Glossary
The terms, in plain English.
64 security, privacy and compliance terms used across the guides — defined without the jargon, tagged by jurisdiction, and linked to the official source where a term has one.
A
Acceptable use policy · AUP
AU + NZThe everyday guardrails for how staff may use company systems, accounts, devices and data — email, web, messaging, AI tools — and what happens when the rules are broken.
Access control · access management
AU + NZThe rules and mechanisms deciding who can reach which systems and information — granting, reviewing and revoking access so people hold only what their role needs.
ACSC · Australian Cyber Security Centre
AustraliaThe Australian Cyber Security Centre — part of the Australian Signals Directorate and the government's technical authority on cyber security, publisher of the Essential Eight and the ISM.
Annex A · Annex A controls
AU + NZThe control catalogue attached to ISO/IEC 27001:2022 — 93 reference controls across organisational, people, physical and technological themes that a certified organisation selects from and justifies in its Statement of Applicability.
APP 11 · APP 11 — security of personal information
AustraliaThe Australian Privacy Principle requiring organisations to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access — the APP most security policies exist to support.
ASD · Australian Signals Directorate
AustraliaThe Australian Signals Directorate — the Commonwealth agency responsible for cyber security and signals intelligence; the ACSC sits within it.
Audit evidence · evidence
AU + NZThe records that prove a policy actually operates — approval sign-offs, access reviews, training logs, patch reports. Auditors and insurers ask for the evidence, not just the document.
Australian Privacy Principles · APPs, APP
AustraliaThe thirteen principles in the Privacy Act 1988 that govern how organisations covered by the Act must collect, use, disclose, secure and give access to personal information.
Automated decision-making transparency · ADM, ADM transparency
AustraliaA Privacy Act reform commencing 10 December 2026: privacy policies must disclose when personal information is used in automated decisions that significantly affect individuals.
B
Biometric Processing Privacy Code · Biometric Code
New ZealandA code of practice issued under the Privacy Act 2020 regulating collection and use of biometric information (such as facial recognition). In force 3 November 2025, with pre-existing processing transitioning until 3 August 2026.
BYOD · bring your own device
AU + NZBring Your Own Device — staff using personal phones or laptops for work. A policy question about what company data may live on personal devices, and under what controls.
C
CERT NZ
New ZealandNew Zealand's former computer emergency response team. Its functions were folded into the National Cyber Security Centre, with integration completed in July 2025 — incident reporting now runs through the NCSC.
Children's Online Privacy Code · Children's Code
AustraliaA code the OAIC must finalise and register by 10 December 2026 setting how the Australian Privacy Principles apply to online services likely to be accessed by children.
CIRMP · Critical Infrastructure Risk Management Program
AustraliaThe Critical Infrastructure Risk Management Program — the written program the SOCI Act requires responsible entities for critical infrastructure assets to adopt and maintain, covering cyber, physical, personnel and supply-chain hazards.
CISC · Cyber and Infrastructure Security Centre
AustraliaThe Cyber and Infrastructure Security Centre in Home Affairs — the regulator administering the SOCI Act's obligations for critical infrastructure.
Cyber Incident Review Board · CIRB
AustraliaA no-fault board created by the Cyber Security Act 2024 (appointed 1 May 2026) that reviews significant cyber incidents and publishes lessons without attributing blame.
Cyber Security Act 2024 · CSA 2024
AustraliaAustralia's first standalone cyber security Act (assented 29 November 2024): ransomware payment reporting, smart-device security standards, limited-use protections for information shared with government, and the Cyber Incident Review Board.
D
Data breach · breach
AU + NZUnauthorised access to, disclosure of, or loss of personal or business information. Whether it must be reported depends on the jurisdiction's test — see eligible data breach (AU) and notifiable privacy breach (NZ).
Data classification · information classification
AU + NZLabelling information by sensitivity — commonly public, internal and confidential — so protection is proportionate and staff know how to handle each level.
DPMC · Department of the Prime Minister and Cabinet
New ZealandNew Zealand's Department of the Prime Minister and Cabinet — leads national cyber security policy, including the Cyber Security Strategy 2026–2030 and the critical-infrastructure reform consultation.
E
Eligible data breach
AustraliaThe Privacy Act 1988 trigger for mandatory notification: unauthorised access, disclosure or loss of personal information that a reasonable person would conclude is likely to result in serious harm, where remedial action can't remove that likelihood.
Encryption · encryption at rest, encryption in transit
AU + NZScrambling data so only holders of the key can read it — applied to stored data (at rest) and data moving across networks (in transit).
Essential Eight · E8
AustraliaThe ACSC's eight prioritised mitigation strategies — patching applications and operating systems, MFA, restricting admin privileges, application control, restricting Office macros, user application hardening, and regular backups.
Essential Eight Maturity Model · maturity level, ML1
AustraliaThe ACSC's implementation ladder for the Essential Eight — Maturity Levels One to Three, each defining how thoroughly the eight strategies must be implemented against increasingly capable attackers. Last revised November 2023.
G
GCSB · Government Communications Security Bureau
New ZealandNew Zealand's Government Communications Security Bureau — the signals-intelligence and information-assurance agency; the NCSC sits within it and it publishes the NZISM.
I
Incident response plan · IRP, incident response
AU + NZThe pre-agreed playbook for a security incident: roles, escalation, containment, assessment, notification and post-incident review — so a bad hour doesn't become a bad month.
Information Privacy Principles · IPPs, IPP
New ZealandThe thirteen principles at the heart of the Privacy Act 2020 governing collection, storage, use, disclosure and access to personal information in New Zealand.
IPP 3A
New ZealandA new Information Privacy Principle in force 1 May 2026: when an agency collects personal information indirectly (from someone other than the person), it must take reasonable steps to notify the person.
IPP 5 · IPP 5 — storage and security
New ZealandThe Information Privacy Principle requiring agencies to protect personal information with reasonable security safeguards against loss, misuse and unauthorised access — the NZ anchor for most security-policy obligations.
ISM · Information Security Manual
AustraliaThe ACSC's Information Security Manual — the detailed control catalogue Australian government (and increasingly business) systems are assessed against; the Essential Eight maps into it.
ISMS · information security management system
AU + NZAn Information Security Management System — the managed set of policies, processes, roles and controls an organisation runs to protect information; the thing ISO/IEC 27001 certifies.
ISO/IEC 27001 · ISO 27001
AU + NZThe international standard for information security management systems. The current edition is ISO/IEC 27001:2022 (adopted in Australia and New Zealand as AS/NZS ISO/IEC 27001:2023); organisations certify against it via accredited auditors.
J
Joiner–mover–leaver · JML, joiner mover leaver
AU + NZThe lifecycle for account access: grant on joining, adjust on role change, revoke promptly on exit. Stale leaver accounts are one of the most common audit findings.
L
Least privilege
AU + NZGranting each person and system the minimum access needed to do the job, and no more — the core principle behind access-control policy.
Limited use obligation · limited use
AustraliaProtections in the Cyber Security Act 2024 restricting how information a business voluntarily shares with government about an incident can be used against it — designed to encourage early engagement.
M
Multi-factor authentication · MFA, two-factor
AU + NZRequiring two or more different proofs of identity (something you know, have or are) to sign in. Phishing-resistant forms (like security keys or passkeys) are increasingly the expected standard for remote and privileged access.
N
NCSC (New Zealand) · NCSC, National Cyber Security Centre
New ZealandNew Zealand's National Cyber Security Centre, part of the GCSB — the lead operational cyber agency, publisher of the NZISM, the Cyber Security Framework and the Minimum Cyber Security Standards, and the single door for incident reporting since CERT NZ was folded in.
Notifiable Data Breaches scheme · NDB, NDB scheme
AustraliaThe Privacy Act 1988 scheme (since 22 February 2018) requiring covered organisations to notify the OAIC and affected individuals of eligible data breaches, after an assessment of up to 30 days.
Notifiable privacy breach
New ZealandThe Privacy Act 2020 trigger: a privacy breach that has caused, or is likely to cause, serious harm to someone. It must be notified to the OPC and affected individuals as soon as practicable.
NotifyUs
New ZealandThe Office of the Privacy Commissioner's online tool for notifying serious privacy breaches, as the Privacy Act 2020 requires.
NZISM · New Zealand Information Security Manual
New ZealandThe New Zealand Information Security Manual — the GCSB/NCSC's detailed security control baseline for government systems, widely used by business as a reference. Current version 3.9 (April 2025).
O
OAIC · Office of the Australian Information Commissioner
AustraliaThe Office of the Australian Information Commissioner — Australia's privacy regulator: administers the Privacy Act 1988 and the NDB scheme, and enforces the APPs.
Offboarding · leaver process
AU + NZThe exit half of joiner–mover–leaver: promptly revoking accounts and access, recovering devices and keys, and confirming nothing sensitive leaves with the person.
