Glossary

The words the platform uses, and what each one means here. Where a word has a looser everyday meaning, the entry says what it does not mean.

Measuring

Framework — a standard or regulation an assessment is run against: NIS2, ISO 27001, CIS, and others. The picker in the platform shows which are available to you; the list grows.

Question library — the set of questions behind a framework. Libraries can ship with the platform or be brought by a partner. Which library you are answering decides how many questions there are, how the levels are worded, and whether each control is asked once or twice.

Maturity assessment — one run through a library, producing scores, a report and material for your action plan. An organisation can run several, against different frameworks or at different times.

Category — a section of the assessment, such as Organisation, Risk Management or Continuity. Categories are what the report scores and what the sidebar tracks while you answer.

Control — a single requirement, answered by one question. Also the unit of work in your action plan, which is where the word does double duty: a control is both something measured and something done.

Task — a step inside a control. Completing a control means completing its tasks. (The word “subtask” appears in exported data and in the content pipeline; in the product a task is a task.)

Policy — what your organisation has formally decided and written down.

Practice — what actually happens day to day.

Level — where an answer sits on the five-step maturity scale. See The maturity scale.

Not applicable — a control that does not apply to your organisation, removed from the score rather than scored zero.

Evidence — documents attached to an answer or a task, supporting the level claimed.

Reporting

Report — what an assessment produced, as at the moment it was generated. It does not move as you work.

Executive Summary — the report’s short version, for people who decide.

Detailed Results — the report’s long version, for people who act.

Observation — something the assessment found in a category.

Recommendation — what the report proposes doing about a finding. A proposal, not committed work.

Acceptable — the fixed floor at level 3. Below it, a category needs action.

Target — the level a category is expected to reach, set by the question library. May be higher than the floor, and may not exist at all.

Coverage — what an assessment did and did not reach. The report names the objectives no question touched, so its silence is not mistaken for a clean bill.

Stale — a report whose assessment has changed since it was generated. Regenerate it to bring the two back together.

Acting

Action Plan — where recommendations become work with owners, dates and progress. One plan per organisation, drawing on every completed assessment.

Objective — a group of controls that belong together, and the unit you decide about: you take an objective’s controls into your plan, not individual recommendations one at a time.

In Plan — work you have committed to. Track what is moving.

Not Planned — identified work you have not committed to. Decide what to take on. It does not mean rejected, and it does not mean forgotten.

Owner — the person accountable for a control. One name, not a team.

Declared — a task marked done with no evidence attached. It says a person asserted this; it is not a synonym for done. Note that this is a task status — it has nothing to do with who performed the assessment.

Risk scenario — a described exposure, with likelihood, consequence and a treatment decision. Lives in the risk register, not the action plan. An action is something you do; a risk scenario is something that could happen to you.

Who is working

Self-assessment — your own people answer the questions.

External review — a partner consultant answers them on your behalf, having examined the evidence. You can follow the work as it happens; the consultant’s internal notes stay with the consultant.

The Swedish terms

Three words carry the structure, and they sit inside one another:

EnglishSwedish
Taskuppgifta step inside a control
Controlåtgärda requirement you work on, made of tasks
Action Planhandlingsplanwhere the controls you have committed to live

So you work on an åtgärd, made of uppgifter, inside a handlingsplan.

Åtgärdsplan is not used. It reads as “the plan of åtgärder” and so collapses the outer level into the middle one — the distinction the three words exist to keep. In conversation the two are often swapped; in the product and in this documentation the plan is a handlingsplan.