Glossary

22 entries

au-compliance frameworks acsc-glossary

ACSC

The Australian Cyber Security Centre, part of ASD. Alerts, advice, assistance. cyber.gov.au and 1300 CYBER1.

practitioner au-compliance privacy hardening

APP 11 — security of personal information

Privacy Act APP 11. Reasonable steps to protect personal information you hold, and to destroy or de-identify it when it is no longer needed. Technical and organisational measures. OAIC APP Guidelines Chapter 11.

au-compliance acsc-glossary

ASD

Australian Signals Directorate. Foreign signals intelligence and, through the ACSC, national cyber security.

practitioner au-compliance soci

CIRMP (Critical Infrastructure Risk Management Program)

Part 2A of the SOCI Act. If you are a responsible entity for a covered critical infrastructure asset, you must have a written risk management program, keep it current, and report on it each year.

practitioner au-compliance IR supply-chain

CIRMP annual report

The board-approved annual attestation for a Critical Infrastructure Risk Management Program. Due within 90 days after the Australian financial year ends.

practitioner au-compliance hardening IR

Critical advisory intake

Getting a vendor critical into change control the same day — including record Patch Tuesday bundles. Owner, source list, exploited-first triage, evidence. ASD patching meets the NDB clock.

IR au-compliance acsc-glossary

Data breach

Data lost, peeked, changed, or leaked without authorisation. In Australia the NDB clock may also be running.

practitioner au-compliance IR

Data breach response plan

OAIC Part 2. Write the plan before the incident. Roles, containment, assessment, notify, and records — so the NDB clock is not where you invent process.

frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

practitioner au-compliance hardening frameworks

Essential Eight evidence

How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.

practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.

practitioner frameworks au-compliance acsc-glossary

Information Security Manual (ISM)

ASD's control catalogue for Australian government systems — and the shared dialect for anyone who needs to speak the same language. Applicability, tailoring, and dated exceptions are the work.

practitioner au-compliance IR

NDB clock

Thirty days to assess a suspicion; notify as soon as practicable once eligible. As of 17 Sep 2026 the AGD Exposure Draft consultation still closes 18 Sep 2026 — proposed 72-hour OAIC notify clock is not law yet.

practitioner au-compliance IR privacy

NDB serious harm test

The Privacy Act gate for an eligible data breach. Reasonable person, more probable than not, s 26WG factors, then remedial action.

practitioner au-compliance IR privacy

NDB statement contents

What the Privacy Act requires in an eligible-data-breach statement to the OAIC and to individuals. Identity, description, kind of information, recommendations.

practitioner au-compliance IR

Privacy Act and OAIC

Privacy Act 1988, APPs, and the OAIC. Who is an APP entity, how NDB sits beside IR, and which desk pages hold the clocks and the serious-harm test.

practitioner au-compliance frameworks

Protective Security Policy Framework

AGD protective security policy for NCEs. Four domains, PSPF Release 2025 Policy 14 cyber floor, Essential Eight to Maturity Level 2 since July 2022.

practitioner au-compliance IR

Ransomware payment reporting

Cyber Security Act 2024 Part 3. If you pay, or someone pays for you, the clock is 72 hours. ASD takes the form; Home Affairs watches compliance.

practitioner au-compliance frameworks

SOCI Act obligations

Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.

practitioner au-compliance IR

SOCI cyber incident clock

Part 2B of the SOCI Act. Significant impact on availability: 12 hours. Other cyber incidents with a relevant impact: 72 hours. The clock starts when the responsible entity becomes aware, not when root cause is finished.

practitioner au-compliance soci

Systems of National Significance (SoNS)

A privately declared subset of critical infrastructure assets. SoNS can attract Enhanced Cyber Security Obligations on top of the ordinary SOCI duties.

practitioner au-compliance hardening

Third-party and supply chain

You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, ISM procurement — and the vendor update channel that pushes your next plugin build.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary