Glossary

Plain definitions of the risk, compliance and cyber terms used across our products and write-ups.

Terms

Attack surface
Everything an attacker can reach from outside your organisation: internet-facing systems, domains, cloud services and exposed credentials.
ALE (annualised loss expectancy)
The loss a risk is expected to cause in a year. In its simple form it is the cost of one event multiplied by how many times a year it is expected to happen; in FAIR it is a range rather than a single number.
BCM (business continuity management)
The plans and practices that keep critical business services running, or restore them quickly, during and after a disruption.
Control testing
Checking, on a schedule and with evidence, that a control is designed properly and actually works. Results should update the risk assessment the control supports.
CRQ (cyber risk quantification)
Expressing cyber risk as probable financial loss rather than as high, medium or low ratings.
FAIR (Factor Analysis of Information Risk)
An open standard model for quantifying information and operational risk in financial terms, by breaking risk down into how often a loss event is likely to occur and how much it is likely to cost.
GRC (governance, risk and compliance)
The combined practice of setting direction and policy, managing risk, and meeting regulatory and contractual obligations.
Impact tolerance
The maximum level of disruption to an important business service that an organisation can tolerate, usually set as a maximum time the service can be unavailable.
Inherent risk
The level of a risk before any controls are taken into account.
KRI (key risk indicator)
A measure that signals rising exposure to a risk, tracked against thresholds so action can be taken before a loss occurs.
Loss event
An incident that caused a financial loss, recorded with its cause, the risks and controls involved, and the amount. Near misses are recorded the same way, without the loss.
RCSA (risk and control self-assessment)
A process in which business units identify their risks, assess the controls that address them, and rate inherent and residual risk.
Residual risk
The level of a risk that remains after controls are taken into account.
Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, usually expressed as limits and thresholds.
RPO (recovery point objective)
The maximum amount of data, measured in time, that can be lost when a system is restored after a disruption.
RTO (recovery time objective)
The maximum acceptable time to restore a process or system after a disruption.
Third-party risk
Risk that arises from suppliers, vendors and other organisations you depend on, including their access to your data and systems.
vCISO (virtual chief information security officer)
Senior security leadership provided part-time or on retainer, instead of a full-time hire.

Frequently asked questions

Is a term missing?

Tell us through the contact page and we will add it.

Where are these terms used?

Across 4Sight Risk Management, the other 4Sight modules and our write-ups.

See these ideas working in 4Sight.

Book a demo on sample data, or start with the free two-minute assessment.