KPI
key performance indicator; significant in showing the performance of an ISMS compared to its stated goals
KRIs
key risk indicators; measure the risk inherent in performing a given action or set of actions
drive-by download
automatic attack triggered simply by visiting a malicious website
management review
formal meeting where senior organizational leaders determine whether the information security management systems are effectively accomplishing their goals
vulnerability remediation after an organizational security assessment
requires the support of everyone from the top of the organization; organizational (as opposed to system-specific) assessments will not just involve a software patch