RiskCompass glossary
Find a term with Ctrl+F (on a Mac Cmd+F), or with the search field at the top of the manual.
| Term | Meaning |
|---|---|
| Alert | A notice that a risk deviates from your policy. See Alerts. |
| Approve | Officially sign off a risk. After that it counts in the register and the reassessment period starts. |
| Assessment | The evaluation of one risk: description, impact, likelihood, treatment plan and status. See Assessing a risk. |
| Assessment framework | The yardstick for all assessments: impact criteria, likelihood scale, risk appetite and policy per level. See Assessment framework. |
| Bowtie | An analysis of the causes and consequences of an event, with the barriers in between. In Dutch: vlinderdas. |
| Check | A recorded reassessment of a risk, with a date and a finding. |
| CIA | Confidentiality, integrity and availability. With the CIA breakdown you assess the impact on each of the three separately. |
| Control framework | Your own catalogue of controls, for example ISO 27002 or BIO, which you import yourself. |
| FMEA | Failure Mode and Effects Analysis: an analysis of failure mode, effect, cause and how quickly you notice it. |
| Freezing | A framework version that has already been used for assessments is fixed. You can only make changes in a new version. |
| Impact score | The highest impact level chosen across all categories, from 1 to 5. |
| KPI | A measurement point that shows whether a risk stays under control. |
| Likelihood scale | The series of statements you use to choose the likelihood, from only theoretically possible to happening often in your own company. |
| Likelihood score | The score from the likelihood scale, from 0 to 5. |
| MAPGOOD | Seven angles for finding risks: people, equipment, software, data, organisation, environment and services. |
| Maturity | How far your risk management has come: Starting, Structured, Mature or Advanced. RiskCompass derives it from your method. |
| Method | Which components of risk management your organisation uses, and how deeply. See Method and registers. |
| Residual risk | The risk that remains after the measures. |
| Retired | A risk that no longer applies. It is kept, but no longer counts. |
| Risk appetite | Which risk score belongs to which level. A decision by senior management, which is why it is locked. |
| Risk level | Low, Medium, High or Critical, derived from the risk score through the risk appetite. |
| Risk owner | The person responsible for a risk. |
| Risk score | Impact times likelihood, from 0 to 25. |
| Statement of applicability | For each control, whether it applies to your organisation, and why. In Dutch: Verklaring van toepasselijkheid. |
| Threat actor | Who or what can cause a risk, such as a criminal, a supplier or a storm. |
| Treatment deadline | Within how many days after approval the measures must be finished, per risk level. |
| Treatment plan | How you deal with a risk: the existing controls and the measures that will be added. |