Risk register, security policy, and SOA each use different words for the same role — auditors call that a nonconformity. Manage ISO 27001 terminology in Confluence: version-controlled, approved, audit-exportable.
ISO 27001 terminology mapped to Clause 7.5 and Annex A controls, with four-eyes approval and audit-export history. Confluence-native. Built for information security teams preparing for ISO 27001:2022 certification or surveillance audits.
An Information Security Management System runs on documentation. Clause 7.5 of ISO 27001:2022 requires you to maintain documented information — policies, risk assessments, the Statement of Applicability, procedures, and records. Every one of those documents uses specialized terms. When the same concept has different names in different documents, auditors flag it.
ISMS documentation is interconnected. Your information security policy references your risk assessment. Your risk assessment feeds the Statement of Applicability. Your SOA maps to operational procedures. If “risk owner” means something different at each step, the chain breaks.
Terms that consistently cause problems in ISO 27001 audits:
Compliance Glossary helps you meet specific ISO 27001:2022 requirements:
| ISO 27001:2022 Reference | Requirement | How We Help |
|---|---|---|
| Clause 7.5 | Documented information — create, update, and control documents | Version-controlled definitions with full change history, mandatory change reasons, and approval workflow |
| Annex A 5.1 | Policies for information security — defined, approved, communicated | Single source of truth for policy terms ensures every policy references the same approved definitions |
| Annex A 5.3 | Segregation of duties — conflicting duties separated | Four-eyes principle enforced — the person who drafts a definition cannot approve it |
| Annex A 5.36 | Compliance with policies, rules and standards for information security | Audit-exportable history of definitions and approvals provides verifiable evidence that policy terminology is followed and reviewed |
| Annex A 8.1 | User endpoint devices — protection of information on devices | Consistent device terminology across acceptable use policies, asset inventories, and endpoint security procedures |
| Clause 6.1.2 | Information security risk assessment process | Consistent risk terms — threat, vulnerability, likelihood, impact defined once and used everywhere |
| Clause 9.2 | Internal audit at planned intervals | Compliance scanner catches terminology drift across Confluence spaces before audit season |
ISMS documented information — the information security policy, risk assessments, procedures, and records — usually lives in Confluence. Clause 7.5.3 of ISO/IEC 27001:2022 requires documented information to be controlled: distributed, accessed, stored, preserved, versioned, and disposed of in a managed way. Confluence covers storage and sharing well, but native Confluence has no term-level control: no approval workflow for definitions, no enforced version history per term, and no automated check that a page still uses the approved wording.
That gap surfaces at review time. Internal audits under Clause 9.2 and management reviews under Clause 9.3 run at planned intervals, and certification bodies repeat surveillance audits across the certification cycle. Each review compares documents written months apart — when “risk owner” or “corrective action” drifted between revisions, the documented-information chain breaks.
Compliance Glossary adds the term-level control layer on top of your existing Confluence spaces:
The ISO/IEC 27001 regulation pack is an editorial starter vocabulary — review it against your licensed copy of the standard before relying on it. One boundary we state plainly: Compliance Glossary is a voluntary supporting control. It does not issue ISO 27001 certification, does not replace an accredited certification body, and does not guarantee audit outcomes. It keeps the terminology layer of your documented information consistent, traceable, and exportable — the certification decision remains your auditor’s.
Key ISO 27001 and ISMS terms, organized by category:
| Category | Terms | Examples |
|---|---|---|
| ISMS Core | 8 | ISMS, Information Security Policy, Risk Assessment, Statement of Applicability |
| Annex A Controls | 8 | Access Control, Cryptography, Incident Management, Business Continuity |
| Risk Management | 6 | Threat, Vulnerability, Likelihood, Impact, Residual Risk |
| Audit & Compliance | 4 | Internal Audit, Management Review, Nonconformity, Corrective Action |
| Roles | 4 | Information Security Officer, Top Management, Competent Authority, Interested Party |
34 ISMS, risk, control, audit, and role terms. Submit your email and the packet is delivered to your inbox.
Start from the ISO 27001 terminology packet as a structural starting point, or define your ISO 27001 terms directly in the app. Each term arrives in “draft” status, ready for your team’s review.
Adapt definitions to your organization’s ISMS scope. “Risk owner” should match your risk assessment methodology exactly. Submit for review — another team member approves (four-eyes principle, enforced by the system).
The compliance scanner checks ISMS policy, risk, control, and procedure pages for deprecated terms, unapproved language, and synonym mismatches. Every finding links to the correct approved definition.
When the certification auditor arrives: export your full glossary with version history and approval chain. Every term shows who defined it, who approved it, and every change since creation. For a step-by-step walkthrough, see our documentation.
| Scope | Coverage | Details |
|---|---|---|
| YES | Centralized ISMS terminology | Single source of truth for risk, control, incident, and role definitions across all Confluence spaces |
| YES | Version history | Full change log with mandatory change reasons on every edit — supports Clause 7.5 documented information control |
| YES | Four-eyes approval | Drafter cannot approve own definition — supports Annex A 5.3 segregation of duties |
| YES | Audit export | CSV of terms (PDF on the 2026 roadmap) with full approval chain for certification and surveillance auditors |
| PARTIAL | Platform coverage | Confluence Cloud only. Not available for Jira, SharePoint, or standalone wiki systems |
| NO | ISMS software replacement | Does not manage risk registers, SOA, or control libraries — use dedicated ISMS tooling for those |
| NO | ISO 27001 certification | Does not issue, audit, or certify ISO 27001 compliance — that requires an accredited certification body |
| NO | Risk assessments | Does not perform threat modeling, risk scoring, or risk treatment workflows |
Build your ISO 27001 glossary in Confluence. Approve your definitions. Scan your docs. Hand the export to your certification auditor. Review our transparent app limitations for full details on what we do and don’t cover.
Evaluate in Confluence Get Free PacketSOC 2 Terminology — 40 Trust Services Criteria terms for InfoSec & GRC teams
NIS2 Directive Terminology — EU cybersecurity compliance terminology guide
DORA Terminology — financial services digital resilience terminology guide
Four-Eyes Principle — approval workflows mapped to SOX, MiFID II, ISO 27001
Security Whitepaper — Forge architecture, SOC 2 / ISO 27001 / DORA / NIS2 coverage
Regulatory Diligence for CEOs — how terminology governance affects fundraising & board reporting
Compliance for Confluence — how compliance teams run audits and evidence inside Confluence
Compliance Guide — what auditors check and how we help