Glossary
The words the platform uses, and what each one means here. Where a word has a looser everyday meaning, the entry says what it does not mean.
Measuring
Framework — a standard or regulation an assessment is run against: NIS2, ISO 27001, CIS, and others. The picker in the platform shows which are available to you; the list grows.
Question library — the set of questions behind a framework. Libraries can ship with the platform or be brought by a partner. Which library you are answering decides how many questions there are, how the levels are worded, and whether each control is asked once or twice.
Maturity assessment — one run through a library, producing scores, a report and material for your action plan. An organisation can run several, against different frameworks or at different times.
Category — a section of the assessment, such as Organisation, Risk Management or Continuity. Categories are what the report scores and what the sidebar tracks while you answer.
Control — a single requirement, answered by one question. Also the unit of work in your action plan, which is where the word does double duty: a control is both something measured and something done.
Task — a step inside a control. Completing a control means completing its tasks. (The word “subtask” appears in exported data and in the content pipeline; in the product a task is a task.)
Policy — what your organisation has formally decided and written down.
Practice — what actually happens day to day.
Level — where an answer sits on the five-step maturity scale. See The maturity scale.
Not applicable — a control that does not apply to your organisation, removed from the score rather than scored zero.
Evidence — documents attached to an answer or a task, supporting the level claimed.
Reporting
Report — what an assessment produced, as at the moment it was generated. It does not move as you work.
Executive Summary — the report’s short version, for people who decide.
Detailed Results — the report’s long version, for people who act.
Observation — something the assessment found in a category.
Recommendation — what the report proposes doing about a finding. A proposal, not committed work.
Acceptable — the fixed floor at level 3. Below it, a category needs action.
Target — the level a category is expected to reach, set by the question library. May be higher than the floor, and may not exist at all.
Coverage — what an assessment did and did not reach. The report names the objectives no question touched, so its silence is not mistaken for a clean bill.
Stale — a report whose assessment has changed since it was generated. Regenerate it to bring the two back together.
Acting
Action Plan — where recommendations become work with owners, dates and progress. One plan per organisation, drawing on every completed assessment.
Objective — a group of controls that belong together, and the unit you decide about: you take an objective’s controls into your plan, not individual recommendations one at a time.
In Plan — work you have committed to. Track what is moving.
Not Planned — identified work you have not committed to. Decide what to take on. It does not mean rejected, and it does not mean forgotten.
Owner — the person accountable for a control. One name, not a team.
Declared — a task marked done with no evidence attached. It says a person asserted this; it is not a synonym for done. Note that this is a task status — it has nothing to do with who performed the assessment.
Risk scenario — a described exposure, with likelihood, consequence and a treatment decision. Lives in the risk register, not the action plan. An action is something you do; a risk scenario is something that could happen to you.
Who is working
Self-assessment — your own people answer the questions.
External review — a partner consultant answers them on your behalf, having examined the evidence. You can follow the work as it happens; the consultant’s internal notes stay with the consultant.
The Swedish terms
Three words carry the structure, and they sit inside one another:
| English | Swedish | |
|---|---|---|
| Task | uppgift | a step inside a control |
| Control | åtgärd | a requirement you work on, made of tasks |
| Action Plan | handlingsplan | where the controls you have committed to live |
So you work on an åtgärd, made of uppgifter, inside a handlingsplan.
Åtgärdsplan is not used. It reads as “the plan of åtgärder” and so collapses the outer level into the middle one — the distinction the three words exist to keep. In conversation the two are often swapped; in the product and in this documentation the plan is a handlingsplan.