Archives Glossary Terms

RA

Risk Assessment The process through which risks are assessed and quantified, but can also include the identification and control process.  Risk Assessment is used within Health & Safety, Information Security and Business Risk.

SOA

Statement of Applicability A requirement of ISO 27001.  The SOA lists the controls provided within the standard and justifies their inclusion or exclusion by the organisation.

OFI

Opportunity for Improvement something that has been identified as having potential for improvement and could escalate to a non-conformance

Obs

Observation Something that has been noted as potentially negative or non-compliant

NC

Non Conformance Something that has not met requirements. Identified as Major or Minor.

CAR

Corrective Action Request Actions required to address / close out a non conformance.

CB

Certification Body An organisation responsible for assessing a management system and providing certification.

UKAS

United Kingdom Accreditation Service National accreditation body that assesses the competence of Certification Bodies. More:

EnMS

Energy Management System A structured system for Energy management often following the ISO 50001 standard. May or may not be certified.

CAB

Change Advisory Board Provides support to a change management team by approving changes and assisting in prioritisation and assessment.