# Glosario — Gobernanza y Compliance Digital

Términos que el curso usa y que el examen puede pedir.

| Término | Definición en una línea |
|---|---|
| **ISO 27001** | Certifiable information security management system (ISMS) standard. |
| **NIST CSF** | Framework: Identify, Protect, Detect, Respond, Recover. |
| **ENS** | Spanish National Security Scheme, by categories. |
| **Declaración de aplicabilidad** | Which controls apply and why (ISO 27001). |
| **Dato personal** | Any data about an identified or identifiable person. |
| **Minimización** | Process only what is necessary for the declared purpose. |
| **Finalidad** | The use declared when collecting; a different use requires a new basis. |
| **Base de licitud** | Legal justification for processing (consent, contract, law...). |
| **Token anónimo** | Identifier not traceable to a person: extreme minimization. |
| **Registro de tratamiento** | Inventory: what, why, how long, with what security. |
| **Riesgo** | Probability × impact on an asset; always with an owner. |
| **Matriz de riesgo** | Table asset × threat × treatment × owner × date. |
| **Dueño del riesgo** | Named person who decides and reviews (not 'the team'). |
| **Transferencia de riesgo** | Moving it to a third party, usually insurance. |
| **Expédiente de compliance** | Chain of claims → verifiable artifacts. |
| **Evidencia** | Artefact that proves that a control works (log, review, capture). |

> Regla de estudio: si no sabes explicarlo en una frase a alguien de fuera, aún no lo sabes.
