What does that ISO term actually mean?
Plain-language definitions for the terms you keep hearing in audits, tenders, and training — no dictionary jargon.
A
Access Control
The set of controls that determine who can access what information or system, and under what conditions — logins, permissions, physical access, and the process for granting and revoking them. Access rights that were not promptly revoked when someone left or changed roles are one of the most common ISO 27001 audit findings.
Accreditation Body
The national or international authority that authorizes certification bodies to issue valid ISO certificates in the first place. When checking whether a certificate is credible, the real question is not just "is this certification body real" but "is it accredited by a recognized accreditation body for this specific standard."
Annex A
ISO 27001's reference list of security controls, grouped by theme — organizational, people, physical, and technological. You are not required to implement every control; you are required to assess each one for relevance and document your decision in the Statement of Applicability.
Annex SL / Harmonized Structure
The common high-level structure every modern ISO management-system standard is built on — the same ten clauses covering context, leadership, planning, support, operation, evaluation, and improvement. It exists so organizations can run one integrated management system across quality, environment, safety, and other disciplines instead of several unrelated ones.
B
BCMS (Business Continuity Management System)
The complete management system ISO 22301 certifies — the structured process of identifying what would disrupt critical operations, understanding the impact, and building and testing plans to keep functioning, or recover quickly, when something goes wrong.
Business Continuity Plan (BCP)
The documented plan for keeping the organization functioning — or recovering quickly — when a disruption occurs, covering people, facilities, suppliers, and communication, not just IT recovery. A disaster recovery plan for your servers is one input into a BCP; on its own, it answers a much narrower question than the BCP is meant to.
Business Impact Analysis (BIA)
The foundation ISO 22301 business continuity planning is built on — identifying which processes are genuinely time-critical, and quantifying what disruption actually costs in terms the business cares about: revenue, contractual penalties, regulatory exposure, reputation. A BIA built by IT alone, without the business units that depend on those systems, consistently gets the priorities wrong.
C
Certification Body
The independent organization that audits your management system and, if it conforms, issues your certificate. Certification bodies are themselves assessed and authorized by an accreditation body — which is what makes a certificate meaningful to a client checking your credentials.
Change Management
The controlled process for assessing, approving, and rolling out changes to IT systems or services — so a well-intentioned update does not become an unplanned outage. Both ISO 20000-1 and ISO 27001 require it, because uncontrolled change is one of the most common causes of both service disruption and security incidents.
Configuration Management
Keeping an accurate, up-to-date record of your IT assets and how they relate to each other — servers, software, dependencies — usually held in a configuration management database (CMDB). Without it, incident and change management are working blind: you cannot assess the impact of a change you cannot map.
Context of the Organization
Clause 4 in every Annex SL standard — the internal and external factors that affect what your management system needs to address: your market, regulatory environment, culture, capabilities, and the needs of interested parties. It is the foundation the rest of the system's scope and risk assessment is built on.
Continual Improvement
The expectation, built into every ISO management-system standard, that the system keeps getting better over time rather than simply maintaining the status quo. In practice it means audit findings, incidents, and management-review decisions actually feed back into how the organization operates.
Corrective Action (CAR)
The action taken to eliminate the root cause of a nonconformity so it does not happen again — distinct from simply fixing the immediate problem. A corrective action request (CAR) is the documented record that tracks this from root-cause analysis through to a verified, closed fix.
D
Documented Information
The current term for what used to be split into "documents" and "records" — any information your system requires you to control and maintain, whether that is a policy, a procedure, or evidence that something happened. Modern ISO standards deliberately require less of it than older versions did; lean, usable documentation beats an exhaustive manual nobody reads.
E
EMS (Environmental Management System)
The complete management system ISO 14001 certifies — how an organization identifies and controls its environmental impacts (waste, emissions, resource use) and works to reduce them over time. It shares Annex SL's structure with quality and safety systems, which is why the three are often trained and audited together.
F
Food Defense
Protecting food from deliberate, malicious contamination or tampering — as opposed to food safety, which deals with accidental hazards. FSSC 22000 requires a documented vulnerability assessment covering physical and procedural weak points, which is often new territory for a team used to thinking only about accidental risk.
Food Fraud
Economically motivated deception involving food — substituting a cheaper ingredient without disclosure, mislabeling origin, or diluting a product, for financial gain rather than by accident. FSSC 22000 requires a food-fraud vulnerability assessment specific to your supply chain, distinct from the food-defense assessment.
FSMS (Food Safety Management System)
The complete management system ISO 22000 (and, with additional prerequisite programs, FSSC 22000) certifies — built around HACCP principles, interactive communication along the supply chain, and the standard Annex SL management structure.
H
HACCP
Hazard Analysis and Critical Control Points — a systematic method for identifying where food safety hazards could enter a process and putting controls at those specific points. It is not a separate certification; it is the core methodology embedded inside both ISO 22000 and FSSC 22000.
HARPC
Hazard Analysis and Risk-Based Preventive Controls — a food-safety framework used primarily by facilities regulated under US FDA rules (FSMA), rather than an ISO standard. It shares HACCP's hazard-analysis logic but adds a broader set of preventive-control categories; GCC exporters selling into the US sometimes need to understand both frameworks side by side.
I
Incident Management
The process for detecting, responding to, and restoring normal operation after an unplanned service disruption or security event, as quickly as possible. It is deliberately distinct from problem management, which digs into the underlying root cause after the immediate fire is out.
Information Asset
Anything that holds or represents information and has value to your organization — a database, a contract archive, a laptop, even institutional knowledge held by a specific person. ISO 27001 requires you to identify and inventory these before you can meaningfully assess the risks to them.
Interested Parties
Everyone with a stake in your management system's performance — customers, employees, regulators, suppliers, owners, even neighbors for an environmental system. Annex SL requires you to identify these parties and their relevant requirements explicitly, as one of the first steps in defining your system's scope.
Internal Audit
A structured, first-party review your own organization runs against its management system and the relevant standard, on a regular schedule, using auditors independent from the area being audited. It is how a certified system checks itself between external certification visits — the requirement every certified standard shares.
ISMS (Information Security Management System)
The complete management system ISO 27001 certifies — the policies, risk assessments, controls, and processes an organization uses to protect the confidentiality, integrity, and availability of its information. "Implementing ISO 27001" and "building an ISMS" describe the same project.
ISO/IEC vs ISO
Standards published as "ISO/IEC" — like ISO/IEC 27001 or ISO/IEC 20000-1 — were developed jointly by the International Organization for Standardization and the International Electrotechnical Commission, reflecting their technology and electrotechnical subject matter. It is the same kind of internationally recognized standard either way; the prefix just tells you who co-authored it.
ITSMS (IT Service Management System)
The complete management system ISO 20000-1 certifies — how an IT function plans, delivers, and improves its services against agreed service levels, covering change, configuration, incident, and problem management as one coherent system rather than separate ad-hoc processes.
M
Management Review
A formal, periodic meeting where top leadership actually looks at how the management system is performing — audit results, nonconformities, customer feedback, objectives — and decides what needs to change. Auditors treat this as a key signal of whether leadership genuinely owns the system or has delegated it entirely.
N
Nonconformity (NC)
Any point where your management system does not meet a requirement — whether that requirement comes from the standard itself, your own documented procedure, or a legal obligation. Finding one is not a failure; not finding and correcting them is.
Nonconformity: Major vs Minor
A minor nonconformity is an isolated lapse that does not undermine the whole management system — a single missed record, for instance. A major nonconformity signals a systemic failure — a whole clause not implemented, or several related minor findings that add up to a pattern — and, unresolved, it can stop a certificate from being issued or renewed.
O
Objective Evidence
Data that confirms something exists or happened — as opposed to someone simply asserting it did. "We review access rights quarterly" is an assertion; a dated access-review log with a named owner and follow-up actions is objective evidence, and it is what auditors are trained to look for.
OHSMS (Occupational Health & Safety Management System)
The complete management system ISO 45001 certifies — how an organization proactively identifies hazards, controls risk, and involves workers in decisions that affect their safety. It sits alongside, not instead of, local occupational health and safety regulation.
Operational PRPs (OPRPs)
Controls that sit between general prerequisite programs and full HACCP critical control points — measures essential to controlling a specific hazard, but that do not meet the strict criteria for a critical control point. Getting this classification right matters, because OPRPs and CCPs are monitored and verified differently.
P
PDCA Cycle
Plan-Do-Check-Act — the continuous improvement loop underneath every ISO management-system standard: plan what you are going to do, do it, check whether it worked, then act on what you learned. Annex SL's clause structure is essentially PDCA formalized into ten sections.
