Gérer les cookies
Ce site utilise des cookies pour recueillir des informations sur votre navigation afin de vous proposer des contenus et des offres promotionnelles plus pertinents, et pour nous aider à comprendre vos centres d'intérêt et à améliorer le site. Consultez notre politique relative aux cookies pour en savoir plus.
Gérer les cookies
Paramètres des cookies
Les cookies nécessaires au bon fonctionnement du site sont toujours activés.
Les autres cookies sont configurables.
Cookies essentiels
Toujours activés. Ces cookies sont indispensables au fonctionnement du site web et à l'utilisation de ses fonctionnalités. Ils ne peuvent pas être désactivés. Ils sont installés en réponse à vos demandes, comme la configuration de vos préférences de confidentialité, la connexion à votre compte ou le remplissage de formulaires.
Cookies analytiques
Désactivé
Ces cookies recueillent des informations qui nous permettent de comprendre comment nos sites Web sont utilisés, d'évaluer l'efficacité de nos campagnes marketing et de personnaliser nos sites Web pour vous. Consultez ici la liste des cookies analytiques que nous utilisons.
Cookies publicitaires
Désactivé
Ces cookies permettent aux sociétés de publicité de recueillir des informations sur votre activité en ligne afin de vous proposer des publicités plus pertinentes ou de limiter le nombre d'affichages d'une même publicité. Ces informations peuvent être partagées avec d'autres sociétés de publicité. Consultez ici la liste des cookies publicitaires que nous utilisons.
Resilience Glossary: 35 Terms Defined | Resilience Guard
Home  ›  Insights  › Glossary
The language of the discipline

The resilience glossary

The 35 terms that carry the discipline, defined in plain language, from BIA and RTO to NIS2, DORA and the Swiss ISG.

Practitioner led since 2014 Led by John Zeppos, Founder and Group Managing Director DRI Accredited training provider 2 BCI Global Awards 16+ EU Horizon research projects Trusted to train 3 of the Big Four

Precision of language is precision of thought. These are the terms Resilience Guard uses with clients, boards and auditors, defined the way we mean them: short, exact and free of vendor mystique.

Business continuity (BC)

The capability of an organisation to continue delivering its critical products and services at acceptable predefined levels following a disruption.

Business continuity management (BCM)

The management discipline of identifying threats to an organisation, understanding their impact on critical activities, and building a rehearsed capability to keep those activities running and recover quickly. See the full guide on our business continuity management page.

Business continuity management system (BCMS)

The formal, auditable framework that establishes, operates, monitors, reviews, maintains and continually improves business continuity across an organisation. A BCMS can be certified against ISO 22301.

Business continuity plan (BCP)

The documented, rehearsed set of procedures that keeps an organisation's critical activities running during a disruption and recovers them within defined timeframes. See our BCP guide.

Business impact analysis (BIA)

The process of identifying an organisation's critical activities, the resources they depend on, and the impact of their interruption over time, producing recovery priorities and objectives.

CER Directive and KRITIS

Directive (EU) 2022/2557 on the resilience of critical entities, applying since 18 October 2024, and Germany's related KRITIS regime: all hazards resilience duties for critical entities across eleven sectors.

Crisis exercise

A structured rehearsal of an organisation's response to a realistic scenario, producing a recorded timeline, findings and corrective actions. See crisis exercising.

Gestion de crise

The leadership discipline of directing an organisation through a disruptive event: assessment, decision making, communication and coordination under pressure, with clear authority and one log.

Critical ICT third party provider (CTPP)

An ICT service provider designated as critical to the EU financial sector under DORA and placed under the direct oversight of a Lead Overseer from the European Supervisory Authorities; financial entities must manage the concentration risk such providers represent.

Critical infrastructure

Assets, systems and services whose disruption would have significant impact on society, the economy or public safety, and which regulation increasingly names and obliges directly.

Cyber resilience

An organisation's ability to keep operating and to lead through a cyber attack: technical response, business continuity and crisis management working as one rehearsed system. See cyber resilience.

Disaster recovery (DR) and IT disaster recovery (ITDR)

The restoration of IT systems, applications and data after disruption, usually to defined recovery time and recovery point objectives; one component of business continuity, not a synonym for it.

