Glossary
This glossary brings together the key terms used on the e-Analyze Risk platform. Refer to this page whenever a term seems imprecise or ambiguous.
Platform terms
Asset Any element of the information system that has value for the organisation. An asset can be hardware, software, data, a process or a person.
Security Review Security report generated by the AI agent, which assesses the acceptability of a software solution against the organisation's security requirements.
Measure catalogue Reference set of security controls (for example MITRE ATT&CK) used as a basis to recommend remediation measures. A project can be associated with several catalogues.
Criticality Priority level of a risk, calculated from its likelihood and its impact. Four levels are possible: Low, Medium, High, Very high.
Lifecycle Progress status of a project. Available values are: New project, Improvement, Migration, Production and Legacy.
AICT Acronym referring to the four fundamental criteria of information security: Availability, Integrity, Confidentiality and Traceability.
Feared event Undesirable impact scenario likely to affect one or more AICT criteria of an asset.
Remediation measure Concrete action put in place to treat an identified risk.
Qualification Initialisation phase of a project. It defines the scope, in-scope assets and security needs before launching the risk analysis.
Risk Scenario combining a threat source, a feared event and an estimate of its likelihood and impact.
Risk source Actor or origin of the threat (for example: external attacker, human error, hardware failure).
Treatment Decision made to handle a risk. Four strategies are possible: Reduce, Avoid, Accept or Transfer.
You will find these terms throughout the documentation, in particular in the Qualification and Risk analysis sections.