Your glossary for risk and compliance
Helpful definitions of all of the terms you need to know to better manage risk and compliance.
Terms
AFSL Authorised Representative AICPA Annex A Controls ASIC Attestation of Compliance (AOC) Business Continuity Management Compliance Automation Software Compliance Risk Management Cybersecurity Maturity Model Certification (CMMC) FedRAMP Governance Risk & Compliance (GRC) GPDR HIPAA HITRUST Incident Management Information Security Management System (ISMS) ISMS Governing Body ISO 27001 Notifiable Data Breach OAIC Policy Management SOC 1 SOC 2 SOC 3 SOC Reports SOC Trust Services Criteria (TSC) SSAE 16 SSAE 18 Third Party Risk Management Vendor Assessment Vendor Management Policy Vendor Review Vulnerability Vulnerability Management
Cyber security
What is an ISMS Governing Body?
An ISMS governing body is an organizational governance team with management oversight, composed of key members of top management—typically defined as senior leadership and executive management responsible for strategic decisions and resource allocation—from within the organization.
The ISMS governing body provides appropriate management oversight for the organization’s Information Security Management System (ISMS) to ensure:
- Information security objectives are in alignment with the business strategy to help meet the organization’s strategic objectives.
- A risk management program identifies and mitigates the risks to an organization’s resources and assets and produces the intended results.
- Policies and procedures supporting the organization’s ISMS are reviewed, approved, and remain current.
- Appropriate allocation and use of resources to meet intended objectives.
- According to established policies and procedures, an internal audit program is defined and carried out, including sufficient independence to maintain a separation of duties and avoid conflicts of interest.
- Metrics such as Key Performance Indicators (KPIs) are defined, useful, and reported to ensure the achievement of intended outcomes and the effectiveness of the ISMS.
Necessary adjustments improve the ISMS.