Glossary

23 entries

practitioner au-compliance privacy hardening

APP 11 — security of personal information

Privacy Act APP 11. Reasonable steps to protect personal information you hold, and to destroy or de-identify it when it is no longer needed. Technical and organisational measures. OAIC APP Guidelines Chapter 11.

practitioner hardening supply-chain

Browser extension supply chain

Chrome and Edge auto-update means a bought extension can turn hostile overnight. Inventory, least privilege, and remove what you do not need.

practitioner au-compliance soci

CIRMP (Critical Infrastructure Risk Management Program)

Part 2A of the SOCI Act. If you are a responsible entity for a covered critical infrastructure asset, you must have a written risk management program, keep it current, and report on it each year.

practitioner au-compliance IR supply-chain

CIRMP annual report

The board-approved annual attestation for a Critical Infrastructure Risk Management Program. Due within 90 days after the Australian financial year ends.

practitioner vulnerability frameworks hardening

CISA KEV

Known Exploited Vulnerabilities catalogue plus BOD 26-04 deadlines. If it is on KEV and you are internet-facing, treat exposure as an incident trigger, not a backlog item.

concepts vulnerability practitioner

CVE vs CVSS

CVE names a flaw. CVSS scores a severity model. EPSS estimates exploit likelihood. KEV records known exploitation. Your triage joins all four to exposure and asset value.

practitioner au-compliance hardening IR

Critical advisory intake

Getting a vendor critical into change control the same day — including record Patch Tuesday bundles. Owner, source list, exploited-first triage, evidence. ASD patching meets the NDB clock.

practitioner au-compliance IR

Data breach response plan

OAIC Part 2. Write the plan before the incident. Roles, containment, assessment, notify, and records — so the NDB clock is not where you invent process.

practitioner identity IR phishing

Device-code phishing

Victim completes a real Microsoft (or other IdP) device-code login for an attacker-controlled client. No fake password form required. Pair with AiTM and helpdesk-impersonation playbooks.

practitioner au-compliance hardening frameworks

Essential Eight evidence

How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.

practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.

practitioner frameworks au-compliance acsc-glossary

Information Security Manual (ISM)

ASD's control catalogue for Australian government systems — and the shared dialect for anyone who needs to speak the same language. Applicability, tailoring, and dated exceptions are the work.

practitioner au-compliance IR

NDB clock

Thirty days to assess a suspicion; notify as soon as practicable once eligible. As of 17 Sep 2026 the AGD Exposure Draft consultation still closes 18 Sep 2026 — proposed 72-hour OAIC notify clock is not law yet.

practitioner au-compliance IR privacy

NDB serious harm test

The Privacy Act gate for an eligible data breach. Reasonable person, more probable than not, s 26WG factors, then remedial action.

practitioner au-compliance IR privacy

NDB statement contents

What the Privacy Act requires in an eligible-data-breach statement to the OAIC and to individuals. Identity, description, kind of information, recommendations.

practitioner au-compliance IR

Privacy Act and OAIC

Privacy Act 1988, APPs, and the OAIC. Who is an APP entity, how NDB sits beside IR, and which desk pages hold the clocks and the serious-harm test.

practitioner au-compliance frameworks

Protective Security Policy Framework

AGD protective security policy for NCEs. Four domains, PSPF Release 2025 Policy 14 cyber floor, Essential Eight to Maturity Level 2 since July 2022.

practitioner au-compliance IR

Ransomware payment reporting

Cyber Security Act 2024 Part 3. If you pay, or someone pays for you, the clock is 72 hours. ASD takes the form; Home Affairs watches compliance.

practitioner hardening supply-chain

SBOM and build-pipeline checklist

Software bill of materials plus the CI controls that make it useful. Inventory what you ship, who can publish, and how fast you can patch a dependency.

practitioner au-compliance frameworks

SOCI Act obligations

Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.

practitioner au-compliance IR

SOCI cyber incident clock

Part 2B of the SOCI Act. Significant impact on availability: 12 hours. Other cyber incidents with a relevant impact: 72 hours. The clock starts when the responsible entity becomes aware, not when root cause is finished.

practitioner au-compliance soci

Systems of National Significance (SoNS)

A privately declared subset of critical infrastructure assets. SoNS can attract Enhanced Cyber Security Obligations on top of the ordinary SOCI duties.

practitioner au-compliance hardening

Third-party and supply chain

You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, ISM procurement — and the vendor update channel that pushes your next plugin build.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary