via exploit-prediction signals or the CISA Known Exploited Vulnerabilities catalogue) rather than patching by raw score alone. The cycle is continuous: discover assets, scan, triage, remediate or mitigate, then verify the fix and feed lessons back. It is distinct from one-off penetration testing and is referenced by ISO 27002 control 8.8 and CIS Control 7. Clear remediation SLAs by severity, plus reporting on mean time to remediate, are what turn scanning output into measurable risk reduction.
- Read the full guide →See a related PDF template →
- Zero TrustGRCPolicies
- A security model that assumes no implicit trust based on network location. Every request is continuously authenticated, authorised and validated against policy, regardless of whether it originates inside or outside the corporate perimeter. It replaces the old “castle and moat” approach, where anything inside the network was trusted, with the maxim “never trust, always verify” — appropriate now that cloud services, remote work and mobile devices have dissolved the perimeter. In practice it relies on strong identity (MFA and device posture checks), least-privilege and just-in-time access, micro-segmentation to limit lateral movement, and continuous monitoring so that trust is re-evaluated on every request rather than granted once at login. NIST SP 800-207 is the reference architecture. Zero Trust is a strategy realised through many controls, not a single product, and is typically adopted incrementally.
From definition to document, in 5 minutes
PolicyForge turns these concepts into audit-ready policies aligned with ISO 27001, SOC 2, GDPR, NIS2 and DORA.