DORA

The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, applying since 17 January 2025: ICT risk management, incident reporting, resilience testing and oversight of critical ICT providers for financial entities.

Essential and important entities

The two classes of organisation regulated by NIS2 across its annex sectors, set chiefly by size and sector: essential entities face proactive supervision, important entities ex post supervision, with broadly the same duty set applying to both.

ICT risk management framework

The documented framework DORA requires of financial entities: strategies, policies, protocols and tools covering identification, protection, detection, response, recovery, learning and communication for ICT risk, approved and owned by the management body.

Impact tolerance

The maximum level of disruption to an important service an organisation is prepared to accept, expressed as a defined limit such as duration or volume, set consciously by leadership.

Incident response

The organised approach to detecting, containing and resolving a disruptive event in its earliest phase, before or alongside invocation of continuity and crisis arrangements.

ISG (Swiss Information Security Act)

The Swiss federal Information Security Act (SR 128), in force since 1 January 2024, with a 24 hour duty to report significant cyber attacks on critical infrastructure to BACS since 1 April 2025 and sanctions since 1 October 2025. See our German language guide.

ISO 22301

The international standard for business continuity management systems: the certifiable framework covering leadership, business impact analysis, plans, exercising, audit and continual improvement.

ISO 27001

The international standard for information security management systems, covering the governance, risk treatment and controls that protect information assets; increasingly integrated with ISO 22301 in one management system.

Major ICT related incident (DORA)

An ICT incident meeting DORA's classification thresholds, triggering the regulation's reporting sequence to the competent authority: initial notification, intermediate report and final report within the deadlines set by the technical standards.

Management accountability (NIS2)

NIS2's explicit placement of cybersecurity duty on management bodies: they must approve and oversee risk management measures, undergo training, and can be held personally liable for infringements.

Maximum tolerable period of disruption (MTPD)

The time after which the viability of an organisation would be irreparably threatened if delivery of a product, service or activity is not resumed.

Minimum business continuity objective (MBCO)

The minimum level of a product, service or activity that an organisation commits to deliver during a disruption, agreed in advance rather than improvised.

NIS2

Directive (EU) 2022/2555 on cybersecurity across the Union, with national transposition due by 17 October 2024: risk management, continuity, incident reporting and management accountability for essential and important entities.

Operational resilience

The ability of an organisation to anticipate, prevent, withstand, respond to, recover from and adapt to disruption so its critical services continue within set tolerances. See our definition page.

Partie 1

The EU aviation information security regime: Delegated Regulation (EU) 2022/1645 applying from 16 October 2025 and Implementing Regulation (EU) 2023/203 from 22 February 2026, requiring information security management across aviation organisations and authorities.

Recovery point objective (RPO)

The maximum tolerable amount of data loss measured in time: the point to which data must be restored after an incident.

Recovery time objective (RTO)

The target time within which a product, service, activity or system must be resumed after a disruption.

Register of information (DORA)

The register DORA requires financial entities to maintain of all contractual arrangements with ICT third party providers, at entity, sub consolidated and consolidated level, available to the competent authority on request.

L'évaluation des risques

The systematic identification, analysis and evaluation of risks to an organisation's critical activities, informing which threats are reduced, transferred, accepted or planned against.

Significant incident (NIS2)

An incident meeting NIS2's significance criteria, starting the directive's reporting clock: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month to the CSIRT or competent authority.

Single point of failure (SPOF)

Any resource, person, system, site or supplier, whose failure alone would interrupt a critical activity because no alternative exists; the honest output of a good dependency analysis.

Third party risk

The exposure an organisation inherits from suppliers and service providers whose failure or compromise would disrupt its own critical activities; a named focus of DORA, NIS2 and supervisory regimes.

Threat led penetration testing (TLPT)

Advanced testing under DORA for designated financial entities: intelligence led attacks on live production systems, based on the TIBER-EU framework, at least every three years, with findings feeding the ICT risk framework.

No term matches that filter. Try a shorter fragment, or ask us directly.

Lancez la conversation

When the vocabulary becomes a programme.

Definitions are the start; capability is the point. Talk to a practitioner about where you are. We respond within 24 hours.

Prendre rendez-vous pour une consultation
Toutes les consultations sont traitées dans le respect de la stricte confidentialité.