# SIDD Glossary, Data Protection and Information Security

> SIDD glossary: 40 central terms from data protection (Swiss DSG / GDPR), information security (ISO 27001, NIS2, TOMs) and offensive security (OWASP, pentest). Definitions, related terms, sources.

- Source: https://www.sidd.swiss/en/glossary/
- Language: en
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

Key terms from data protection (Swiss DSG / GDPR), information security (ISO 27001, NIS2) and offensive security. Concise, sourced definitions.

## A

### Annex A (ISO 27001)

Annex A of ISO/IEC 27001:2022 is a normative catalogue of 93 information security controls grouped into four themes: organizational, people, physical, and technological. It provides the reference list organizations use to select and justify controls in the Statement of Applicability and is a mandatory component of every certification audit.

**Verwandt:** ISO/IEC 27001 · ISO/IEC 27002 · Statement of Applicability (SoA) · Risk treatment

**Quellen:** ISO/IEC 27001:2022 Annex A · [/en/leistungen/isms-iso27001](https://www.sidd.swiss/en/services/iso-27001-isms)

### Anonymization

Anonymization is the irreversible processing of personal data so that the data subject can no longer be identified, or only with disproportionate effort. Correctly anonymized data falls outside both the Swiss DSG and the GDPR. What matters is effectiveness against realistic re-identification attacks, not the mere removal of names.

**Verwandt:** Pseudonymization · FADP · GDPR · Technical and organizational measures (TOMs)

**Quellen:** Art. 4 No. 1 GDPR · Recital 26 GDPR

## B

### Binding Corporate Rules (BCRs)

Binding Corporate Rules are internal data protection rules approved by the competent EU supervisory authority that bind all entities of a corporate group. They enable lawful intra-group transfers of personal data to third countries as an alternative to Standard Contractual Clauses. The approval procedure is demanding but creates a durable transfer basis, particularly attractive for multinational groups with centralized IT and HR systems.

**Verwandt:** Standard Contractual Clauses (SCCs) · Group Data Protection Officer · GDPR · Controller

**Quellen:** Art. 47 GDPR

## C

### CIA Triad (Confidentiality · Integrity · Availability)

The CIA Triad denotes the three classical security objectives of information security: confidentiality, integrity, and availability. It forms the conceptual core of every ISMS and every risk analysis. From these three objectives, protection-needs classes, technical controls, and KPIs are derived, all of which are addressed systematically in ISO/IEC 27001.

**Verwandt:** Security objective (confidentiality / integrity / availability) · ISMS · ISO/IEC 27001 · Technical and organizational measures (TOMs)

### CIS Cert

CIS Cert (CIS, Certification & Information Security Services GmbH) is an accredited certification body of the Quality Austria Group, based in Vienna. It certifies management systems worldwide against ISO/IEC 27001 and related standards. SIDD regularly accompanies Swiss and EU clients through stage-1 and stage-2 audits with CIS Cert and handles the full audit preparation.

**Verwandt:** ISO/IEC 27001 · ISO/IEC 17021 · ISMS · Statement of Applicability (SoA)

**Quellen:** [/en/leistungen/isms-iso27001](https://www.sidd.swiss/en/services/iso-27001-isms)

### CISO (Chief Information Security Officer)

The Chief Information Security Officer is the executive-level owner of an organization's information security strategy, ISMS, and risk governance. The CISO typically reports directly to the CEO or board. SMEs frequently engage the function as external CISO-as-a-Service to cover regulatory requirements from NIS2, ISO 27001, or the Swiss ICT minimum standard economically.

**Verwandt:** ISB (Information Security Officer · German title) · ISMS · NIS2 · Swiss ICT minimum standard

**Quellen:** [/en/leistungen/ciso-isb-iso](https://www.sidd.swiss/en/services/vciso)

### Controller

The controller is the natural or legal person, public authority, or body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The role is named Verantwortlicher in the Swiss DSG and controller in the GDPR. The controller bears the accountability obligation, concludes DPAs with processors, and is the primary addressee of supervisory measures.

**Verwandt:** Data Processing Agreement (DPA) · GDPR · FADP · Records of Processing Activities (ROPA)

**Quellen:** Art. 4 No. 7 GDPR · Art. 5 lit. j DSG

### CVSS

The Common Vulnerability Scoring System is an open industry standard for rating the severity of technical vulnerabilities on a scale from 0.0 to 10.0. CVSS v3.1 and v4.0 account for attack vector, complexity, required privileges, and impact. SIDD applies CVSS in penetration test reports so clients can prioritize findings objectively and delegate them reproducibly to developers.

