SIDD Glossary, Data Protection and Information Security
Key terms from data protection (Swiss DSG / GDPR), information security (ISO 27001, NIS2) and offensive security. Concise, sourced definitions.
A
Annex A (ISO 27001)Information Security
Annex A of ISO/IEC 27001:2022 is a normative catalogue of 93 information security controls grouped into four themes: organizational, people, physical, and technological. It provides the reference list organizations use to select and justify controls in the Statement of Applicability and is a mandatory component of every certification audit.
AnonymizationData Protection
Anonymization is the irreversible processing of personal data so that the data subject can no longer be identified, or only with disproportionate effort. Correctly anonymized data falls outside both the Swiss DSG and the GDPR. What matters is effectiveness against realistic re-identification attacks, not the mere removal of names.
B
Binding Corporate Rules (BCRs)Data Protection
Binding Corporate Rules are internal data protection rules approved by the competent EU supervisory authority that bind all entities of a corporate group. They enable lawful intra-group transfers of personal data to third countries as an alternative to Standard Contractual Clauses. The approval procedure is demanding but creates a durable transfer basis, particularly attractive for multinational groups with centralized IT and HR systems.
C
CIA Triad (Confidentiality · Integrity · Availability)Information Security
The CIA Triad denotes the three classical security objectives of information security: confidentiality, integrity, and availability. It forms the conceptual core of every ISMS and every risk analysis. From these three objectives, protection-needs classes, technical controls, and KPIs are derived, all of which are addressed systematically in ISO/IEC 27001.
CIS CertInformation Security
CIS Cert (CIS, Certification & Information Security Services GmbH) is an accredited certification body of the Quality Austria Group, based in Vienna. It certifies management systems worldwide against ISO/IEC 27001 and related standards. SIDD regularly accompanies Swiss and EU clients through stage-1 and stage-2 audits with CIS Cert and handles the full audit preparation.
CISO (Chief Information Security Officer)Roles & Organization
The Chief Information Security Officer is the executive-level owner of an organization's information security strategy, ISMS, and risk governance. The CISO typically reports directly to the CEO or board. SMEs frequently engage the function as external CISO-as-a-Service to cover regulatory requirements from NIS2, ISO 27001, or the Swiss ICT minimum standard economically.
ControllerData Protection
The controller is the natural or legal person, public authority, or body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The role is named Verantwortlicher in the Swiss DSG and controller in the GDPR. The controller bears the accountability obligation, concludes DPAs with processors, and is the primary addressee of supervisory measures.
CVSSOffensive Security
The Common Vulnerability Scoring System is an open industry standard for rating the severity of technical vulnerabilities on a scale from 0.0 to 10.0. CVSS v3.1 and v4.0 account for attack vector, complexity, required privileges, and impact. SIDD applies CVSS in penetration test reports so clients can prioritize findings objectively and delegate them reproducibly to developers.
D
Data Processing Agreement (DPA)Data Protection
A Data Processing Agreement governs in writing how a processor handles personal data on behalf of the controller. It is mandatory under Art. 28 GDPR and Art. 9 DSG and defines the subject matter, duration, nature, and purpose of the processing as well as the technical and organizational measures. Without a valid DPA, the controller risks a breach of the processing-security principle.
Data Protection Impact Assessment (DPIA)Data Protection
A Data Protection Impact Assessment is a documented process for the prior evaluation of processing operations likely to result in a high risk to data subjects. It describes the processing, its necessity, the risks, and the safeguards. Under Art. 35 GDPR and Art. 22 DSG it is mandatory for systematic monitoring, sensitive data, or new technologies and is a precondition for lawful deployment.
Data Protection Officer (DPO)Data Protection
The Data Protection Officer monitors compliance with data protection law within the organization, advises management, and serves as contact point for supervisory authorities and data subjects. Under Art. 37 GDPR the appointment is mandatory in defined cases; the Swiss DSG instead provides for the voluntary data protection advisor under Art. 10. SIDD provides the role as an external mandate solution for SMEs.
Data subject rightsData Protection
Data subject rights are the enforceable claims of natural persons against controllers, including access, rectification, erasure, restriction, data portability, and objection. They are anchored in Art. 12–22 GDPR and Art. 25 et seq. DSG. Organizations must respond to requests within one month and maintain demonstrable processes to handle the rights efficiently and lawfully.
DSG (Swiss Federal Act on Data Protection, FADP)Data Protection
The Swiss DSG, in English the Federal Act on Data Protection (FADP), governs the processing of personal data by private parties and federal bodies in Switzerland. The fully revised version entered into force on 1 September 2023 and introduced, among other things, breach notification duties, the records of processing activities, and criminal-law duties for natural persons. The DSG is GDPR-compatible but not identical. The maximum personal fine under Art. 60 DSG is CHF 250,000.
E
EU Representative (Art. 27 GDPR)Data Protection
The EU Representative is the EU-based point of contact for a controller or processor established in a third country, such as Switzerland. The representative is appointed in writing, represents the organization vis-à-vis supervisory authorities and data subjects, and co-maintains the records of processing activities. The obligation regularly applies when goods, services, or behavioural monitoring are offered to EU persons on a regular basis.
External Data Protection AdvisorRoles & Organization
The External Data Protection Advisor is the voluntary role provided for in the Swiss DSG under Art. 10. The advisor counsels the controller independently, trains staff, and can be registered with the FDPIC, which removes the obligation to consult on DPIAs. SIDD offers the role as a mandate solution for Swiss SMEs and group companies, including documented availability. This is distinct from the EU DPO under Art. 37 GDPR.
F
FDPIC (Federal Data Protection and Information Commissioner)Data Protection
The Federal Data Protection and Information Commissioner is Switzerland's independent supervisory authority for the DSG. The FDPIC advises federal bodies and private parties, investigates data protection violations, issues binding measures, and maintains the register of data protection advisors. Personal data breaches involving a high risk must be reported to the FDPIC. Its practice has shaped the interpretation of the revised DSG materially since September 2023.
G
GDPR (General Data Protection Regulation)Data Protection
The General Data Protection Regulation is EU Regulation 2016/679 and has applied directly in all EU and EEA states since 25 May 2018. It governs the processing of personal data and has extraterritorial effect via the market-place principle. Swiss organizations offering goods or services to EU data subjects fall under it directly and frequently need an EU Representative under Art. 27. Maximum fines reach EUR 20m or 4% of global annual turnover under Art. 83.
Group Data Protection OfficerRoles & Organization
The Group Data Protection Officer performs the DPO function group-wide for several affiliated companies. Under Art. 37(2) GDPR the prerequisite is easy accessibility from every establishment. The consolidation creates uniform standards, DPA templates, and training programmes and is in particular the organizational backbone for Binding Corporate Rules in multinational groups.
I
ISB (Information Security Officer, German title)Roles & Organization
The ISB (Informationssicherheitsbeauftragter) is operationally responsible for the establishment, operation, and continuous improvement of the ISMS and typically reports to the CISO or executive management. The role coordinates risk analyses, training, internal audits, and maintenance of the Statement of Applicability. In smaller organizations the role often merges with that of the CISO or is sourced externally. The German title is preserved because the role taxonomy is German-language.
ISMSInformation Security
An Information Security Management System is a documented, risk-based management system for protecting an organization's information assets. It comprises policies, roles, processes, controls, and continuous improvement following the PDCA cycle. ISO/IEC 27001 defines the normative requirements, fulfilment of which is the precondition for certification, for example through CIS Cert.
ISO (Information Security Officer per eCH-0199)Roles & Organization
The ISO (Informationssicherheitsoffizier) is the role defined in eCH-0199 of the Swiss e-government standards and is a Swiss public-sector role. The officer steers the information security of an administrative unit or project, coordinates protection-needs analyses, and ensures conformity with overarching requirements. The acronym collides with the ISO standards body; in the Swiss public-sector environment the role is nonetheless established and relevant in tenders.
ISO/IEC 17021Information Security
ISO/IEC 17021 sets out the requirements for bodies that audit and certify management systems. It defines independence, competence, the audit process, and reporting duties. Accredited certifiers such as CIS Cert must comply with the standard so that their certificates are internationally recognized. For clients it serves as a quality signal when selecting a certification body.
ISO/IEC 27001Information Security
ISO/IEC 27001 is the international standard for Information Security Management Systems. The 2022 edition defines binding requirements in clauses 4–10 and references 93 controls in Annex A. A successful certification by accredited bodies such as CIS Cert demonstrably proves that an organization governs information security in a risk-based and systematic manner.
ISO/IEC 27002Information Security
ISO/IEC 27002 is the guide to selecting, implementing, and governing the 93 information security controls from Annex A of ISO/IEC 27001. For each control it provides purpose, implementation guidance, and further information. The 2022 edition assigns the controls to four themes and introduces five attributes for categorization, such as cybersecurity concept and security objective.
N
NIS2Information Security
The NIS2 Directive (EU 2022/2555) requires essential and important entities in 18 sectors to operate risk-based cybersecurity management, comply with notification duties, and assume management-level responsibility. It has had to be transposed into national law since 18 October 2024. Swiss organizations with EU establishments or as suppliers to critical infrastructures frequently fall under NIS2 indirectly and need a conformant ISMS.
O
OWASP Top 10Offensive Security
The OWASP Top 10 is the internationally recognized list of the ten most prevalent and severe security risks for web applications. It is updated regularly by the Open Worldwide Application Security Project, most recently in 2021. SIDD tests every web application during penetration testing against the Top 10 categories such as Broken Access Control, Injection, and Cryptographic Failures and documents findings reproducibly.
