Shared language
Terms of the New Era
A guide to the concepts we use across our services — Resilience, Cybersecurity, Compliance, ESG, AI Governance — so management, IT and Compliance share a common language.
Governance • Risk • Compliance
- Governance
- decision-making structure and accountability
- Risk
- likelihood × impact on operations
- Compliance
- proof that obligations are met
- GRC
- integrated governance of risk and compliance
- Business Resilience
- endurance, continuity and recovery of operations
- Accountability
- clear ownership and responsibility
- Control Framework
- system of controls and approvals
- Controls
- preventive, detective and responsive measures
- Risk Register
- record of risks and mitigating actions
- Audit Readiness
- preparedness for audits
Cybersecurity & Information Protection
- Cybersecurity
- protection of digital services and data
- Information Security
- confidentiality, integrity and availability
- Cyber Risk Assessment
- exposure picture and priorities
- Vulnerability Assessment
- identification of system weaknesses
- Penetration Testing
- controlled simulation of an attack
- Incident Response
- management of security incidents
- Preparedness
- readiness before an incident occurs
- Threat
- potential source of attack
- Third-Party Risk
- risk from suppliers and outsourcing
- ISMS
- information security management system
Regulations & Frameworks
- NIS2
- management accountability for cyber risk
- National Cybersecurity Authority
- NIS2 supervision in Greece
- DORA
- digital operational resilience for financial entities
- GDPR
- rules for personal data protection
- AI Act (EU)
- European regulation of artificial intelligence
- CSRD
- mandatory sustainability reporting
- ESRS
- reporting standards under CSRD
As-a-Service roles
- DPO
- data protection officer
- DPO as a Service
- external DPO with ongoing oversight
- V-CISO
- external executive oversight of security
- AI Officer
- owner of AI use and governance
- AI Officer as a Service
- external oversight of AI compliance
- ESG Officer
- coordination of ESG metrics and governance
- ESG Officer as a Service
- external oversight of ESG operations
ESG & Sustainability
- ESG
- Environment, Social and Governance
- ESG Strategy
- goals, indicators and responsibilities
- ESG Governance
- management oversight of ESG
- Environmental Management
- control of environmental impacts
- Energy Management
- measurement and reduction of consumption
- Emissions (GHG)
- greenhouse gas emissions
Whistleblowing & Integrity
- Whistleblowing
- channel for reporting violations
- Case Handling
- assessment, investigation and documentation
- Anti-Bribery
- prevention of bribery
Business Continuity & Crisis
- Business Continuity
- keeping operations running through disruption
- BIA
- business impact analysis of disruption
- BCP
- business continuity plan
- Crisis Management
- decision structure during a crisis
- Recovery
- restoration of services within time
Strategy & Transformation
- Operating Model
- how the organization actually works
- BPR
- end-to-end process redesign
- Business Planning
- strategy, finances and execution
- Market Expansion
- preparation for new markets
- Funding / NSRF
- funding, eligibility and implementation
ISO standards as operating tools
- ISO 9001
- quality and consistency management system
- ISO 27001
- ISMS and information-risk control
- ISO 27701
- privacy management extending the ISMS
- ISO 22301
- business continuity management system
- ISO 31000
- risk-management framework
- ISO 37001
- anti-bribery management system
- ISO 20000-1
- service management for IT services
- ISO 14001
- environmental management
- ISO 50001
- energy management and performance
- ISO 14064
- GHG measurement and reporting
- ISO 45001
- occupational health and safety
- ISO 26000
- CSR guidance
- ISO 30415
- diversity and inclusion framework
- ISO 42001
- AIMS, AI management system
Digital Trust & AI Governance
- Digital Trust
- trust in digital operations
- AI Governance
- control of AI use and decisions
- AIMS
- AI management system
- Model Risk
- risk arising from AI outputs
- Human Oversight
- a person reviews critical decisions
Managed Services & Continuous Oversight
- Managed Compliance Services
- ongoing oversight of obligations
- Compliance Calendar
- programme of actions and reviews
- Reporting
- management updates with indicators
- Continuous Improvement
- operating improvement cycle
Not sure what applies to you?
Talk to the team and get a concise executive view of the terms and obligations that matter to your organization.
Contact us 3–4 minutes, executive summary