Security terms, explained clearly.
Plain-language definitions for the work behind security controls, evidence, incident response, and framework readiness.
AI triage
AI triage is the use of artificial intelligence to enrich, summarize, classify, prioritize, route, or suggest next steps for security reports and incidents.
Alert
A security alert is a notification that activity may require investigation, usually generated by a monitoring, detection, or reporting source.
Audit evidence
Audit evidence is reliable information or records used to show that a requirement, control, process, or decision exists and operates as described.
Control applicability
Control applicability is the reasoned decision about whether a security control is relevant to an organization's scope, risks, requirements, or operating model.
Control mapping
Control mapping connects security controls to the policies, processes, owners, and evidence that support their implementation.
Control owner
A control owner is the person or role accountable for keeping a security control defined, implemented, evidenced, and reviewed.
Event
A security event is an observable occurrence in a system or process; it may be harmless, suspicious, or part of a larger incident.
Evidence gap
An evidence gap is a missing or incomplete artifact needed to show that a security control exists and works.
Human-in-the-loop AI
Human-in-the-loop AI is an operating model where people review, approve, correct, or reject AI suggestions before material security decisions are made.
Incident
An incident is an event that threatens the confidentiality, integrity, or availability of systems, data, or services and requires a coordinated response.
Incident severity
Incident severity is a classification of the business, technical, legal, and customer impact of a security incident.
Incident timeline
An incident timeline is the ordered record of facts, decisions, actions, and communications during a security incident.
Incident triage
Incident triage is the first structured review used to validate a security signal, assess impact, set priority, and assign the next action.
ISO 27001
ISO/IEC 27001 is an international standard for establishing, operating, maintaining, and continually improving an information security management system.
Mean Time to Acknowledge (MTTA)
Mean Time to Acknowledge (MTTA) measures how long it takes a team to recognize and accept ownership of a reported incident or alert.
Mean Time to Resolve (MTTR)
Mean Time to Resolve (MTTR) measures the average time from identifying an incident to restoring service, containing the issue, or completing the defined resolution.
NIS2
NIS2 is the EU cybersecurity directive that sets risk management, incident reporting, governance, and supply-chain expectations for covered entities.
NIST CSF
The NIST Cybersecurity Framework is a flexible way to organize cybersecurity outcomes, risk discussions, improvement priorities, and evidence.
Risk register
A risk register is a maintained record of security and business risks, their owners, treatment decisions, status, and review history.
Root cause analysis
Root cause analysis is a structured review of why an incident happened, how it progressed, and which changes can reduce recurrence.
Security control
A security control is a safeguard, process, or responsibility used to reduce risk and protect systems, data, people, or business operations.
Security framework readiness
Security framework readiness is the state of being prepared to demonstrate controls, evidence, owners, and gaps against a framework or buyer expectation.
Security policy
A security policy is an approved statement of direction and expected behavior for protecting an organization's systems, data, and operations.
Security workflow automation
Security workflow automation uses connected rules, tools, and approvals to move recurring security work from intake through action, evidence, and review.
Significant incident
A significant incident is a security incident whose impact or characteristics meet applicable reporting or escalation criteria under the relevant NIS2 rules.
Statement of Applicability
A Statement of Applicability records which ISO 27001 Annex A controls apply, which do not, why decisions were made, and how implementation is tracked.
Supply-chain security
Supply-chain security is the practice of managing cybersecurity risks introduced by suppliers, service providers, software, and dependencies.
Vendor risk
Vendor risk is the security, privacy, resilience, and operational risk introduced by suppliers and service providers that support a business.