Prerequisite Programs (PRPs)
The basic hygiene and environmental conditions a food operation needs before HACCP controls can even be meaningful — pest control, facility hygiene design, water quality, staff hygiene practices, and similar foundations. FSSC 22000 requires detailed, sector-specific PRPs on top of what ISO 22000 asks for generally.
Preventive Action
Action taken to eliminate the cause of a potential nonconformity — one that has not happened yet. Modern ISO standards fold this into risk-based thinking rather than treating it as a separate formal process, but the underlying idea — acting before something goes wrong, not just after — is still central to how a mature management system operates.
Q
QMS (Quality Management System)
The complete management system ISO 9001 certifies — how an organization plans, controls, and improves the way it consistently meets customer requirements. It covers everything from understanding what customers need through to catching and correcting problems.
R
Recertification Audit
The full audit conducted at the end of each three-year certification cycle to renew your certificate — more thorough than a surveillance audit, closer in depth to the original certification audit. It confirms the system has kept working over the full cycle, not just at the surveillance snapshots.
Recovery Point Objective (RPO)
The maximum amount of data loss, measured in time, that is acceptable after a disruption — essentially, how far back your last usable backup needs to be. An RPO of one hour means you can tolerate losing at most an hour's worth of data; achieving it dictates how often you actually need to back up.
Recovery Time Objective (RTO)
The maximum acceptable time a process or system can be down before the disruption becomes unacceptable to the business — set by the business impact analysis, not by what IT can technically achieve. A shorter RTO usually means a more expensive recovery solution, which is exactly why the BIA has to justify it with real impact data.
Risk
The effect of uncertainty on your objectives — in plain terms, what could happen that would knock you off course, and how likely and how severe that would be. Every current ISO management-system standard requires you to identify, evaluate, and treat risk as a core, ongoing activity rather than a one-time exercise.
Risk-based Thinking
The principle that planning and decisions should be shaped by what could realistically go wrong (and what opportunities could be seized), rather than by rigid procedure alone. It replaced the old stand-alone "preventive action" clause in most current ISO standards, embedding risk consideration into every part of the system instead of one section.
Root Cause Analysis (RCA)
The structured process of digging past the obvious, immediate cause of a problem to find what actually made it possible in the first place. A machine failed because a part wore out is a symptom; nobody scheduled preventive maintenance is often the root cause — and only fixing the second one stops it from happening again elsewhere.
S
Scope
The formal boundary of what your management system actually covers — which sites, which processes, which products or services. Auditors certify only what is inside a clearly defined scope, which is why an overly broad or vague scope statement is one of the most common early-stage stumbling blocks.
Service Level Agreement (SLA)
A documented agreement setting out what level of service a provider commits to — response times, uptime, resolution targets — and what happens if those targets are missed. ISO 20000-1 requires SLAs to be defined, monitored, and actually reviewed against real performance, not just signed and filed away.
Stage 1 / Stage 2 Audit
The two-part structure of an initial certification audit. Stage 1 is a documentation and readiness review — checking your scope, policies, and risk assessment exist and are coherent, and flagging anything that would cause a full audit to fail outright. Stage 2 is the substantive audit: interviews, evidence sampling, and testing whether controls actually operate as documented.
Statement of Applicability (SoA)
A required ISO 27001 document listing every Annex A control, whether your organization applies it, and why. It is the document auditors return to most often, because a generic, copy-pasted SoA — with everything marked "applicable" regardless of relevance — is an immediate credibility problem.
Surveillance Audit
A shorter audit your certification body conducts roughly once a year between the initial certification and the three-year recertification, checking that your system is still genuinely operating, not just that the certificate is still on the wall. Treating the initial certification audit as the finish line is why surveillance audits sometimes catch organizations off guard.
T
Threat
Anything with the potential to cause harm to an information asset — a hacker, a fire, a disgruntled employee, a power outage. A threat only becomes a meaningful risk when it meets a vulnerability that lets it actually cause damage.
Traceability
The ability to trace a product, batch, or material forward through your process to where it went, and backward to where it came from. In food safety it is what makes a targeted recall possible instead of pulling everything off the shelf; in quality management it is what lets you isolate exactly which units a defect affects.
V
Vulnerability
A weakness that a threat can exploit — an unpatched system, an untrained employee who clicks a phishing link, a door without a lock. Risk assessment is fundamentally about finding the combinations of threat and vulnerability that matter, and deciding what to do about each one.
Ready to train your team?
Tell us your context and we'll tailor a program — onsite or online, across the GCC.