Glosario

Todos los términos de la

SGSI, DdA, CAPA, EIPD, Fase 2… cada acrónimo de nuestro trabajo definido sin rodeos, con referencia directa a la norma y a sus términos vinculados.

Descubre todos los términos ahora mismo.

SGSI (Sistema de Gestión de la Seguridad de la Información)

Sistema de Gestión de Seguridad de la Información

The information security management system

A structured set of policies, procedures, roles and controls for managing information security. Being certified means having a working ISMS, not just documents.

Estado de Cuentas

Declaración de Aplicabilidad

Document declaring which ISO 27001 controls apply

The central ISMS document listing all 93 Annex A 2022 controls, justifying the inclusion or exclusion of each. The first document requested at Stage 1.

CAPA

Acción Correctiva y Preventiva

Corrective and preventive actions for handling nonconformities

A process required by practically every ISO standard. It analyses the root cause and prevents the problem recurring.

Grabador de Video Digital (DVR)

Italian Risk Assessment Document

Mandatory Italian document for occupational health and safety

An Italian legal obligation, separate from ISO 45001 but able to be integrated with it. It remains mandatory even with 45001 certification.

Registro de Actividades de Tratamiento (RAT)

Registro de Actividades de Tratamiento

Register of personal data processing required by the GDPR

Article 30 of the GDPR requires almost every organisation to keep a register of all processing activities, with purposes, legal bases, recipients and retention periods.

Fase 1

The first audit visit: documentation and readiness review

The certification body checks that documentation exists, that the system is running and that there is enough evidence to schedule Stage 2. It usually lasts half a day or a day.

Etapa 2

The certification audit proper

The auditor verifies on site how the system works through interviews, operational evidence and inspections. It ends with a report and any nonconformities to close before the certificate is issued.

Surveillance audit

Annual audits between certification and the three-year renewal

After initial certification the body returns each year to verify the system is maintained. Every three years there is a full renewal audit. These are critical moments if the system has not been kept up.

Nonconformity

Carolina del Norte

A gap between what the standard requires and what is actually done

Nonconformities can be minor (resolved with one action) or major (blocking the certificate). The aim is to handle them in a structured way.

Anexo A

The list of 93 ISO 27001:2022 security controls

It lists 93 controls (down from 114 in the 2013 version) across four themes: organisational, people, physical and technological. The SoA maps them one by one.

Evaluación de Riesgos

The process of identifying, analysing and evaluating risk

Required by almost every ISO standard (27001, 9001, 14001, 45001). It identifies what can go wrong, how likely it is and how serious. It is the basis for deciding which controls to implement.

Causa primordial

The root cause of a nonconformity or an incident

Root cause analysis (for example 5 Whys or Ishikawa) exists so you do not stop at the symptom. It is explicitly required in the corrective actions of ISO 9001, 27001 and 13485.

Delegado de Protección de Datos (DPO)

Delegado de Protección de Datos

The person responsible for personal data protection

A mandatory role for certain categories of controller (public bodies, systematic monitoring, sensitive data). Independent, reporting to leadership and protected from sanctions for their assessments.

EIPD

Evaluación de Impacto de Protección de Datos

Data protection impact assessment

Mandatory when processing presents a high risk to rights (new technologies, profiling, sensitive data). The output is a document justifying the choices made.

HLS

Estructura de Alto Nivel

The framework shared by all ISO management system standards

All ISO management system standards (9001, 14001, 27001, 45001) share ten clauses. This makes integration between systems both possible and worthwhile.

Integrated system

Several ISO standards run with a single documentation structure

Typically 9001+14001+45001 or 9001+27001. It uses the High Level Structure to avoid duplicated policies and meetings, cutting overhead by 40-60%.

NIS2

The European cybersecurity directive, implemented in Italy by Legislative Decree 138/2024

It requires around 50,000 Italian organisations (medium and large companies in critical sectors) to implement security measures, register on the national cybersecurity portal and report incidents.

ACN

Italian National Cybersecurity Agency

The Italian authority responsible for cybersecurity

It receives NIS2 incident notifications, runs the register of in-scope entities, and can inspect and impose penalties. The first step is registering on its portal within the deadlines.

Management review

The annual meeting where top management assesses the system

Required by every ISO management system standard. It reviews audit results, nonconformities, objectives, resources and improvement opportunities. It is the moment leadership signs off on the system’s effectiveness.

Internal audit

A review of the system carried out by the organisation’s own people

Required at least annually by every ISO standard. Carried out by trained staff independent of the area being audited. Often supported by qualified external consultants.

PARA LAS EMPRESAS EN CRECIMIENTO

Un glosario no es suficiente
para entender si realmente necesitas
una certificación.

Complaion está diseñada para empresas de hasta 250 empleados que no cuentan con un departamento de compliance interno. Es para quienes entienden que la certificación ISO abre puertas, pero no tienen el tiempo ni los recursos para afrontarla por su cuenta.

PARA LAS EMPRESAS EN CRECIMIENTO

Un glosario no es suficiente
para entender si realmente necesitas
una certificación.

Complaion está diseñada para empresas de hasta 250 empleados que no cuentan con un departamento de compliance interno. Es para quienes entienden que la certificación ISO abre puertas, pero no tienen el tiempo ni los recursos para afrontarla por su cuenta.

PARA LAS EMPRESAS EN CRECIMIENTO

Un glosario no es suficiente
para entender si realmente necesitas
una certificación.

Complaion está diseñada para empresas de hasta 250 empleados que no cuentan con un departamento de compliance interno. Es para quienes entienden que la certificación ISO abre puertas, pero no tienen el tiempo ni los recursos para afrontarla por su cuenta.

Solicita información

Te ayudamos a certificarte rápidamente.

©2026 Complaion. Todos los derechos reservados / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milán
PEC: part@pec.it, Capital Social: €17.017,18, REA MI-2690509

Solicita información

Te ayudamos a certificarte rápidamente.

©2026 Complaion. Todos los derechos reservados / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capital Social: 17.017,18 €, REA MI-2690509

Solicita información

Te ayudamos a certificarte rápidamente.

©2026 Complaion. Todos los derechos reservados / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capital Social: 17.017,18 €, REA MI-2690509