GRC and ISMS concepts# GRC and ISMS concepts This page explains the vocabulary used in RiskPilot. **GRC** brings together governance, risk management and compliance. **ISMS** is the management system that organizes responsibilities, processes, evidence and improvements related to information security. ## From assets to risk A **perimeter** delimits what is studied. An **asset** is an element that provides value and must be protected: information, service, application, material or process. A **threat** is an event likely to cause harm. A **vulnerability** is a weakness that this threat can exploit. A **security measure** reduces plausibility, impact, or both. RiskPilot assembles these elements into a scenario: ```text Périmètre → Actif → Menace → Vulnérabilité → Mesures → Évaluation → Traitement ``` ## Assess a risk Likelihood and impact are rated from 1 to 5. Their product gives a score from 1 to 25. | Evaluation | Question answered | | --- | --- | | Brute | What would the risk be without taking t