**Verwandt:** Penetration test · Vulnerability scan · OWASP Top 10 · Responsible Disclosure

**Quellen:** [/en/leistungen/penetrationstest](https://www.sidd.swiss/en/services/penetration-test) · [/en/leistungen/schwachstellenscan](https://www.sidd.swiss/en/services/vulnerability-scan)

## D

### Data Processing Agreement (DPA)

A Data Processing Agreement governs in writing how a processor handles personal data on behalf of the controller. It is mandatory under Art. 28 GDPR and Art. 9 DSG and defines the subject matter, duration, nature, and purpose of the processing as well as the technical and organizational measures. Without a valid DPA, the controller risks a breach of the processing-security principle.

**Verwandt:** Controller · GDPR · FADP · Technical and organizational measures (TOMs)

**Quellen:** Art. 28 GDPR · Art. 9 DSG

### Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment is a documented process for the prior evaluation of processing operations likely to result in a high risk to data subjects. It describes the processing, its necessity, the risks, and the safeguards. Under Art. 35 GDPR and Art. 22 DSG it is mandatory for systematic monitoring, sensitive data, or new technologies and is a precondition for lawful deployment.

**Verwandt:** Records of Processing Activities (ROPA) · GDPR · FADP · Controller

**Quellen:** Art. 35 GDPR · Art. 22 DSG

### Data Protection Officer (DPO)

The Data Protection Officer monitors compliance with data protection law within the organization, advises management, and serves as contact point for supervisory authorities and data subjects. Under Art. 37 GDPR the appointment is mandatory in defined cases; the Swiss DSG instead provides for the voluntary data protection advisor under Art. 10. SIDD provides the role as an external mandate solution for SMEs.

**Verwandt:** External Data Protection Advisor · Group Data Protection Officer · GDPR · FADP

**Quellen:** Art. 37–39 GDPR · Art. 10 DSG · [/en/leistungen/datenschutzbeauftragter-eu](https://www.sidd.swiss/en/services/data-protection-officer-eu)

### Data subject rights

Data subject rights are the enforceable claims of natural persons against controllers, including access, rectification, erasure, restriction, data portability, and objection. They are anchored in Art. 12–22 GDPR and Art. 25 et seq. DSG. Organizations must respond to requests within one month and maintain demonstrable processes to handle the rights efficiently and lawfully.

**Verwandt:** GDPR · FADP · Controller · Data Protection Officer (DPO)

**Quellen:** Art. 12–22 GDPR · Art. 25 et seq. DSG

### DSG (Swiss Federal Act on Data Protection, FADP)

The Swiss DSG, in English the Federal Act on Data Protection (FADP), governs the processing of personal data by private parties and federal bodies in Switzerland. The fully revised version entered into force on 1 September 2023 and introduced, among other things, breach notification duties, the records of processing activities, and criminal-law duties for natural persons. The DSG is GDPR-compatible but not identical. The maximum personal fine under Art. 60 DSG is CHF 250,000.

**Verwandt:** GDPR · FDPIC · Swiss Data Protection Ordinance (DSV) · Controller

**Quellen:** [/en/leistungen/datenschutzberater-schweiz](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland)

## E

### EU Representative (Art. 27 GDPR)

The EU Representative is the EU-based point of contact for a controller or processor established in a third country, such as Switzerland. The representative is appointed in writing, represents the organization vis-à-vis supervisory authorities and data subjects, and co-maintains the records of processing activities. The obligation regularly applies when goods, services, or behavioural monitoring are offered to EU persons on a regular basis.

**Verwandt:** GDPR · Controller · Records of Processing Activities (ROPA) · Standard Contractual Clauses (SCCs)

**Quellen:** Art. 27 GDPR · [/en/leistungen/eu-vertreter](https://www.sidd.swiss/en/services/eu-representative)

### External Data Protection Advisor

The External Data Protection Advisor is the voluntary role provided for in the Swiss DSG under Art. 10. The advisor counsels the controller independently, trains staff, and can be registered with the FDPIC, which removes the obligation to consult on DPIAs. SIDD offers the role as a mandate solution for Swiss SMEs and group companies, including documented availability. This is distinct from the EU DPO under Art. 37 GDPR.

**Verwandt:** Data Protection Officer (DPO) · Group Data Protection Officer · FADP · FDPIC

**Quellen:** Art. 10 DSG · [/en/leistungen/datenschutzberater-schweiz](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland)

## F

### FDPIC (Federal Data Protection and Information Commissioner)

The Federal Data Protection and Information Commissioner is Switzerland's independent supervisory authority for the DSG. The FDPIC advises federal bodies and private parties, investigates data protection violations, issues binding measures, and maintains the register of data protection advisors. Personal data breaches involving a high risk must be reported to the FDPIC. Its practice has shaped the interpretation of the revised DSG materially since September 2023.

**Verwandt:** FADP · Personal data breach · Controller · Data Protection Officer (DPO)

**Quellen:** Art. 43 et seq. DSG

## G

### GDPR (General Data Protection Regulation)

The General Data Protection Regulation is EU Regulation 2016/679 and has applied directly in all EU and EEA states since 25 May 2018. It governs the processing of personal data and has extraterritorial effect via the market-place principle. Swiss organizations offering goods or services to EU data subjects fall under it directly and frequently need an EU Representative under Art. 27. Maximum fines reach EUR 20m or 4% of global annual turnover under Art. 83.

**Verwandt:** FADP · EU Representative (Art. 27 GDPR) · Standard Contractual Clauses (SCCs) · Controller

**Quellen:** Regulation (EU) 2016/679 · [/en/leistungen/eu-vertreter](https://www.sidd.swiss/en/services/eu-representative)

### Group Data Protection Officer

The Group Data Protection Officer performs the DPO function group-wide for several affiliated companies. Under Art. 37(2) GDPR the prerequisite is easy accessibility from every establishment. The consolidation creates uniform standards, DPA templates, and training programmes and is in particular the organizational backbone for Binding Corporate Rules in multinational groups.

**Verwandt:** Data Protection Officer (DPO) · Binding Corporate Rules (BCRs) · External Data Protection Advisor · GDPR

**Quellen:** Art. 37(2) GDPR

## I

### ISB (Information Security Officer, German title)

The ISB (Informationssicherheitsbeauftragter) is operationally responsible for the establishment, operation, and continuous improvement of the ISMS and typically reports to the CISO or executive management. The role coordinates risk analyses, training, internal audits, and maintenance of the Statement of Applicability. In smaller organizations the role often merges with that of the CISO or is sourced externally. The German title is preserved because the role taxonomy is German-language.

**Verwandt:** CISO (Chief Information Security Officer) · ISMS · Statement of Applicability (SoA) · ISO/IEC 27001

**Quellen:** [/en/leistungen/ciso-isb-iso](https://www.sidd.swiss/en/services/vciso)

### ISMS

An Information Security Management System is a documented, risk-based management system for protecting an organization's information assets. It comprises policies, roles, processes, controls, and continuous improvement following the PDCA cycle. ISO/IEC 27001 defines the normative requirements, fulfilment of which is the precondition for certification, for example through CIS Cert.

**Verwandt:** ISO/IEC 27001 · Annex A (ISO 27001) · Statement of Applicability (SoA) · Risk treatment

**Quellen:** ISO/IEC 27001:2022 · [/en/leistungen/isms-iso27001](https://www.sidd.swiss/en/services/iso-27001-isms)

### ISO (Information Security Officer per eCH-0199)

The ISO (Informationssicherheitsoffizier) is the role defined in eCH-0199 of the Swiss e-government standards and is a Swiss public-sector role. The officer steers the information security of an administrative unit or project, coordinates protection-needs analyses, and ensures conformity with overarching requirements. The acronym collides with the ISO standards body; in the Swiss public-sector environment the role is nonetheless established and relevant in tenders.

**Verwandt:** ISB (Information Security Officer · German title) · CISO (Chief Information Security Officer) · ISMS · Swiss ICT minimum standard

**Quellen:** eCH-0199 · [/en/leistungen/ciso-isb-iso](https://www.sidd.swiss/en/services/vciso)

### ISO/IEC 17021

ISO/IEC 17021 sets out the requirements for bodies that audit and certify management systems. It defines independence, competence, the audit process, and reporting duties. Accredited certifiers such as CIS Cert must comply with the standard so that their certificates are internationally recognized. For clients it serves as a quality signal when selecting a certification body.

**Verwandt:** CIS Cert · ISO/IEC 27001 · ISMS · Annex A (ISO 27001)

**Quellen:** ISO/IEC 17021-1:2015

### ISO/IEC 27001

ISO/IEC 27001 is the international standard for Information Security Management Systems. The 2022 edition defines binding requirements in clauses 4–10 and references 93 controls in Annex A. A successful certification by accredited bodies such as CIS Cert demonstrably proves that an organization governs information security in a risk-based and systematic manner.

**Verwandt:** ISMS · Annex A (ISO 27001) · Statement of Applicability (SoA) · CIS Cert

**Quellen:** ISO/IEC 27001:2022 · [/en/leistungen/isms-iso27001](https://www.sidd.swiss/en/services/iso-27001-isms)

### ISO/IEC 27002

ISO/IEC 27002 is the guide to selecting, implementing, and governing the 93 information security controls from Annex A of ISO/IEC 27001. For each control it provides purpose, implementation guidance, and further information. The 2022 edition assigns the controls to four themes and introduces five attributes for categorization, such as cybersecurity concept and security objective.

**Verwandt:** ISO/IEC 27001 · Annex A (ISO 27001) · Statement of Applicability (SoA) · ISMS

**Quellen:** ISO/IEC 27002:2022

## N

### NIS2

The NIS2 Directive (EU 2022/2555) requires essential and important entities in 18 sectors to operate risk-based cybersecurity management, comply with notification duties, and assume management-level responsibility. It has had to be transposed into national law since 18 October 2024. Swiss organizations with EU establishments or as suppliers to critical infrastructures frequently fall under NIS2 indirectly and need a conformant ISMS.

**Verwandt:** ISMS · ISO/IEC 27001 · Swiss ICT minimum standard · CISO (Chief Information Security Officer)

**Quellen:** Directive (EU) 2022/2555

## O

### OWASP Top 10

The OWASP Top 10 is the internationally recognized list of the ten most prevalent and severe security risks for web applications. It is updated regularly by the Open Worldwide Application Security Project, most recently in 2021. SIDD tests every web application during penetration testing against the Top 10 categories such as Broken Access Control, Injection, and Cryptographic Failures and documents findings reproducibly.

**Verwandt:** Penetration test · Vulnerability scan · CVSS · Responsible Disclosure

**Quellen:** [/en/leistungen/penetrationstest](https://www.sidd.swiss/en/services/penetration-test)

## P

### Penetration test

A penetration test is a controlled, authorized simulation of real attacks against systems, applications, or networks, intended to surface exploitable vulnerabilities before real attackers do. SIDD works manually and with tooling support, classifies findings by CVSS, and delivers prioritized remediation recommendations. Penetration tests complement automated vulnerability scans and are a precondition for many ISO 27001 certifications and customer audits.

**Verwandt:** Vulnerability scan · CVSS · OWASP Top 10 · Responsible Disclosure

**Quellen:** [/en/leistungen/penetrationstest](https://www.sidd.swiss/en/services/penetration-test)

### Personal data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data. Under the GDPR it must be reported to the supervisory authority within 72 hours; under the Swiss DSG it must be reported to the FDPIC as soon as possible. Affected data subjects must additionally be informed where the risk is high.

**Verwandt:** FDPIC · GDPR · FADP · Technical and organizational measures (TOMs)

**Quellen:** Art. 33–34 GDPR · Art. 24 DSG

### Pseudonymization

Pseudonymization is the processing of personal data such that the data can no longer be attributed to a specific data subject without additional information, which is kept separately. Unlike anonymization, it is reversible; the data remains personal and stays subject to the DSG and GDPR. It is considered an effective technical safeguard and is explicitly named in Art. 32 GDPR.

**Verwandt:** Anonymization · Technical and organizational measures (TOMs) · GDPR · FADP

**Quellen:** Art. 4 No. 5 GDPR · Art. 32 GDPR

## R

### Records of Processing Activities (ROPA)

Records of Processing Activities systematically document every processing operation of an organization, including purposes, categories of data subjects and data, recipients, third-country transfers, retention periods, and technical and organizational measures. They are mandatory under Art. 30 GDPR and Art. 12 DSG and are the central evidence instrument of the accountability obligation. SMEs under 250 employees benefit from narrow exemptions, but only under conditions.

**Verwandt:** Controller · GDPR · FADP · Data Protection Impact Assessment (DPIA)

**Quellen:** Art. 30 GDPR · Art. 12 DSG

### Responsible Disclosure

Responsible Disclosure is the coordinated process by which security researchers report discovered vulnerabilities to the vendor confidentially and grant reasonable time to remediate before publication. A published vulnerability disclosure policy creates legal certainty for both sides and is a component of mature security programmes under ISO/IEC 27001 and NIS2.

**Verwandt:** Penetration test · Vulnerability scan · CVSS · OWASP Top 10

### Risk treatment

Risk treatment is the documented decision in the ISMS as to how an identified information security risk is governed: avoid, mitigate, transfer, or accept. It connects the risk analysis with concrete controls from Annex A and culminates in the risk treatment plan. Acceptance decisions must be approved by the risk owners and are a mandatory evidence item in the ISO/IEC 27001 audit.

**Verwandt:** ISMS · Annex A (ISO 27001) · Statement of Applicability (SoA) · ISO/IEC 27001

**Quellen:** ISO/IEC 27001:2022 clause 6.1.3

## S

### Security objective (confidentiality / integrity / availability)

Security objectives describe which property of an information asset is to be protected. The classical objectives are confidentiality, integrity, and availability, the CIA Triad. Modern frameworks add authenticity, non-repudiation, and accountability. In the ISMS, protection-needs classes are defined per asset for each security objective, and these subsequently steer the selection of controls from Annex A of ISO/IEC 27001.

**Verwandt:** CIA Triad (Confidentiality · Integrity · Availability) · ISMS · Annex A (ISO 27001) · Technical and organizational measures (TOMs)

### Standard Contractual Clauses (SCCs)

Standard Contractual Clauses are contract templates approved by the European Commission that serve as a safeguard for transfers of personal data to third countries lacking an adequacy decision. The 2021 modules cover the most relevant constellations. Controllers must additionally conduct a Transfer Impact Assessment and, where required, implement supplementary technical measures such as encryption or pseudonymization.

**Verwandt:** GDPR · FADP · Controller · Pseudonymization

**Quellen:** Implementing Decision (EU) 2021/914

### Statement of Applicability (SoA)

The Statement of Applicability is the central control document in the ISMS in which, for each of the 93 controls from Annex A of ISO/IEC 27001, the applicability, implementation status, and justification are documented. Exclusions must be substantively justified. The SoA is a mandatory evidence item in the stage-1 audit and therefore a precondition for every certification, for example through CIS Cert.

**Verwandt:** ISO/IEC 27001 · Annex A (ISO 27001) · ISMS · CIS Cert

**Quellen:** ISO/IEC 27001:2022 clause 6.1.3 d) · [/en/leistungen/isms-iso27001](https://www.sidd.swiss/en/services/iso-27001-isms)

### Swiss Data Protection Ordinance (DSV)

The Swiss Data Protection Ordinance (DSV) concretizes the DSG and entered into force together with the revised act on 1 September 2023. It governs detailed questions regarding data security, the records of processing activities, cross-border disclosure, data protection impact assessment, and the role of the data protection advisor. Controllers must adapt their processes, DPAs, and technical measures to the DSV requirements.

**Verwandt:** FADP · Records of Processing Activities (ROPA) · Technical and organizational measures (TOMs) · Data Protection Impact Assessment (DPIA)

**Quellen:** SR 235.11

### Swiss ICT minimum standard

The Swiss ICT minimum standard (BWL ICT-Minimalstandard) is a framework recommended by the Federal Office for National Economic Supply to strengthen ICT resilience of critical infrastructures in Switzerland. It is based on the NIST Cybersecurity Framework and defines 106 measures across five functions. It is not mandatory but serves as a reference for utilities, public authorities, and SMEs during audits.

**Verwandt:** ISMS · NIS2 · ISO/IEC 27001 · CIA Triad (Confidentiality · Integrity · Availability)

## T

### Technical and organizational measures (TOMs)

Technical and organizational measures are the safeguards required by Art. 32 GDPR and Art. 8 DSG to ensure processing security. They include access controls, encryption, pseudonymization, backup concepts, training, and incident-response processes. TOMs must be described in the Data Processing Agreement and must be proportionate to the protection need, the state of the art, and the cost of implementation.

**Verwandt:** Data Processing Agreement (DPA) · Pseudonymization · GDPR · FADP

**Quellen:** Art. 32 GDPR · Art. 8 DSG

### TISAX

TISAX (Trusted Information Security Assessment Exchange) is the assessment and exchange mechanism of the German automotive industry for information security at suppliers. It is based on the VDA ISA catalogue, which is closely aligned with ISO/IEC 27001. Audits are performed by approved providers; results are shared with awarding parties via the ENX platform and constitute de facto market access in the automotive sector.

**Verwandt:** ISO/IEC 27001 · ISMS · Annex A (ISO 27001) · Statement of Applicability (SoA)

## V

### Vulnerability scan

A vulnerability scan is the automated examination of systems and applications for known security vulnerabilities using signatures and CVE databases. It delivers broad coverage in a short time but without manual verification. SIDD deploys regular scans as a cost-effective complement to penetration tests and prioritizes findings by CVSS, reachability, and business criticality.

**Verwandt:** Penetration test · CVSS · OWASP Top 10 · Responsible Disclosure

**Quellen:** [/en/leistungen/schwachstellenscan](https://www.sidd.swiss/en/services/vulnerability-scan)

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