OPC · Office of the Privacy Commissioner, Privacy Commissioner
New ZealandNew Zealand's Office of the Privacy Commissioner — the privacy regulator: administers the Privacy Act 2020, the IPPs, codes of practice like the Biometric Code, and breach notification via NotifyUs.
Own Your Online
New ZealandThe NCSC's public-facing cyber security guidance service for New Zealand businesses and individuals — practical, plain-English advice and tools.
P
Passphrase
AU + NZA long password built from multiple words. Length beats complexity: modern guidance prefers long, unique passphrases over short passwords with forced symbols and routine expiry.
Password manager
AU + NZSoftware that generates, stores and fills strong unique credentials so people don't reuse passwords. Business-grade managers add shared vaults and offboarding controls.
Patch management · patching
AU + NZApplying security updates to applications and operating systems within defined timeframes — with the tightest clocks (as short as 48 hours) for actively exploited critical vulnerabilities.
Phishing
AU + NZFraudulent messages that impersonate someone trusted to steal credentials, deliver malware or trigger payments. The entry point for most real-world incidents, and the reason phishing-resistant MFA matters.
Privacy Act 1988
AustraliaAustralia's federal privacy law: the APPs, the NDB scheme, and the OAIC's enforcement powers. Substantially amended by the Privacy and Other Legislation Amendment Act 2024, with further tranches under discussion.
Privacy Act 2020
New ZealandNew Zealand's privacy law (in force 1 December 2020): the thirteen IPPs, mandatory notifiable privacy breach reporting, and the OPC's compliance powers. Amended in 2025 to add IPP 3A.
Privileged access · admin access, privileged account
AU + NZAccounts with elevated rights — administrators, domain and cloud-console access, service accounts. The keys to the kingdom: separated from daily-driver accounts, MFA-protected, logged and reviewed.
PSR · Protective Security Requirements
New ZealandNew Zealand's Protective Security Requirements — the government's policy framework covering security governance, personnel, physical and information security, referenced alongside the NZISM.
R
Ransomware · cyber extortion
AU + NZMalware that encrypts or steals data and demands payment. Defences lean on backups, patching, MFA and application control; in Australia, payments above the threshold must now be reported.
Ransomware payment reporting
AustraliaThe Cyber Security Act 2024 obligation (active 30 May 2025): businesses over the A$3 million turnover threshold that make or become aware of a ransomware payment must report it within 72 hours.
S
Security awareness training · awareness training
AU + NZRegular, role-relevant training on phishing, passwords, data handling and reporting — with records kept, because training logs are standard audit evidence.
Serious harm (AU) · serious harm test, serious harm
AustraliaThe NDB scheme's threshold: whether a reasonable person would conclude the breach is likely to result in serious harm — physical, psychological, emotional, financial or reputational — to affected individuals.
Serious harm (NZ) · section 113, serious harm
New ZealandThe Privacy Act 2020 threshold for notifiable privacy breaches, assessed using the section 113 factors — including the sensitivity of the information, who obtained it, and any protections in place.
Service account · API credential, machine account
AU + NZA non-human account used by systems and integrations. Because no person owns the login day-to-day, these need an assigned owner, long unique credentials, least privilege and rotation on staff exit.
SMB1001
AustraliaA multi-tier cyber security standard for small and medium businesses published by Dynamic Standards International, with annual editions (current edition SMB1001:2026) and certification through accredited providers.
SOCI Act · Security of Critical Infrastructure Act 2018, SOCI
AustraliaThe Security of Critical Infrastructure Act 2018 — obligations for critical infrastructure assets: asset registration, incident reporting, the CIRMP risk-management program, and government assistance powers. Significantly amended in 2024.
Statutory tort for serious invasions of privacy · privacy tort, statutory tort
AustraliaA cause of action commencing 10 June 2025 letting individuals sue for serious invasions of privacy — intrusion upon seclusion or misuse of information — where they had a reasonable expectation of privacy.
V
VERIFIED / INFERRED · verified, inferred
AU + NZThis site's own evidence labels. VERIFIED: the claim is directly supported by the official source cited, in its own words. INFERRED: a reasonable reading of sourced material where the source doesn't state it in exactly those terms. Every claim carries one, so you can weigh it.
W
Workplace surveillance laws · surveillance notice
AustraliaState laws (notably NSW and the ACT) requiring written notice — and in some cases a policy — before monitoring employees' computer use. The legal footing an acceptable use policy's monitoring clause has to respect.