Information Security

ISO 27001 Terminology Management for Confluence

Risk register, security policy, and SOA each use different words for the same role — auditors call that a nonconformity. Manage ISO 27001 terminology in Confluence: version-controlled, approved, audit-exportable.

ISO 27001 terminology mapped to Clause 7.5 and Annex A controls, with four-eyes approval and audit-export history. Confluence-native. Built for information security teams preparing for ISO 27001:2022 certification or surveillance audits.

Compliance Glossary terms table in Confluence with Regulation Packs import, approval statuses, lifecycle state, and version history
Compliance Glossary for Confluence: version-controlled terms with approval statuses, lifecycle tracking, and one-click Regulation Packs import.

Why does ISO 27001 terminology cause audit findings?

An Information Security Management System runs on documentation. Clause 7.5 of ISO 27001:2022 requires you to maintain documented information — policies, risk assessments, the Statement of Applicability, procedures, and records. Every one of those documents uses specialized terms. When the same concept has different names in different documents, auditors flag it.

ISMS documentation is interconnected. Your information security policy references your risk assessment. Your risk assessment feeds the Statement of Applicability. Your SOA maps to operational procedures. If “risk owner” means something different at each step, the chain breaks.

Common pattern in audits: when role definitions diverge between the risk register and the information security policy — for example, a different scope or accountability for “risk owner” in each document — this can be cited as inconsistent documented information under ISO/IEC 27001:2022 Clause 7.5 and as a gap in the risk assessment process under Clause 6.1.2.

Terms that consistently cause problems in ISO 27001 audits:

How does Compliance Glossary map to ISO 27001:2022?

Compliance Glossary helps you meet specific ISO 27001:2022 requirements:

ISO 27001:2022 ReferenceRequirementHow We Help
Clause 7.5Documented information — create, update, and control documentsVersion-controlled definitions with full change history, mandatory change reasons, and approval workflow
Annex A 5.1Policies for information security — defined, approved, communicatedSingle source of truth for policy terms ensures every policy references the same approved definitions
Annex A 5.3Segregation of duties — conflicting duties separatedFour-eyes principle enforced — the person who drafts a definition cannot approve it
Annex A 5.36Compliance with policies, rules and standards for information securityAudit-exportable history of definitions and approvals provides verifiable evidence that policy terminology is followed and reviewed
Annex A 8.1User endpoint devices — protection of information on devicesConsistent device terminology across acceptable use policies, asset inventories, and endpoint security procedures
Clause 6.1.2Information security risk assessment processConsistent risk terms — threat, vulnerability, likelihood, impact defined once and used everywhere
Clause 9.2Internal audit at planned intervalsCompliance scanner catches terminology drift across Confluence spaces before audit season

ISO 27001 Documentation in Confluence: Where Terminology Fits

ISMS documented information — the information security policy, risk assessments, procedures, and records — usually lives in Confluence. Clause 7.5.3 of ISO/IEC 27001:2022 requires documented information to be controlled: distributed, accessed, stored, preserved, versioned, and disposed of in a managed way. Confluence covers storage and sharing well, but native Confluence has no term-level control: no approval workflow for definitions, no enforced version history per term, and no automated check that a page still uses the approved wording.

That gap surfaces at review time. Internal audits under Clause 9.2 and management reviews under Clause 9.3 run at planned intervals, and certification bodies repeat surveillance audits across the certification cycle. Each review compares documents written months apart — when “risk owner” or “corrective action” drifted between revisions, the documented-information chain breaks.

Compliance Glossary adds the term-level control layer on top of your existing Confluence spaces:

The ISO/IEC 27001 regulation pack is an editorial starter vocabulary — review it against your licensed copy of the standard before relying on it. One boundary we state plainly: Compliance Glossary is a voluntary supporting control. It does not issue ISO 27001 certification, does not replace an accredited certification body, and does not guarantee audit outcomes. It keeps the terminology layer of your documented information consistent, traceable, and exportable — the certification decision remains your auditor’s.

ISO 27001 Terminology — Categorized

Key ISO 27001 and ISMS terms, organized by category:

ISMS Core (8 terms)

Information Security Management System
Information Security Policy
Risk Assessment
Risk Treatment
Statement of Applicability
Risk Owner
Security Objective
Continual Improvement

Annex A Controls (8 terms)

Access Control
Cryptography
Physical Security
Operations Security
Communications Security
Supplier Relationships
Incident Management
Business Continuity

Risk Management (6 terms)

Threat
Vulnerability
Likelihood
Impact
Residual Risk
Risk Acceptance

Audit & Compliance (4 terms)

Internal Audit
Management Review
Nonconformity
Corrective Action

Roles (4 terms)

Information Security Officer
Top Management
Competent Authority
Interested Party
CategoryTermsExamples
ISMS Core8ISMS, Information Security Policy, Risk Assessment, Statement of Applicability
Annex A Controls8Access Control, Cryptography, Incident Management, Business Continuity
Risk Management6Threat, Vulnerability, Likelihood, Impact, Residual Risk
Audit & Compliance4Internal Audit, Management Review, Nonconformity, Corrective Action
Roles4Information Security Officer, Top Management, Competent Authority, Interested Party

Free ISO 27001 Terminology Packet

34 ISMS, risk, control, audit, and role terms. Submit your email and the packet is delivered to your inbox.

How Teams Use This for ISO 27001 Audit Prep

Step 1: Build Your Term Set

Start from the ISO 27001 terminology packet as a structural starting point, or define your ISO 27001 terms directly in the app. Each term arrives in “draft” status, ready for your team’s review.

Step 2: Customize and Approve

Adapt definitions to your organization’s ISMS scope. “Risk owner” should match your risk assessment methodology exactly. Submit for review — another team member approves (four-eyes principle, enforced by the system).

Step 3: Scan Your Documentation

The compliance scanner checks ISMS policy, risk, control, and procedure pages for deprecated terms, unapproved language, and synonym mismatches. Every finding links to the correct approved definition.

Step 4: Audit Evidence Package

When the certification auditor arrives: export your full glossary with version history and approval chain. Every term shows who defined it, who approved it, and every change since creation. For a step-by-step walkthrough, see our documentation.

Who Uses This

What this app does / does not do

ScopeCoverageDetails
YESCentralized ISMS terminologySingle source of truth for risk, control, incident, and role definitions across all Confluence spaces
YESVersion historyFull change log with mandatory change reasons on every edit — supports Clause 7.5 documented information control
YESFour-eyes approvalDrafter cannot approve own definition — supports Annex A 5.3 segregation of duties
YESAudit exportCSV of terms (PDF on the 2026 roadmap) with full approval chain for certification and surveillance auditors
PARTIALPlatform coverageConfluence Cloud only. Not available for Jira, SharePoint, or standalone wiki systems
NOISMS software replacementDoes not manage risk registers, SOA, or control libraries — use dedicated ISMS tooling for those
NOISO 27001 certificationDoes not issue, audit, or certify ISO 27001 compliance — that requires an accredited certification body
NORisk assessmentsDoes not perform threat modeling, risk scoring, or risk treatment workflows

Full transparent app limitations →

Sources

Audit-Ready ISMS Terminology in Minutes

Build your ISO 27001 glossary in Confluence. Approve your definitions. Scan your docs. Hand the export to your certification auditor. Review our transparent app limitations for full details on what we do and don’t cover.

Evaluate in Confluence Get Free Packet

Related Compliance Resources

SOC 2 Terminology — 40 Trust Services Criteria terms for InfoSec & GRC teams

NIS2 Directive Terminology — EU cybersecurity compliance terminology guide

DORA Terminology — financial services digital resilience terminology guide

Four-Eyes Principle — approval workflows mapped to SOX, MiFID II, ISO 27001

Security Whitepaper — Forge architecture, SOC 2 / ISO 27001 / DORA / NIS2 coverage

Regulatory Diligence for CEOs — how terminology governance affects fundraising & board reporting

Compliance for Confluence — how compliance teams run audits and evidence inside Confluence

Compliance Guide — what auditors check and how we help