Skip to content

Glossary

The vocabulary below is the one used throughout CyberGuard and the rest of this manual. Where a screen label differs from the concept’s older or internal name, both are given.

Actor — Anyone who can own or be assigned work: a user, a team or an external entity. Actors are created automatically alongside the object they wrap.

Applied control — The main building block of the action plan: a concrete measure your team runs or plans to run — technical, organisational, a process, a policy. One control can satisfy requirements across several frameworks.

Asset — Anything of value worth protecting. Primary assets contribute directly to the organisation’s objectives; supporting assets are the systems, services, locations and people that hold them up.

Assessment — Umbrella term for audits, risk assessments, business impact analyses and entity assessments.

Audit — The evaluation of a perimeter against a framework, producing a per-requirement view of result, score and evidence. Also called a compliance assessment.

Business impact analysis (BIA) — A structured assessment of what disruption to an asset costs over time, feeding resilience and continuity planning.

Catalog object — A reusable building block: framework, threat, risk matrix, reference control, mapping, security advisory, CWE. Catalog objects are distributed inside libraries.

Current risk — The risk level given the controls already in place — the state of risk today. The middle tier of inherent, current and residual.

CWE — Common Weakness Enumeration: a catalogued category of software weakness, used to characterise vulnerabilities and advisories.

Domain — The top-level container: a business unit, subsidiary or any boundary used to organise work and isolate permissions. Domains nest. Internally a folder.

EBIOS RM — The French ANSSI risk-management method, supported as its own graph of studies, feared events, stakeholders and scenarios.

Entity — An external party, typically a supplier or vendor, in third-party risk management.

Entity assessment — The review of an entity, usually a questionnaire answered by that entity’s representative.

Evidence — An artifact attached to a control or a requirement to substantiate it. Replacing the file creates an evidence revision, with its own version number and integrity hash, rather than overwriting the previous one.

Feature flag — A switch that turns a whole module on or off across the instance, changing the navigation without touching stored data.

Filtering label — A free-form tag attachable to most objects for filtering and reporting.

Finding — A single issue to remediate: a non-conformity, an observation, a pentest result. Findings are collected in a findings binder, the record driving one review to closure.

Framework — A set of requirements representing a regulation, a certification or a baseline. Distributed as a library.

Implementation group — A named tier inside a multi-level framework. Selecting groups scopes an audit to the requirements of those tiers.

Incident — A security or operational event being tracked. Distinct from a risk (potential) and a vulnerability (weakness).

Inherent risk — The risk level with no controls applied at all — the top tier of the three.

Journey — A guided sequence of steps applied to a domain to bootstrap it, instantiated from a preset.

Library — A versioned package of catalog objects. Loading one makes its contents available; upgrading it pulls newer versions into what is already in use.

Mapping — A directed set of links between the requirements of two frameworks, used to carry work from one framework to another.

Perimeter — A scoped subset of a domain that an assessment applies to. Unlike a domain, it does not enforce access control. Previously called a project.

Personal access token (PAT) — A long-lived token issued from your profile to authenticate API calls.

Policy — A kind of applied control: a document stating what is expected of some part of your organisation, managed alongside the rest of your controls.

Reference control — A template for an applied control, supplied by a framework library or written locally. Optional, but it keeps controls consistent.

Representative — The person at an entity who answers its questionnaire.

Requirement — A single normative statement inside a framework. Its evaluation inside an audit is a requirement assessment.

Residual risk — The risk level expected once all planned controls are implemented — the target state, and the input to a risk-acceptance decision.

Respondent mode — The surface where a contributor answers only the requirements assigned to them, inside a shared audit.

Risk acceptance — A formal, approved record that the organisation tolerates a residual risk without further treatment.

Risk matrix — The lookup table deriving a risk level from probability and impact. Fixed per risk assessment once it is created.

Risk scenario — The building block of a risk assessment: threats, assets and existing controls combined into a story that can be evaluated.

Role — A bundle of permissions: domain manager sets up everything on a domain, analyst reads and writes data but not domain settings, reader is read-only, approver validates workflows such as risk acceptance. A role assignment attaches a user or user group to a role on a domain.

Security advisory — A catalogued warning published by a vendor or CERT, linked to vulnerabilities and affected assets.

Security exception — A documented, time-bound, approved deviation from a control or policy.

Severity — The shared ordinal scale for vulnerabilities, incidents and findings: undefined, info, low, medium, high, critical.

Solution — A product or service provided by an entity.

Task definition — A reusable specification of work — assignee, recurrence, expected evidence — generating task occurrences on a schedule, each with its own due date and status.

Team — A named group of users used for shared ownership and assignment. Distinct from a user group, which grants a role on a domain.

Terminology — Your organisation’s overrides to the platform’s default labels.

Threat — A catalogued source of harm, reusable across scenarios. Informative: assessments work without referencing threats.

Trust center — A public, read-only portal publishing certifications, documents and compliance snapshots to anyone holding the link.

URN — The unique identifier used to reference catalog objects across libraries.

User group — A pairing of a role and a domain onto which users are placed. Created automatically with each domain.

Validation flow — A configurable approval workflow routing an object through one or more approvers before it is considered signed off.

Vulnerability — A weakness that a threat could exploit, tracked with severity, status and linked controls.

Webhook endpoint — A registered URL CyberGuard posts to when subscribed events occur.

Workflow — An automation defined in the platform — a trigger, steps and connections — running with the permissions of whoever published it.

X-rays — The inconsistency checker that reports errors, warnings and information across your assessments.