Resources
Compliance glossary
36 terms you will meet working towards ISO 27001, the Essential Eight and Australian privacy obligations, in plain English. Each links to where we go deeper.
A
- Annex A
- The list of 93 information security controls in ISO/IEC 27001:2022, grouped into organisational, people, physical and technological themes. You decide which apply to you and record why in the Statement of Applicability. Inside a Statement of Applicability →
- APRA CPS 230
- APRA’s operational risk management standard, in force from 1 July 2025. It covers operational risk, business continuity and the management of material service providers. CPS 230 and the Essential Eight →
- APRA CPS 234
- The prudential standard requiring APRA-regulated entities (banks, insurers, superannuation trustees) to maintain information security capability that matches their threats, test their controls and notify APRA of material incidents. CPS 234 services →
- Australian Privacy Principles (APPs)
- The 13 principles in the Privacy Act 1988 that govern how Australian Government agencies, organisations with annual turnover above $3 million and some smaller ones (such as health service providers) collect, use, disclose and secure personal information. Privacy Act readiness →
C
- Certification body
- An independent organisation, accredited to audit against a standard such as ISO/IEC 27001, that runs your Stage 1 and Stage 2 audits and issues the certificate.
- Control owner
- The person accountable for a control working: keeping it in place, producing its evidence and fixing it when it fails.
- Corrective action
- What you do about a nonconformity: fix it, find the root cause, act on the cause so it does not happen again, and check that the action worked (ISO/IEC 27001 Clause 10.2).
D
- Defence Industry Security Program (DISP)
- The Department of Defence program that sets security requirements for businesses working on Defence contracts, with membership levels for governance, personnel, physical and information security. DISP requirements →
E
- Essential Eight
- The eight mitigation strategies the Australian Signals Directorate recommends as a baseline against cyber attacks, such as patching, multi-factor authentication, application control and backups. Essential Eight guide →
- Essential Eight maturity level
- How fully the Essential Eight is implemented, from Maturity Level Zero to Three. Each level is aimed at a more capable adversary; Maturity Level Two is a common target for government suppliers. ML2 or ML3? →
- Evidence
- The records that show a control or requirement is in place and working: a configuration export, a review record, signed minutes, a training report. Auditors sample it.
I
- Information Security Management System (ISMS)
- The policies, processes, roles and records an organisation uses to manage information security risk and keep improving. ISO/IEC 27001 sets out what one must include. What an ISMS really is →
- Information Security Manual (ISM)
- The Australian Signals Directorate’s framework of security controls for Australian Government systems, used as the basis for IRAP assessments. DISP, ISM and IRAP services →
- Internal audit
- Your own planned check that the ISMS meets the standard and your own rules and is working (ISO/IEC 27001 Clause 9.2). Auditors must not audit their own work.
- IRAP
- The Infosec Registered Assessors Program: ASD-endorsed assessors who assess systems against the Information Security Manual, typically for Australian Government use. DISP, ISM and IRAP services →
- IS18
- The Queensland Government’s information security policy, which requires departments to run an ISMS aligned to ISO/IEC 27001. IS18 services →
- ISO/IEC 27001
- The international standard for an information security management system, and the one organisations certify against. ISO 27001 services →
- ISO/IEC 27701
- The standard for a privacy information management system. Its 2025 edition can be certified on its own, without ISO/IEC 27001. ISO 27701:2025 →
- ISO/IEC 42001
- The standard for an AI management system: how an organisation governs the AI it builds or uses, including risk and impact assessment. ISO 42001 services →
M
- Management review
- Top management’s planned review of whether the ISMS is suitable, adequate and effective, with decisions on changes and resources (ISO/IEC 27001 Clause 9.3).
N
- NIST Cybersecurity Framework (NIST CSF)
- A US framework of cyber security outcomes, organised under Govern, Identify, Protect, Detect, Respond and Recover, often used in Australian due-diligence questionnaires. NIST CSF in Australia →
- Nonconformity
- A requirement not met, whether of the standard or of your own policies. An auditor grades it as major or minor.
- Notifiable Data Breaches scheme (NDB)
- The part of the Privacy Act requiring an assessment, within 30 days, of a suspected data breach, and notice to the OAIC and affected people when a breach is likely to cause serious harm. Privacy Act readiness →
R
- Ransomware payment report
- Under the Cyber Security Act 2024, businesses with annual turnover over $3 million, and critical infrastructure entities, must report a ransomware payment to the Australian Signals Directorate within 72 hours. Ransomware reporting readiness →
- Record of processing activities (RoPA)
- A register of the personal information an organisation handles: what it is, why, where it goes and how long it is kept. What a good RoPA looks like →
- Residual risk
- The risk left after your controls and treatment are in place. If it is above your risk appetite, someone with authority must accept it or it needs more treatment.
- Right Fit For Risk (RFFR)
- The Australian Government’s information security accreditation for providers delivering employment services. RFFR services →
- Risk acceptance
- A recorded decision by the person accountable to live with a residual risk, with the reason and the date.
- Risk appetite
- How much risk an organisation is prepared to accept in pursuit of its objectives. Risks scoring above it need treatment or a recorded acceptance.
- Risk treatment plan
- The actions you will take on each risk (treat, transfer, avoid or accept), who owns them and by when (ISO/IEC 27001 Clause 6.1.3). A risk register in SharePoint →
S
- Segregation of duties
- Splitting duties so one person cannot both do and approve the same thing, such as writing a policy and approving it (ISO/IEC 27001 control 5.3).
- SOC 2
- An attestation report under the AICPA’s Trust Services Criteria, common with US customers. It is an auditor’s report on your controls, not a certificate. ISO 27001 or SOC 2? →
- Stage 1 audit
- The certification body’s first audit: a review of your ISMS documentation and readiness, to decide whether you are ready for Stage 2.
- Stage 2 audit
- The certification audit itself: the certification body checks your ISMS is implemented and working, by sampling records and interviewing people.
- Statement of Applicability (SoA)
- The ISO/IEC 27001 document listing every Annex A control, whether it applies to you, why, and whether it is implemented. Inside a Statement of Applicability →
- Surveillance audit
- The certification body’s audit in each year between certification and recertification, checking a sample of the ISMS is still working. Certificates last three years.