Navigated to
Go directly to contents.

VAHTI glossary on risk management in the digital operating environment

Terminological vocabulary ·Valid

Go directly to search results.

Filter list

Terminology concepts

No filters

ConceptValid

an assessment made at the beginning of the assessment process to get a rough overview

ConceptValid

an operating environment consisting of one or more digital information systems

ConceptValid

a target state where a digital operating environment can be trusted and operations both there and related to it are secure and managed, even in the event of disruptions

ConceptValid

a risk active in the digital operating environment, applicable to or resulting from the digital operating environment

ConceptValid

assessment of the direction of changes in an organisation’s operation and operating environment, and determining the prerequisites for potential developments

ConceptValid

lack of information about the nature or timing of a future event

ConceptValid

a shortcoming, defect or way of operation that exposes one to security threats

ConceptValid

from the perspective of an organisation’s objectives, an undesired or harmful feature within the organisation’s operations or assets

ConceptValid

the target that the attack aims to influence

ConceptValid

an act or action aimed at damaging or unauthorised use of the target or preventing the target’s objective from being realised

ConceptValid

an unexpected or undesired event that disrupts the operation of a system, a user of a system or parties dependent on them

ConceptValid

the process of an organisation for identifying the risks that are key to operations, assessing their effects within the organisation and its network of actors, and creating an operating method for the management of disruptive events and the continuity of operations in all conditions

ConceptValid

the risk remaining after risk processing

ConceptValid

the level from which a risk is viewed

ConceptValid

a consequential risk, which may have been transferred from another target

ConceptValid

an action aimed at changing or maintaining a risk

ConceptValid

a decision-making level within an organisation at which decisions are made regarding the organisation of the operations of individual operational areas and units, taking strategic-level decisions into account

ConceptValid

the necessity to achieve objectives or to avoid particularly harmful consequences

ConceptValid

a risk whose magnitude is formed by the combined effects of several risk factors

ConceptValid

a target state in which threats and risks arising from the cyber operating environment to society’s vital functions or other functions dependent on the cyber operating environment are under control, even in the event of disruptions

ConceptValid

the level at which a risk is addressed

ConceptValid

enabling the assessment of risk management for stakeholders and internal actors in such a way that related information is passed on to the extent that this does not in itself produce significant risks

ConceptValid

an event or course of development that may be caused by the effects of a risk, which can be used to promote objectives

ConceptValid

an organisation or part of it from whose point of view an inspection is carried out

ConceptValid

enabling and encouraging stakeholders to participate in an organisation’s risk management

ConceptValid

the difference between the item examined and the desired or usual one

ConceptValid

continuous and recurring processes by which an organisation provides, shares or acquires information and engages in dialogue within the organisation and with its stakeholders about risk management and risks

ConceptValid

effect of uncertainty on objectives

ConceptValid

finding out the information needed for risk assessment or processing about the nature of risks

ConceptValid

determining the probability of risks becoming realised and their possible effects

ConceptValid

a process that covers risk identification, risk analysis and risk assessment

ConceptValid

a risk management tool that guides one to implement parts of the risk assessment process in a consistent manner, following certain models or methods

ConceptValid

groupings done for the efficient assessment and handling of risks, owing to which similar risks or risks belonging to a single area of ​​responsibility, or parts of these risks, can be viewed as a single entity

ConceptValid

determining the state of risks and their directions of change

ConceptValid

a compiled description of the results of risk monitoring

ConceptValid

organisation of risk management, division of responsibilities and a detailed operating model, which as part of the management system enable the implementation of risk management principles in an organisation’s processes

ConceptValid

observing the state of the risk management process and the related activities

ConceptValid

a compiled description of the results of risk management monitoring

ConceptValid

a management system that covers risk management policies and objectives as well as the processes and possible risk management tools with which these objectives are reached

ConceptValid

observation of the methods and scope of application of a risk management system and its change history

ConceptValid

risk management objectives and a general operating model, which as part of a management system support the creation and preservation of an organisation’s value

ConceptValid

an organisation-specific description of risk management principles and risk management frameworks considered key

ConceptValid

software, form or other aid that guides one to implement some part of risk management consistently, following certain models or methods

ConceptValid

the grounds for assessing the significance of risks in a uniform manner

ConceptValid

a person’s or an organisation’s perception of what a particular risk is like

ConceptValid

the stages of the existence of a risk, from the formation of the threat to the identification of the risk and further until the potential removal of the risk

ConceptValid

an attack or other threat that seeks to avoid countermeasures by remaining below the threshold values ​​used in risk assessment