Resources

Compliance glossary

36 terms you will meet working towards ISO 27001, the Essential Eight and Australian privacy obligations, in plain English. Each links to where we go deeper.

A

Annex A
The list of 93 information security controls in ISO/IEC 27001:2022, grouped into organisational, people, physical and technological themes. You decide which apply to you and record why in the Statement of Applicability. Inside a Statement of Applicability →
APRA CPS 230
APRA’s operational risk management standard, in force from 1 July 2025. It covers operational risk, business continuity and the management of material service providers. CPS 230 and the Essential Eight →
APRA CPS 234
The prudential standard requiring APRA-regulated entities (banks, insurers, superannuation trustees) to maintain information security capability that matches their threats, test their controls and notify APRA of material incidents. CPS 234 services →
Australian Privacy Principles (APPs)
The 13 principles in the Privacy Act 1988 that govern how Australian Government agencies, organisations with annual turnover above $3 million and some smaller ones (such as health service providers) collect, use, disclose and secure personal information. Privacy Act readiness →

C

Certification body
An independent organisation, accredited to audit against a standard such as ISO/IEC 27001, that runs your Stage 1 and Stage 2 audits and issues the certificate.
Control owner
The person accountable for a control working: keeping it in place, producing its evidence and fixing it when it fails.
Corrective action
What you do about a nonconformity: fix it, find the root cause, act on the cause so it does not happen again, and check that the action worked (ISO/IEC 27001 Clause 10.2).

D

Defence Industry Security Program (DISP)
The Department of Defence program that sets security requirements for businesses working on Defence contracts, with membership levels for governance, personnel, physical and information security. DISP requirements →

E

Essential Eight
The eight mitigation strategies the Australian Signals Directorate recommends as a baseline against cyber attacks, such as patching, multi-factor authentication, application control and backups. Essential Eight guide →
Essential Eight maturity level
How fully the Essential Eight is implemented, from Maturity Level Zero to Three. Each level is aimed at a more capable adversary; Maturity Level Two is a common target for government suppliers. ML2 or ML3? →
Evidence
The records that show a control or requirement is in place and working: a configuration export, a review record, signed minutes, a training report. Auditors sample it.

I

Information Security Management System (ISMS)
The policies, processes, roles and records an organisation uses to manage information security risk and keep improving. ISO/IEC 27001 sets out what one must include. What an ISMS really is →
Information Security Manual (ISM)
The Australian Signals Directorate’s framework of security controls for Australian Government systems, used as the basis for IRAP assessments. DISP, ISM and IRAP services →
Internal audit
Your own planned check that the ISMS meets the standard and your own rules and is working (ISO/IEC 27001 Clause 9.2). Auditors must not audit their own work.
IRAP
The Infosec Registered Assessors Program: ASD-endorsed assessors who assess systems against the Information Security Manual, typically for Australian Government use. DISP, ISM and IRAP services →
IS18
The Queensland Government’s information security policy, which requires departments to run an ISMS aligned to ISO/IEC 27001. IS18 services →
ISO/IEC 27001
The international standard for an information security management system, and the one organisations certify against. ISO 27001 services →
ISO/IEC 27701
The standard for a privacy information management system. Its 2025 edition can be certified on its own, without ISO/IEC 27001. ISO 27701:2025 →
ISO/IEC 42001
The standard for an AI management system: how an organisation governs the AI it builds or uses, including risk and impact assessment. ISO 42001 services →

M

Management review
Top management’s planned review of whether the ISMS is suitable, adequate and effective, with decisions on changes and resources (ISO/IEC 27001 Clause 9.3).

N

NIST Cybersecurity Framework (NIST CSF)
A US framework of cyber security outcomes, organised under Govern, Identify, Protect, Detect, Respond and Recover, often used in Australian due-diligence questionnaires. NIST CSF in Australia →
Nonconformity
A requirement not met, whether of the standard or of your own policies. An auditor grades it as major or minor.
Notifiable Data Breaches scheme (NDB)
The part of the Privacy Act requiring an assessment, within 30 days, of a suspected data breach, and notice to the OAIC and affected people when a breach is likely to cause serious harm. Privacy Act readiness →

R

Ransomware payment report
Under the Cyber Security Act 2024, businesses with annual turnover over $3 million, and critical infrastructure entities, must report a ransomware payment to the Australian Signals Directorate within 72 hours. Ransomware reporting readiness →
Record of processing activities (RoPA)
A register of the personal information an organisation handles: what it is, why, where it goes and how long it is kept. What a good RoPA looks like →
Residual risk
The risk left after your controls and treatment are in place. If it is above your risk appetite, someone with authority must accept it or it needs more treatment.
Right Fit For Risk (RFFR)
The Australian Government’s information security accreditation for providers delivering employment services. RFFR services →
Risk acceptance
A recorded decision by the person accountable to live with a residual risk, with the reason and the date.
Risk appetite
How much risk an organisation is prepared to accept in pursuit of its objectives. Risks scoring above it need treatment or a recorded acceptance.
Risk treatment plan
The actions you will take on each risk (treat, transfer, avoid or accept), who owns them and by when (ISO/IEC 27001 Clause 6.1.3). A risk register in SharePoint →

S

Segregation of duties
Splitting duties so one person cannot both do and approve the same thing, such as writing a policy and approving it (ISO/IEC 27001 control 5.3).
SOC 2
An attestation report under the AICPA’s Trust Services Criteria, common with US customers. It is an auditor’s report on your controls, not a certificate. ISO 27001 or SOC 2? →
Stage 1 audit
The certification body’s first audit: a review of your ISMS documentation and readiness, to decide whether you are ready for Stage 2.
Stage 2 audit
The certification audit itself: the certification body checks your ISMS is implemented and working, by sampling records and interviewing people.
Statement of Applicability (SoA)
The ISO/IEC 27001 document listing every Annex A control, whether it applies to you, why, and whether it is implemented. Inside a Statement of Applicability →
Surveillance audit
The certification body’s audit in each year between certification and recertification, checking a sample of the ISMS is still working. Certificates last three years.
Microsoft Teams