VAHTI glossary on risk management in the digital operating environment
Filter list
Terminology concepts
preliminary assessmentNo contributors
Concept Valid
an assessment made at the beginning of the assessment process to get a rough overview
digital operating environmentNo contributors
Concept Valid
an operating environment consisting of one or more digital information systems
digital securityNo contributors
Concept Valid
a target state where a digital operating environment can be trusted and operations both there and related to it are secure and managed, even in the event of disruptions
digital activity/operation riskNo contributors
Concept Valid
a risk active in the digital operating environment, applicable to or resulting from the digital operating environment
foresightNo contributors
Concept Valid
assessment of the direction of changes in an organisation’s operation and operating environment, and determining the prerequisites for potential developments
uncertaintyNo contributors
Concept Valid
lack of information about the nature or timing of a future event
vulnerabilityNo contributors
Concept Valid
a shortcoming, defect or way of operation that exposes one to security threats
weaknessNo contributors
Concept Valid
from the perspective of an organisation’s objectives, an undesired or harmful feature within the organisation’s operations or assets
attackNo contributors
Concept Valid
an act or action aimed at damaging or unauthorised use of the target or preventing the target’s objective from being realised
disruptionNo contributors
Concept Valid
an unexpected or undesired event that disrupts the operation of a system, a user of a system or parties dependent on them
continuity managementNo contributors
Concept Valid
the process of an organisation for identifying the risks that are key to operations, assessing their effects within the organisation and its network of actors, and creating an operating method for the management of disruptive events and the continuity of operations in all conditions
concatenated riskNo contributors
Concept Valid
a consequential risk, which may have been transferred from another target
coordination levelNo contributors
Concept Valid
a decision-making level within an organisation at which decisions are made regarding the organisation of the operations of individual operational areas and units, taking strategic-level decisions into account
criticalityNo contributors
Concept Valid
the necessity to achieve objectives or to avoid particularly harmful consequences
cumulative riskNo contributors
Concept Valid
a risk whose magnitude is formed by the combined effects of several risk factors
cybersecurityNo contributors
Concept Valid
a target state in which threats and risks arising from the cyber operating environment to society’s vital functions or other functions dependent on the cyber operating environment are under control, even in the event of disruptions
transparency in risk managementNo contributors
Concept Valid
enabling the assessment of risk management for stakeholders and internal actors in such a way that related information is passed on to the extent that this does not in itself produce significant risks
opportunityNo contributors
Concept Valid
an event or course of development that may be caused by the effects of a risk, which can be used to promote objectives
organisational contextNo contributors
Concept Valid
an organisation or part of it from whose point of view an inspection is carried out
inclusivity in risk managementNo contributors
Concept Valid
enabling and encouraging stakeholders to participate in an organisation’s risk management
deviationNo contributors
Concept Valid
the difference between the item examined and the desired or usual one
risk-related communications and information exchangesNo contributors
Concept Valid
continuous and recurring processes by which an organisation provides, shares or acquires information and engages in dialogue within the organisation and with its stakeholders about risk management and risks
risk analysis [activity]No contributors
Concept Valid
finding out the information needed for risk assessment or processing about the nature of risks
risk assessment [activity]No contributors
Concept Valid
determining the probability of risks becoming realised and their possible effects
risk assessment processNo contributors
Concept Valid
a process that covers risk identification, risk analysis and risk assessment
risk assessment process toolNo contributors
Concept Valid
a risk management tool that guides one to implement parts of the risk assessment process in a consistent manner, following certain models or methods
risk classificationNo contributors
Concept Valid
groupings done for the efficient assessment and handling of risks, owing to which similar risks or risks belonging to a single area of responsibility, or parts of these risks, can be viewed as a single entity
risk monitoringNo contributors
Concept Valid
determining the state of risks and their directions of change
risk situation pictureNo contributors
Concept Valid
a compiled description of the results of risk monitoring
risk management frameworkNo contributors
Concept Valid
organisation of risk management, division of responsibilities and a detailed operating model, which as part of the management system enable the implementation of risk management principles in an organisation’s processes
risk management monitoringNo contributors
Concept Valid
observing the state of the risk management process and the related activities
risk management situation pictureNo contributors
Concept Valid
a compiled description of the results of risk management monitoring
risk management systemNo contributors
Concept Valid
a management system that covers risk management policies and objectives as well as the processes and possible risk management tools with which these objectives are reached
risk management system monitoringNo contributors
Concept Valid
observation of the methods and scope of application of a risk management system and its change history
risk management system situation pictureNo contributors
Concept Valid
a compiled description of the results of the monitoring of the risk management system
risk management principlesNo contributors
Concept Valid
risk management objectives and a general operating model, which as part of a management system support the creation and preservation of an organisation’s value
risk management policyNo contributors
Concept Valid
an organisation-specific description of risk management principles and risk management frameworks considered key
risk management toolNo contributors
Concept Valid
software, form or other aid that guides one to implement some part of risk management consistently, following certain models or methods
risk criteriaNo contributors
Concept Valid
the grounds for assessing the significance of risks in a uniform manner
risk conceptionNo contributors
Concept Valid
a person’s or an organisation’s perception of what a particular risk is like
risk life cycleNo contributors
Concept Valid
the stages of the existence of a risk, from the formation of the threat to the identification of the risk and further until the potential removal of the risk
threat that evades the limit value of a riskNo contributors
Concept Valid
an attack or other threat that seeks to avoid countermeasures by remaining below the threshold values used in risk assessment