P
Penetration testOffensive Security
A penetration test is a controlled, authorized simulation of real attacks against systems, applications, or networks, intended to surface exploitable vulnerabilities before real attackers do. SIDD works manually and with tooling support, classifies findings by CVSS, and delivers prioritized remediation recommendations. Penetration tests complement automated vulnerability scans and are a precondition for many ISO 27001 certifications and customer audits.
Personal data breachData Protection
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data. Under the GDPR it must be reported to the supervisory authority within 72 hours; under the Swiss DSG it must be reported to the FDPIC as soon as possible. Affected data subjects must additionally be informed where the risk is high.
PseudonymizationData Protection
Pseudonymization is the processing of personal data such that the data can no longer be attributed to a specific data subject without additional information, which is kept separately. Unlike anonymization, it is reversible; the data remains personal and stays subject to the DSG and GDPR. It is considered an effective technical safeguard and is explicitly named in Art. 32 GDPR.
R
Records of Processing Activities (ROPA)Data Protection
Records of Processing Activities systematically document every processing operation of an organization, including purposes, categories of data subjects and data, recipients, third-country transfers, retention periods, and technical and organizational measures. They are mandatory under Art. 30 GDPR and Art. 12 DSG and are the central evidence instrument of the accountability obligation. SMEs under 250 employees benefit from narrow exemptions, but only under conditions.
Responsible DisclosureOffensive Security
Responsible Disclosure is the coordinated process by which security researchers report discovered vulnerabilities to the vendor confidentially and grant reasonable time to remediate before publication. A published vulnerability disclosure policy creates legal certainty for both sides and is a component of mature security programmes under ISO/IEC 27001 and NIS2.
Risk treatmentInformation Security
Risk treatment is the documented decision in the ISMS as to how an identified information security risk is governed: avoid, mitigate, transfer, or accept. It connects the risk analysis with concrete controls from Annex A and culminates in the risk treatment plan. Acceptance decisions must be approved by the risk owners and are a mandatory evidence item in the ISO/IEC 27001 audit.
S
Security objective (confidentiality / integrity / availability)Information Security
Security objectives describe which property of an information asset is to be protected. The classical objectives are confidentiality, integrity, and availability, the CIA Triad. Modern frameworks add authenticity, non-repudiation, and accountability. In the ISMS, protection-needs classes are defined per asset for each security objective, and these subsequently steer the selection of controls from Annex A of ISO/IEC 27001.
Standard Contractual Clauses (SCCs)Data Protection
Standard Contractual Clauses are contract templates approved by the European Commission that serve as a safeguard for transfers of personal data to third countries lacking an adequacy decision. The 2021 modules cover the most relevant constellations. Controllers must additionally conduct a Transfer Impact Assessment and, where required, implement supplementary technical measures such as encryption or pseudonymization.
Statement of Applicability (SoA)Information Security
The Statement of Applicability is the central control document in the ISMS in which, for each of the 93 controls from Annex A of ISO/IEC 27001, the applicability, implementation status, and justification are documented. Exclusions must be substantively justified. The SoA is a mandatory evidence item in the stage-1 audit and therefore a precondition for every certification, for example through CIS Cert.
Swiss Data Protection Ordinance (DSV)Data Protection
The Swiss Data Protection Ordinance (DSV) concretizes the DSG and entered into force together with the revised act on 1 September 2023. It governs detailed questions regarding data security, the records of processing activities, cross-border disclosure, data protection impact assessment, and the role of the data protection advisor. Controllers must adapt their processes, DPAs, and technical measures to the DSV requirements.
Swiss ICT minimum standardInformation Security
The Swiss ICT minimum standard (BWL ICT-Minimalstandard) is a framework recommended by the Federal Office for National Economic Supply to strengthen ICT resilience of critical infrastructures in Switzerland. It is based on the NIST Cybersecurity Framework and defines 106 measures across five functions. It is not mandatory but serves as a reference for utilities, public authorities, and SMEs during audits.
T
Technical and organizational measures (TOMs)Data Protection
Technical and organizational measures are the safeguards required by Art. 32 GDPR and Art. 8 DSG to ensure processing security. They include access controls, encryption, pseudonymization, backup concepts, training, and incident-response processes. TOMs must be described in the Data Processing Agreement and must be proportionate to the protection need, the state of the art, and the cost of implementation.
TISAXInformation Security
TISAX (Trusted Information Security Assessment Exchange) is the assessment and exchange mechanism of the German automotive industry for information security at suppliers. It is based on the VDA ISA catalogue, which is closely aligned with ISO/IEC 27001. Audits are performed by approved providers; results are shared with awarding parties via the ENX platform and constitute de facto market access in the automotive sector.
V
Vulnerability scanOffensive Security
A vulnerability scan is the automated examination of systems and applications for known security vulnerabilities using signatures and CVE databases. It delivers broad coverage in a short time but without manual verification. SIDD deploys regular scans as a cost-effective complement to penetration tests and prioritizes findings by CVSS, reachability, and business criticality.