Glossary

11 entries

au-compliance frameworks acsc-glossary

ACSC

The Australian Cyber Security Centre, part of ASD. Alerts, advice, assistance. cyber.gov.au and 1300 CYBER1.

practitioner vulnerability frameworks hardening

CISA KEV

Known Exploited Vulnerabilities catalogue plus BOD 26-04 deadlines. If it is on KEV and you are internet-facing, treat exposure as an incident trigger, not a backlog item.

frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

practitioner au-compliance hardening frameworks

Essential Eight evidence

How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.

practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.

frameworks

ISO/IEC 27001

A management system standard. The certificate is proof you run the system, not that you are unbreachable.

practitioner frameworks au-compliance acsc-glossary

Information Security Manual (ISM)

ASD's control catalogue for Australian government systems — and the shared dialect for anyone who needs to speak the same language. Applicability, tailoring, and dated exceptions are the work.

detection frameworks

MITRE ATT&CK

A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.

frameworks

NIST Cybersecurity Framework

Identify, Protect, Detect, Respond, Recover — plus Govern in 2.0. A common language, not a certification.

practitioner au-compliance frameworks

Protective Security Policy Framework

AGD protective security policy for NCEs. Four domains, PSPF Release 2025 Policy 14 cyber floor, Essential Eight to Maturity Level 2 since July 2022.

practitioner au-compliance frameworks

SOCI Act obligations

Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary