Skip to Content

Glossary of crisis management

SMSI, PCA, PRA, RTO, RPO, crisis unit, POI... crisis management has its own vocabulary, often technical or regulatory. This glossary brings together clear definitions of the most useful concepts, with a link to our dedicated pages to go further.

Anticipating a crisis (cyberattack, disaster, industrial accident) means mastering precise vocabulary: each acronym refers to a mechanism, a regulatory obligation, or a practical method. This glossary is not exhaustive, but covers the concepts most frequently encountered in a project involving cyber crisis management, business continuity or internal emergency plan.

SMSIInformation Security Management System

A governance, process, and control framework (ISO/IEC 27001 standard) through which an organization continuously manages its security risks. Learn more →

PCABusiness Continuity Plan

A mechanism that enables an organization to maintain its essential activities during a crisis (cyberattack, disaster, major outage). Learn more →

PRADisaster Recovery Plan

The technical component of the PCA: procedures and resources for restoring information systems after a disaster, within defined timeframes. Learn more →

RTORecovery Time Objective

The maximum acceptable time to restore a system or activity to service after an incident. Learn more →

RPORecovery Point Objective

The amount of data an organization can afford to lose, expressed as the time between two backups. Learn more →

Crisis unitCrisis unit

A multidisciplinary decision-making group (executive management, technical, legal, communications) mobilized to steer the response to a major incident. Learn more →

POIInternal Emergency Plan

A regulatory mechanism (SEVESO/ICPE sites) that organizes resources and response procedures in the event of an on-site accident. Learn more →

Incident responseIncident response

A structured set of actions (detection, qualification, containment, eradication, remediation) triggered as soon as a security incident is identified. Learn more →

EBIOS Risk ManagerEBIOS Risk Manager

ANSSI's risk analysis method, which identifies the most critical risk scenarios in order to prioritize security measures. Learn more →

Organizational resilienceOrganizational resilience

An organization's ability to anticipate, absorb, and recover from a major disruption without compromising its mission. Learn more →

RSSIInformation Systems Security Manager

The leader of the information security strategy, often on the front line during crisis management. Learn more →

RETEXPost-Incident Review

A post-event analysis of a crisis or exercise, used to draw lessons and improve the mechanisms already in place.

These concepts remain abstract until they are put into practice

We help our clients turn this vocabulary into concrete mechanisms: SMSI operational, PCA/PRA tested, with a trained crisis unit. Let's discuss your context.

Is a concept unclear, or would you like to implement it?

Let's take 15 minutes to discuss it. We will explain what concretely applies to your organization, without unnecessary jargon.