The terms in this section establish a shared vocabulary for cybersecurity risk work. Begin with systems, information and security outcomes, then distinguish risk, assessment methods, exposure, aggregation, appetite and tolerance.
Use the explanations to clarify your organisation's own criteria before assigning scores. A common label is useful only when reviewers understand the scope, scale and assumptions behind it.