Glossario
Tutti i termini di conformità,
resi semplici.
ISMS, SoA, CAPA, DPIA, Stage 2; ogni acronimo del nostro settore definito in modo semplice, con riferimenti alla norma pertinente e ai termini correlati.
Scopri tutti i termini.
SGSI
Sistema di Gestione della Sicurezza delle Informazioni
Il sistema di gestione della sicurezza delle informazioni
Un insieme strutturato di politiche, procedure, ruoli e controlli per la gestione della sicurezza delle informazioni. Essere certificati significa avere un ISMS funzionante, non solo documenti.
SoA
Statement of Applicability
Document declaring which ISO 27001 controls apply
The central ISMS document listing all 93 Annex A 2022 controls, justifying the inclusion or exclusion of each. The first document requested at Stage 1.
CAPA
Corrective and Preventive Action
Corrective and preventive actions for handling nonconformities
A process required by practically every ISO standard. It analyses the root cause and prevents the problem recurring.
DVR
Italian Risk Assessment Document
Mandatory Italian document for occupational health and safety
An Italian legal obligation, separate from ISO 45001 but able to be integrated with it. It remains mandatory even with 45001 certification.
RoPA
Record of Processing Activities
Register of personal data processing required by the GDPR
Article 30 of the GDPR requires almost every organisation to keep a register of all processing activities, with purposes, legal bases, recipients and retention periods.
Stage 1
The first audit visit: documentation and readiness review
The certification body checks that documentation exists, that the system is running and that there is enough evidence to schedule Stage 2. It usually lasts half a day or a day.
Stage 2
The certification audit proper
The auditor verifies on site how the system works through interviews, operational evidence and inspections. It ends with a report and any nonconformities to close before the certificate is issued.
Surveillance audit
Annual audits between certification and the three-year renewal
After initial certification the body returns each year to verify the system is maintained. Every three years there is a full renewal audit. These are critical moments if the system has not been kept up.
Nonconformity
NC
Un divario tra ciò che lo standard richiede e ciò che viene effettivamente fatto
Nonconformities can be minor (resolved with one action) or major (blocking the certificate). The aim is to handle them in a structured way.
Annex A
The list of 93 ISO 27001:2022 security controls
It lists 93 controls (down from 114 in the 2013 version) across four themes: organisational, people, physical and technological. The SoA maps them one by one.
Risk Assessment
The process of identifying, analysing and evaluating risk
Required by almost every ISO standard (27001, 9001, 14001, 45001). It identifies what can go wrong, how likely it is and how serious. It is the basis for deciding which controls to implement.
Root Cause
The root cause of a nonconformity or an incident
Root cause analysis (for example 5 Whys or Ishikawa) exists so you do not stop at the symptom. It is explicitly required in the corrective actions of ISO 9001, 27001 and 13485.
DPO
Data Protection Officer
The person responsible for personal data protection
A mandatory role for certain categories of controller (public bodies, systematic monitoring, sensitive data). Independent, reporting to leadership and protected from sanctions for their assessments.
DPIA
Data Protection Impact Assessment
Data protection impact assessment
Mandatory when processing presents a high risk to rights (new technologies, profiling, sensitive data). The output is a document justifying the choices made.
HLS
High Level Structure
The framework shared by all ISO management system standards
All ISO management system standards (9001, 14001, 27001, 45001) share ten clauses. This makes integration between systems both possible and worthwhile.
Integrated system
Several ISO standards run with a single documentation structure
Typically 9001+14001+45001 or 9001+27001. It uses the High Level Structure to avoid duplicated policies and meetings, cutting overhead by 40-60%.
NIS2
The European cybersecurity directive, implemented in Italy by Legislative Decree 138/2024
It requires around 50,000 Italian organisations (medium and large companies in critical sectors) to implement security measures, register on the national cybersecurity portal and report incidents.
ACN
Italian National Cybersecurity Agency
L'autorità responsabile per la sicurezza informatica
It receives NIS2 incident notifications, runs the register of in-scope entities, and can inspect and impose penalties. The first step is registering on its portal within the deadlines.
Management review
The annual meeting where top management assesses the system
Required by every ISO management system standard. It reviews audit results, nonconformities, objectives, resources and improvement opportunities. It is the moment leadership signs off on the system’s effectiveness.
Internal audit
A review of the system carried out by the organisation’s own people
Required at least annually by every ISO standard. Carried out by trained staff independent of the area being audited. Often supported by qualified external consultants.






