Glossary
The vocabulary, without approximation
An hour of reading that prevents six months of misunderstanding. Every term is reformulated in our words and points to its normative source.
A
B
A copy of data held separately to enable restoration. The 3-2-1-1-0 rule summarises good practice: three copies, two media, one off-site, one immutable, zero verified restore errors.
DORA art. 12 / CIS Controls v8.1, contrôle 11
An analysis technique linking the causes of a top event to its consequences, showing preventive barriers on the left and protective barriers on the right.
IEC 31010:2019
The capability of an organisation to continue delivering products and services at an acceptable predefined level following a disruption. It is a capability, not a document.
ISO 22300:2021
The part of the overall management system that establishes, implements, operates, monitors, reviews, maintains and improves business continuity.
ISO 22301:2019
The process of analysing the consequences of disruption on activities over time, in order to prioritise them and derive quantified recovery requirements.
ISO 22301:2019, 8.2.2 / ISO/TS 22317:2021
C
Third-party attestation that a system, product or person meets specified requirements. For a management system it addresses conformity, not performance.
ISO/IEC 17021-1:2015
The physical or virtual location from which response is directed and coordinated. It must have communication means independent of the everyday information system.
ISO 22320:2018
A shared, continuously updated representation of the situation that lets all responders decide from the same factual basis.
ISO 22320:2018
Exposure arising from dependence on a hard-to-substitute provider, or on several interlinked providers, for a critical function.
Règlement (UE) 2022/2554, art. 29
Maintaining and developing professional competence over time, usually measured in points or hours and required to retain an individual certification.
BCI / DRI International
Action to eliminate the cause of a nonconformity so that it does not recur. Distinct from correction, which only addresses the observed effect.
ISO 22301:2019, 10.1
An unusual, unstable and complex situation that threatens an organisation's strategic objectives, reputation or viability. What defines it is uncertainty, not severity.
ISO 22361:2022
A mandated group responsible for managing a crisis: assessing the situation, deciding, allocating resources and communicating. It arbitrates; it does not execute.
ISO 22361:2022
An activity whose failure would materially impair the viability of the institution or the stability of the financial system.
BCBS 516
A function whose disruption would materially impair a financial entity's financial performance, soundness or continuity of services, or its compliance with the conditions of its authorisation.
Règlement (UE) 2022/2554, art. 3
D
A representation of the resources — people, processes, technology, facilities, information, third parties — required to deliver a service, and of their relationships.
BCBS 516, principe 4
An event, anticipated or not, that causes an unplanned negative deviation from the expected delivery of products and services.
ISO 22300:2021
E
A process to train for, assess, practise or improve performance in an organisation. An exercise without measurable objectives is a meeting.
ISO 22398:2013
A documented plan to terminate an outsourcing arrangement without interrupting service delivery or breaching regulatory requirements. It must be established before signature.
EBA/GL/2019/02 / DORA art. 28
F
G
H
The common ten-clause structure imposed on all ISO management system standards, which makes integration possible: context, leadership, planning, support, operation, evaluation, improvement.
Directives ISO/IEC, partie 1
A brief communication issued very early in a crisis, acknowledging established facts and announcing next steps, without speculating on causes or responsibility.
ISO 22361:2022
I
The capability of information systems to support business continuity, covering detection, response and recovery — not just technical restoration.
ISO/IEC 27031:2011
A backup that cannot be altered or deleted for a defined period, even by an administrator. It is the only genuinely effective protection against ransomware that compromises the directory.
DORA art. 12 / CIS Controls v8.1
The maximum level of disruption to an important service that an organisation can tolerate, usually expressed in time. It is a regulatory ceiling on harm, not an internal recovery target.
PRA SS1/21 / BCBS 516
A service delivered to an external client or to the market whose disruption would cause intolerable harm. It is expressed from the user's viewpoint, never from the org chart.
PRA SS1/21 / FCA PS21/3
A situation that might lead to a disruption, loss, emergency or crisis. An incident is handled with a known procedure.
ISO 22300:2021
A time-stamped record of facts, decisions and actions during a crisis. It is the single most requested artefact in debriefs, audits and litigation.
Pratique — ISO 22361:2022
Information introduced during an exercise to evolve the situation and force a decision. The quality of an exercise rests on the quality of its injects.
ISO 22398:2013
A person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity.
ISO 22300:2021
A systematic, independent and documented process for obtaining evidence and evaluating it objectively against defined criteria.
ISO 19011:2018 / ISO 22301:2019, 9.2
A plan describing the restoration of information systems at a recovery site or infrastructure. It is a component of the continuity arrangements, not their equivalent.
NIST SP 800-34 Rev. 1
K
L
Structured analysis of an event or exercise to identify what worked, what was missing, and to produce dated, owned actions.
ISO 22398:2013 / NIST SP 800-61
Systematic collection of incidents that caused an operational loss, with amount, cause, business line and event type. Without root cause analysis, collection produces nothing.
BCBS PSMOR, principe 6
M
An ICT incident with a high adverse impact on networks and systems supporting critical or important functions, assessed against harmonised criteria: clients affected, duration, geographical spread, data losses, criticality and economic impact.
Règlement (UE) 2022/2554, art. 3 et 18
A periodic examination of the management system by top management, from defined inputs, producing improvement and resourcing decisions.
ISO 22301:2019, 9.3
The time beyond which the consequences of disruption become unacceptable to the organisation. It is a ceiling, not a target.
ISO 22300:2021
The minimum level of service acceptable to achieve the organisation's objectives during a disruption. It answers: what must we absolutely keep doing?
ISO 22300:2021
N
O
The observe — orient — decide — act cycle that structures response under uncertainty. Whoever cycles fastest keeps the initiative.
Pratique — ISO 22320:2018
The ability of an organisation to deliver critical services through disruption while remaining within impact tolerances set in advance. The reasoning starts from the service delivered to the client, not the internal process.
BCBS 516 / PRA SS1/21
A structured classification of operational risk event types, enabling loss aggregation and comparison across business lines or institutions.
Cadre de Bâle, OPE
P
The continual improvement cycle underpinning all ISO management systems. Without the "check" step, the system ossifies.
Annexe SL — Structure harmonisée
An activity to which urgency is given in order to avoid unacceptable impacts during a disruption. Prioritisation results from the BIA, not from a declaration by the business line concerned.
ISO 22300:2021
R
Malware that encrypts or exfiltrates data for extortion. It is today the reference scenario for most continuity exercises.
ENISA / NIST SP 800-61
The volume of data, expressed in time, that the organisation accepts losing during a disruption. A four-hour RPO means the last four hours of input may be lost.
ISO 22300:2021
The period of time within which an activity, product or service must be resumed after disruption, and the associated resources restored.
ISO 22300:2021
The team simulating the adversary during a resilience test, reproducing real methods without the defenders being informed.
TIBER-EU
A structured inventory of all contractual arrangements on the use of ICT services provided by third parties, submitted annually to the competent authority.
Règlement (UE) 2022/2554, art. 28
The risk remaining after treatment. It must be explicitly accepted by a body with the authority to do so.
ISO 31000:2018
The ability to absorb a shock and adapt to a changing environment. It subsumes continuity but adds adaptation and learning.
ISO 22300:2021 / ISO 22316:2017
An exercise in which frontline staff identify their risks, assess control effectiveness and determine residual risk.
BCBS PSMOR, principe 6
The level and nature of risk the organisation is willing to take to achieve its objectives. To be usable it is expressed in thresholds, not adjectives.
ISO 31000:2018 / COSO ERM 2017
S
A description of a hypothetical situation used as the basis for an exercise or a risk analysis. It must be severe but plausible to produce usable learning.
IEC 31010:2019 / BCBS 516
The calibration criterion for a test scenario: severe enough to stress the arrangements, credible enough that management accepts the conclusions.
BCBS 516 / PRA SS1/21
An element whose failure alone is enough to interrupt an entire service. Dependency maps exist first and foremost to expose them.
DORA art. 10 / BCBS 516
T
A discussion-based exercise guided by a scenario, with no real resources mobilised. The most effective format for testing decision-making and interfaces.
ISO 22398:2013
A test simulating real adversaries' tactics, techniques and procedures against production systems, conducted within an authority-supervised framework.
TIBER-EU / DORA art. 26
A risk governance model: the first line takes and manages risk, the second oversees and challenges it, the third provides independent assurance. Three roles, not three hierarchical levels.
BCBS PSMOR / IIA