Glossary
Glossary
Plain definitions of the risk, compliance and cyber terms used across our products and write-ups.
Terms
- Attack surface
- Everything an attacker can reach from outside your organisation: internet-facing systems, domains, cloud services and exposed credentials.
- ALE (annualised loss expectancy)
- The loss a risk is expected to cause in a year. In its simple form it is the cost of one event multiplied by how many times a year it is expected to happen; in FAIR it is a range rather than a single number.
- BCM (business continuity management)
- The plans and practices that keep critical business services running, or restore them quickly, during and after a disruption.
- Control testing
- Checking, on a schedule and with evidence, that a control is designed properly and actually works. Results should update the risk assessment the control supports.
- CRQ (cyber risk quantification)
- Expressing cyber risk as probable financial loss rather than as high, medium or low ratings.
- FAIR (Factor Analysis of Information Risk)
- An open standard model for quantifying information and operational risk in financial terms, by breaking risk down into how often a loss event is likely to occur and how much it is likely to cost.
- GRC (governance, risk and compliance)
- The combined practice of setting direction and policy, managing risk, and meeting regulatory and contractual obligations.
- Impact tolerance
- The maximum level of disruption to an important business service that an organisation can tolerate, usually set as a maximum time the service can be unavailable.
- Inherent risk
- The level of a risk before any controls are taken into account.
- KRI (key risk indicator)
- A measure that signals rising exposure to a risk, tracked against thresholds so action can be taken before a loss occurs.
- Loss event
- An incident that caused a financial loss, recorded with its cause, the risks and controls involved, and the amount. Near misses are recorded the same way, without the loss.
- RCSA (risk and control self-assessment)
- A process in which business units identify their risks, assess the controls that address them, and rate inherent and residual risk.
- Residual risk
- The level of a risk that remains after controls are taken into account.
- Risk appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, usually expressed as limits and thresholds.
- RPO (recovery point objective)
- The maximum amount of data, measured in time, that can be lost when a system is restored after a disruption.
- RTO (recovery time objective)
- The maximum acceptable time to restore a process or system after a disruption.
- Third-party risk
- Risk that arises from suppliers, vendors and other organisations you depend on, including their access to your data and systems.
- vCISO (virtual chief information security officer)
- Senior security leadership provided part-time or on retainer, instead of a full-time hire.
Frequently asked questions
Is a term missing?
Tell us through the contact page and we will add it.
Where are these terms used?
Across 4Sight Risk Management, the other 4Sight modules and our write-ups.
Related
See these ideas working in 4Sight.
Book a demo on sample data, or start with the free two-minute assessment.