Glossary
Statement of Applicability: What Auditors Check
The Statement of Applicability is the document listing every Annex A control, whether it applies to your organisation,…
Glossary
The Statement of Applicability is the document listing every Annex A control, whether it applies to your organisation,…
Glossary
An ISMS is the set of policies, processes and records an organisation uses to manage information security decisions,…
Glossary
An SBOM is a machine-readable list of every component inside a piece of software, so that when a…
Glossary
SCA identifies the open-source libraries your application depends on and checks each one against known vulnerabilities and licence…
Glossary
SAST analyses your source code without running it, looking for insecure patterns that could become vulnerabilities once the…
Glossary
CSPM continuously checks your cloud accounts against secure configuration baselines and flags the settings that would expose data…
Glossary
A SIEM collects security events from across your systems, correlates them, and raises an alert when the combination…
Glossary
API security is the practice of protecting the endpoints your applications expose, where the main risk is not…
Glossary
ISO 27001 is the international standard for information security management. It sets out how a company should identify…