> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# ISMS Reference

> Risk levels, treatment strategies, objective statuses, due dates, and terms of the ISMS module.

## Risk assessment

The risk matrix axis labels for values 1 through 5:

| Value | Likelihood | Impact |
| - | - | - |
| 1 | *Rare* | *Insignificant* |
| 2 | *Unlikely* | *Minor* |
| 3 | *Possible* | *Moderate* |
| 4 | *Likely* | *Major* |
| 5 | *Almost Certain* | *Catastrophic* |

Risk levels: *Low*, *Medium*, *High*, *Critical*.

## Treatment strategies

| Strategy | Meaning |
| - | - |
| *Mitigate* | Implement controls to lower the risk |
| *Transfer* | Transfer the risk to a third party |
| *Avoid* | Discontinue the triggering activity or system |
| *Accept* | Knowingly bear and document the risk |

## Control priority

*Low*, *Medium*, *High*, *Critical*.

## Control status

*Open*, *Planned*, *In Progress*, *Implemented*.

## Evidence effectiveness

*Effective*, *Partially Effective*, *Ineffective*.

## Control category

Docusnap365 provides the categories; they appear in the interface language.

## Recurrence units

*Days*, *Weeks*, *Months*, *Years*. With an interval of 1, an adverb appears
instead of "Every 1 month": *Daily*, *Weekly*, *Monthly*, *Yearly*.

## Regulation types

*Standard*, *Law*, *Catalog*, *Custom*.

## Objective status

*Pending*, *Not implemented*, *Partial*, *Complete*, *Not applicable*.

## Terms

**Threat** — An event that can cause harm.

**Vulnerability** — A gap that makes the event possible.

**Scenario** — The combination of at least one threat and at least one
vulnerability in a risk.

**Risk assessment** — The product of likelihood and impact.

**Risk reduction** — The difference between the current and target
assessment. A positive value means the risk goes down; the display then
reads *Risk Reduction*, *Risk Increase* with a higher target, or *No Change*
with an equal value.

**Protection need** — The highest of the three levels of *Confidentiality*,
*Integrity*, and *Availability* for an asset (the Maximum Principle).

**Owner / Responsible** — The person accountable for a risk, a control, or an
asset's protection need. Docusnap365 uses *Owner* on the risk and *Responsible*
on the control and in the asset's *ISMS* tab.

**Recurrence** — Whether a control is carried out once or repeatedly.

**Evidence** — The record of a control's execution, with effectiveness and
result.

**Regulation** — The umbrella term for anything compliance is measured
against: a standard, law, catalog, or custom regulation.

**Objective** — The individual, assessable item of a regulation. Only the
leaves of the objective tree are assessable; an objective has no detail page
of its own — clicking one opens the regulation it belongs to instead.

**Gap** — An applicable objective that is not fully implemented, unconfirmed
objectives included. The *Gaps* KPI carries the subtitle *Open, not or
partially implemented*.

**Review** — The recurring check on a risk, a control, or a regulation's
objective.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.