Glossary

All compliance terms,
made simple.

ISMS, SoA, CAPA, DPIA, Stage 2… every acronym in our line of work defined straightforwardly, with references to the relevant standard and related terms.

Discover all the terms.

ISMS

Information Security Management System

The information security management system

A structured set of policies, procedures, roles and controls for managing information security. Being certified means having a working ISMS, not just documents.

SoA

Statement of Applicability

Document declaring which ISO 27001 controls apply

The central ISMS document listing all 93 Annex A 2022 controls, justifying the inclusion or exclusion of each. The first document requested at Stage 1.

CAPA

Corrective and Preventive Action

Corrective and preventive actions for handling nonconformities

A process required by practically every ISO standard. It analyses the root cause and prevents the problem recurring.

DVR

Italian Risk Assessment Document

Mandatory Italian document for occupational health and safety

An Italian legal obligation, separate from ISO 45001 but able to be integrated with it. It remains mandatory even with 45001 certification.

RoPA

Record of Processing Activities

Register of personal data processing required by the GDPR

Article 30 of the GDPR requires almost every organisation to keep a register of all processing activities, with purposes, legal bases, recipients and retention periods.

Stage 1

The first audit visit: documentation and readiness review

The certification body checks that documentation exists, that the system is running and that there is enough evidence to schedule Stage 2. It usually lasts half a day or a day.

Stage 2

The certification audit proper

The auditor verifies on site how the system works through interviews, operational evidence and inspections. It ends with a report and any nonconformities to close before the certificate is issued.

Surveillance audit

Annual audits between certification and the three-year renewal

After initial certification the body returns each year to verify the system is maintained. Every three years there is a full renewal audit. These are critical moments if the system has not been kept up.

Nonconformity

NC

A gap between what the standard requires and what is actually done

Nonconformities can be minor (resolved with one action) or major (blocking the certificate). The aim is to handle them in a structured way.

Annex A

The list of 93 ISO 27001:2022 security controls

It lists 93 controls (down from 114 in the 2013 version) across four themes: organisational, people, physical and technological. The SoA maps them one by one.

Risk Assessment

The process of identifying, analysing and evaluating risk

Required by almost every ISO standard (27001, 9001, 14001, 45001). It identifies what can go wrong, how likely it is and how serious. It is the basis for deciding which controls to implement.

Root Cause

The root cause of a nonconformity or an incident

Root cause analysis (for example 5 Whys or Ishikawa) exists so you do not stop at the symptom. It is explicitly required in the corrective actions of ISO 9001, 27001 and 13485.

DPO

Data Protection Officer

The person responsible for personal data protection

A mandatory role for certain categories of controller (public bodies, systematic monitoring, sensitive data). Independent, reporting to leadership and protected from sanctions for their assessments.

DPIA

Data Protection Impact Assessment

Data protection impact assessment

Mandatory when processing presents a high risk to rights (new technologies, profiling, sensitive data). The output is a document justifying the choices made.

HLS

High Level Structure

The framework shared by all ISO management system standards

All ISO management system standards (9001, 14001, 27001, 45001) share ten clauses. This makes integration between systems both possible and worthwhile.

Integrated system

Several ISO standards run with a single documentation structure

Typically 9001+14001+45001 or 9001+27001. It uses the High Level Structure to avoid duplicated policies and meetings, cutting overhead by 40-60%.

NIS2

The European cybersecurity directive, implemented in Italy by Legislative Decree 138/2024

It requires around 50,000 Italian organisations (medium and large companies in critical sectors) to implement security measures, register on the national cybersecurity portal and report incidents.

ACN

Italian National Cybersecurity Agency

The Italian authority responsible for cybersecurity

It receives NIS2 incident notifications, runs the register of in-scope entities, and can inspect and impose penalties. The first step is registering on its portal within the deadlines.

Management review

The annual meeting where top management assesses the system

Required by every ISO management system standard. It reviews audit results, nonconformities, objectives, resources and improvement opportunities. It is the moment leadership signs off on the system’s effectiveness.

Internal audit

A review of the system carried out by the organisation’s own people

Required at least annually by every ISO standard. Carried out by trained staff independent of the area being audited. Often supported by qualified external consultants.

FOR GROWING COMPANIES

A glossary isn't enough
to understand if you need
a certification.

If NIS2, ISO 27001, GDPR, and other regulations seem like a maze to you, book a free call. In 30 minutes, we’ll let you know if they apply to you and what steps to take.

FOR GROWING COMPANIES

A glossary isn't enough
to understand if you need
a certification.

If NIS2, ISO 27001, GDPR, and other regulations seem like a maze to you, book a free call. In 30 minutes, we’ll let you know if they apply to you and what steps to take.

FOR GROWING COMPANIES

A glossary isn't enough
to understand if you need
a certification.

If NIS2, ISO 27001, GDPR, and other regulations seem like a maze to you, book a free call. In 30 minutes, we’ll let you know if they apply to you and what steps to take.

REQUEST INFORMATION

We help you get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano
PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509

REQUEST INFORMATION

We help you get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509

REQUEST INFORMATION

We help you
get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509