Backup
A separate copy of data that can be used to restore it after loss or damage.
In practice: A successful backup job does not prove that recovery works. A restore test checks whether the copy can actually be used.
Related help: Infrastructure & modernisation ↗Cloud
Computing services rented from a provider rather than all running on equipment you operate.
In practice: A cloud-hosted application still needs access management, maintenance responsibilities and a recovery plan.
Related help: Infrastructure & modernisation ↗Cyber Resilience Act (CRA)
An EU regulation that sets cybersecurity, vulnerability handling and reporting requirements for products with digital elements.
In practice: A manufacturer may need to maintain a vulnerability process throughout a product’s support period and report certain actively exploited vulnerabilities or severe incidents.
Related help: CRA preparation & reporting support ↗Dependency
Something a system needs in order to work.
In practice: Your application may depend on a database, an identity service or an external payment provider.
Related help: IT systems & architecture review ↗DevSecOps
Including security checks and responsibilities in the way software is built, released and maintained.
In practice: Checking dependencies during a build helps only if somebody reviews relevant findings and takes action.
Related help: Cybersecurity & audit preparation ↗Disaster recovery
The arrangements for restoring systems after a serious disruption.
In practice: A recovery plan identifies what to restore first, who will do it and how the restored service will be checked.
Related help: Infrastructure & modernisation ↗Fractional leadership
An agreed part-time leadership role instead of a full-time appointment.
In practice: An external technical lead may review decisions and coordinate work on a regular schedule. Availability must be agreed.
Related help: External technical leadership ↗ISO 27001
An international standard for managing information security through a management system.
In practice: Technical safeguards are part of the work. Certification also considers the organisation’s management processes and is assessed by a certification body.
Related help: Cybersecurity & audit preparation ↗Reference: ISO/IEC 27001
IT architecture
How applications, infrastructure and data fit together.
In practice: If your sales system relies on a warehouse application, the connection and its operating needs are part of the architecture.
Related help: IT systems & architecture review ↗Migration
Moving a system, application or data from one setup to another.
In practice: Moving an application to a new server needs testing, an agreed cutover and a way to recover if the move fails.
Related help: Infrastructure & modernisation ↗NIS2
An EU directive setting cybersecurity requirements for certain organisations, implemented through national law.
In practice: Whether your organisation is covered and which obligations apply depends on its circumstances and the relevant national rules.
Related help: Cybersecurity & audit preparation ↗Reference: NIS2 directive
Penetration test
An authorised security test that attempts to exploit weaknesses within an agreed scope.
In practice: A test might examine whether an attacker can access data through a web application. Fixing the reported issues is a separate piece of work.
Related help: Security findings & fixes ↗Remediation
Work to fix a problem or reduce its risk, followed by a check of the result.
In practice: After an audit identifies an exposed internal tool, remediation might mean changing access, testing it and recording the change.
Related help: Security findings & fixes ↗SBOM
A software bill of materials: a list of the components included in a software product.
In practice: It helps a team check whether a newly reported vulnerability concerns a library used in its product. The list itself does not fix anything.
Related help: CRA preparation & reporting support ↗Security control
A safeguard intended to reduce a security risk.
In practice: Requiring a second sign-in factor helps protect accounts when a password is stolen.
Related help: Cybersecurity & audit preparation ↗Security evidence
Records that support a statement about how security is managed.
In practice: A dated access review or restore-test record supports an answer that a control is actually used.
Related help: Cybersecurity & audit preparation ↗Technical debt
Earlier technical choices that make later changes or maintenance harder.
In practice: A temporary integration that becomes permanent may require extra work every time either system changes.
Related help: IT systems & architecture review ↗Total cost of ownership
The cost of using and maintaining a solution over a chosen period, including more than its purchase price.
In practice: A comparison might include setup, licences, hosting, support, training and the eventual cost of moving away.
Related help: Technology & supplier decisions ↗Vendor lock-in
Dependence on a supplier or technology that makes switching difficult or expensive.
In practice: Data export limits or proprietary integrations can increase the work needed to leave a platform.
Related help: Technology & supplier decisions ↗VEX
Vulnerability Exploitability eXchange: information about whether a known vulnerability affects a particular product.
In practice: A component may contain a vulnerable function that the product never uses. That conclusion needs technical justification and review when the product changes.
Related help: CRA preparation & reporting support ↗Vulnerability
A weakness that could be used to compromise a system or its information.
In practice: An unpatched application may allow someone to access data they should not be able to see.
Related help: Security findings & fixes ↗