Your glossary for risk and compliance
Helpful definitions of all of the terms you need to know to better manage risk and compliance.
Terms
AFSL Authorised Representative AICPA Annex A Controls ASIC Attestation of Compliance (AOC) Business Continuity Management Compliance Automation Software Compliance Risk Management Cybersecurity Maturity Model Certification (CMMC) FedRAMP Governance Risk & Compliance (GRC) GPDR HIPAA HITRUST Incident Management Information Security Management System (ISMS) ISMS Governing Body ISO 27001 Notifiable Data Breach OAIC Policy Management SOC 1 SOC 2 SOC 3 SOC Reports SOC Trust Services Criteria (TSC) SSAE 16 SSAE 18 Third Party Risk Management Vendor Assessment Vendor Management Policy Vendor Review Vulnerability Vulnerability Management
ISO 27001
Cyber security
SOC
What is an Information Security Management System (ISMS)?
An Information Security Management System, also known as an ISMS, is a systematic approach consisting of processes, technology and people that helps you protect and manage your organisation’s information through effective risk management. It enables compliance with a range of standards, laws and regulations including IEC/ISO 27001, FedRAMP, SOC2, NIST CSF, and focuses on protecting three key aspects of information:
- Confidentiality: The information is not available or disclosed to unauthorised people, entities or processes.
- Integrity: The information is complete and accurate, and protected from corruption.
- Availability: The information is accessible and usable by authorised users.