Glossary

The vocabulary, without approximation

An hour of reading that prevents six months of misunderstanding. Every term is reformulated in our words and points to its normative source.

A

B

C

Certification

Third-party attestation that a system, product or person meets specified requirements. For a management system it addresses conformity, not performance.

ISO/IEC 17021-1:2015

Command postPC

The physical or virtual location from which response is directed and coordinated. It must have communication means independent of the everyday information system.

ISO 22320:2018

Common operating picture

A shared, continuously updated representation of the situation that lets all responders decide from the same factual basis.

ISO 22320:2018

Concentration risk

Exposure arising from dependence on a hard-to-substitute provider, or on several interlinked providers, for a critical function.

Règlement (UE) 2022/2554, art. 29

Continuing professional developmentCPD

Maintaining and developing professional competence over time, usually measured in points or hours and required to retain an individual certification.

BCI / DRI International

Corrective action

Action to eliminate the cause of a nonconformity so that it does not recur. Distinct from correction, which only addresses the observed effect.

ISO 22301:2019, 10.1

Crisis

An unusual, unstable and complex situation that threatens an organisation's strategic objectives, reputation or viability. What defines it is uncertainty, not severity.

ISO 22361:2022

Crisis management team

A mandated group responsible for managing a crisis: assessing the situation, deciding, allocating resources and communicating. It arbitrates; it does not execute.

ISO 22361:2022

Critical operation

An activity whose failure would materially impair the viability of the institution or the stability of the financial system.

BCBS 516

Critical or important function

A function whose disruption would materially impair a financial entity's financial performance, soundness or continuity of services, or its compliance with the conditions of its authorisation.

Règlement (UE) 2022/2554, art. 3

D

E

F

G

H

I

ICT readiness for business continuityIRBC

The capability of information systems to support business continuity, covering detection, response and recovery — not just technical restoration.

ISO/IEC 27031:2011

Immutable backup

A backup that cannot be altered or deleted for a defined period, even by an administrator. It is the only genuinely effective protection against ransomware that compromises the directory.

DORA art. 12 / CIS Controls v8.1

Impact tolerance

The maximum level of disruption to an important service that an organisation can tolerate, usually expressed in time. It is a regulatory ceiling on harm, not an internal recovery target.

PRA SS1/21 / BCBS 516

Important business serviceIBS

A service delivered to an external client or to the market whose disruption would cause intolerable harm. It is expressed from the user's viewpoint, never from the org chart.

PRA SS1/21 / FCA PS21/3

Incident

A situation that might lead to a disruption, loss, emergency or crisis. An incident is handled with a known procedure.

ISO 22300:2021

Incident log

A time-stamped record of facts, decisions and actions during a crisis. It is the single most requested artefact in debriefs, audits and litigation.

Pratique — ISO 22361:2022

Inject

Information introduced during an exercise to evolve the situation and force a decision. The quality of an exercise rests on the quality of its injects.

ISO 22398:2013

Interested party

A person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity.

ISO 22300:2021

Internal audit

A systematic, independent and documented process for obtaining evidence and evaluating it objectively against defined criteria.

ISO 19011:2018 / ISO 22301:2019, 9.2

IT disaster recovery planPRA / DRP

A plan describing the restoration of information systems at a recovery site or infrastructure. It is a component of the continuity arrangements, not their equivalent.

NIST SP 800-34 Rev. 1

K

L

M

N

O

P

R

Ransomware

Malware that encrypts or exfiltrates data for extortion. It is today the reference scenario for most continuity exercises.

ENISA / NIST SP 800-61

Recovery point objectiveRPO / PDMA

The volume of data, expressed in time, that the organisation accepts losing during a disruption. A four-hour RPO means the last four hours of input may be lost.

ISO 22300:2021

Recovery time objectiveRTO / DMIA

The period of time within which an activity, product or service must be resumed after disruption, and the associated resources restored.

ISO 22300:2021

Red team

The team simulating the adversary during a resilience test, reproducing real methods without the defenders being informed.

TIBER-EU

Register of information

A structured inventory of all contractual arrangements on the use of ICT services provided by third parties, submitted annually to the competent authority.

Règlement (UE) 2022/2554, art. 28

Residual risk

The risk remaining after treatment. It must be explicitly accepted by a body with the authority to do so.

ISO 31000:2018

Resilience

The ability to absorb a shock and adapt to a changing environment. It subsumes continuity but adds adaptation and learning.

ISO 22300:2021 / ISO 22316:2017

Risk and control self-assessmentRCSA

An exercise in which frontline staff identify their risks, assess control effectiveness and determine residual risk.

BCBS PSMOR, principe 6

Risk appetite

The level and nature of risk the organisation is willing to take to achieve its objectives. To be usable it is expressed in thresholds, not adjectives.

ISO 31000:2018 / COSO ERM 2017

S

T

W