SecurityPolicy.com.au
Home/Glossary

Glossary

The terms, in plain English.

64 security, privacy and compliance terms used across the guides — defined without the jargon, tagged by jurisdiction, and linked to the official source where a term has one.

64 shown

A

Acceptable use policy · AUP

AU + NZ

The everyday guardrails for how staff may use company systems, accounts, devices and data — email, web, messaging, AI tools — and what happens when the rules are broken.

Access control · access management

AU + NZ

The rules and mechanisms deciding who can reach which systems and information — granting, reviewing and revoking access so people hold only what their role needs.

ACSC · Australian Cyber Security Centre

Australia

The Australian Cyber Security Centre — part of the Australian Signals Directorate and the government's technical authority on cyber security, publisher of the Essential Eight and the ISM.

Annex A · Annex A controls

AU + NZ

The control catalogue attached to ISO/IEC 27001:2022 — 93 reference controls across organisational, people, physical and technological themes that a certified organisation selects from and justifies in its Statement of Applicability.

APP 11 · APP 11 — security of personal information

Australia

The Australian Privacy Principle requiring organisations to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access — the APP most security policies exist to support.

ASD · Australian Signals Directorate

Australia

The Australian Signals Directorate — the Commonwealth agency responsible for cyber security and signals intelligence; the ACSC sits within it.

Australian Privacy Principles · APPs, APP

Australia

The thirteen principles in the Privacy Act 1988 that govern how organisations covered by the Act must collect, use, disclose, secure and give access to personal information.

Automated decision-making transparency · ADM, ADM transparency

Australia

A Privacy Act reform commencing 10 December 2026: privacy policies must disclose when personal information is used in automated decisions that significantly affect individuals.

B

Biometric Processing Privacy Code · Biometric Code

New Zealand

A code of practice issued under the Privacy Act 2020 regulating collection and use of biometric information (such as facial recognition). In force 3 November 2025, with pre-existing processing transitioning until 3 August 2026.

C

CERT NZ

New Zealand

New Zealand's former computer emergency response team. Its functions were folded into the National Cyber Security Centre, with integration completed in July 2025 — incident reporting now runs through the NCSC.

Children's Online Privacy Code · Children's Code

Australia

A code the OAIC must finalise and register by 10 December 2026 setting how the Australian Privacy Principles apply to online services likely to be accessed by children.

CIRMP · Critical Infrastructure Risk Management Program

Australia

The Critical Infrastructure Risk Management Program — the written program the SOCI Act requires responsible entities for critical infrastructure assets to adopt and maintain, covering cyber, physical, personnel and supply-chain hazards.

CISC · Cyber and Infrastructure Security Centre

Australia

The Cyber and Infrastructure Security Centre in Home Affairs — the regulator administering the SOCI Act's obligations for critical infrastructure.

Cyber Incident Review Board · CIRB

Australia

A no-fault board created by the Cyber Security Act 2024 (appointed 1 May 2026) that reviews significant cyber incidents and publishes lessons without attributing blame.

Cyber Security Act 2024 · CSA 2024

Australia

Australia's first standalone cyber security Act (assented 29 November 2024): ransomware payment reporting, smart-device security standards, limited-use protections for information shared with government, and the Cyber Incident Review Board.

D

Data breach · breach

AU + NZ

Unauthorised access to, disclosure of, or loss of personal or business information. Whether it must be reported depends on the jurisdiction's test — see eligible data breach (AU) and notifiable privacy breach (NZ).

Data classification · information classification

AU + NZ

Labelling information by sensitivity — commonly public, internal and confidential — so protection is proportionate and staff know how to handle each level.

DPMC · Department of the Prime Minister and Cabinet

New Zealand

New Zealand's Department of the Prime Minister and Cabinet — leads national cyber security policy, including the Cyber Security Strategy 2026–2030 and the critical-infrastructure reform consultation.

E

Eligible data breach

Australia

The Privacy Act 1988 trigger for mandatory notification: unauthorised access, disclosure or loss of personal information that a reasonable person would conclude is likely to result in serious harm, where remedial action can't remove that likelihood.

Encryption · encryption at rest, encryption in transit

AU + NZ

Scrambling data so only holders of the key can read it — applied to stored data (at rest) and data moving across networks (in transit).

Essential Eight · E8

Australia

The ACSC's eight prioritised mitigation strategies — patching applications and operating systems, MFA, restricting admin privileges, application control, restricting Office macros, user application hardening, and regular backups.

Essential Eight Maturity Model · maturity level, ML1

Australia

The ACSC's implementation ladder for the Essential Eight — Maturity Levels One to Three, each defining how thoroughly the eight strategies must be implemented against increasingly capable attackers. Last revised November 2023.

G

GCSB · Government Communications Security Bureau

New Zealand

New Zealand's Government Communications Security Bureau — the signals-intelligence and information-assurance agency; the NCSC sits within it and it publishes the NZISM.

I

Incident response plan · IRP, incident response

AU + NZ

The pre-agreed playbook for a security incident: roles, escalation, containment, assessment, notification and post-incident review — so a bad hour doesn't become a bad month.

Information Privacy Principles · IPPs, IPP

New Zealand

The thirteen principles at the heart of the Privacy Act 2020 governing collection, storage, use, disclosure and access to personal information in New Zealand.

IPP 3A

New Zealand

A new Information Privacy Principle in force 1 May 2026: when an agency collects personal information indirectly (from someone other than the person), it must take reasonable steps to notify the person.

IPP 5 · IPP 5 — storage and security

New Zealand

The Information Privacy Principle requiring agencies to protect personal information with reasonable security safeguards against loss, misuse and unauthorised access — the NZ anchor for most security-policy obligations.

ISM · Information Security Manual

Australia

The ACSC's Information Security Manual — the detailed control catalogue Australian government (and increasingly business) systems are assessed against; the Essential Eight maps into it.

ISMS · information security management system

AU + NZ

An Information Security Management System — the managed set of policies, processes, roles and controls an organisation runs to protect information; the thing ISO/IEC 27001 certifies.

ISO/IEC 27001 · ISO 27001

AU + NZ

The international standard for information security management systems. The current edition is ISO/IEC 27001:2022 (adopted in Australia and New Zealand as AS/NZS ISO/IEC 27001:2023); organisations certify against it via accredited auditors.

J

Joiner–mover–leaver · JML, joiner mover leaver

AU + NZ

The lifecycle for account access: grant on joining, adjust on role change, revoke promptly on exit. Stale leaver accounts are one of the most common audit findings.

L

Limited use obligation · limited use

Australia

Protections in the Cyber Security Act 2024 restricting how information a business voluntarily shares with government about an incident can be used against it — designed to encourage early engagement.

M

Multi-factor authentication · MFA, two-factor

AU + NZ

Requiring two or more different proofs of identity (something you know, have or are) to sign in. Phishing-resistant forms (like security keys or passkeys) are increasingly the expected standard for remote and privileged access.

N

NCSC (New Zealand) · NCSC, National Cyber Security Centre

New Zealand

New Zealand's National Cyber Security Centre, part of the GCSB — the lead operational cyber agency, publisher of the NZISM, the Cyber Security Framework and the Minimum Cyber Security Standards, and the single door for incident reporting since CERT NZ was folded in.

Notifiable Data Breaches scheme · NDB, NDB scheme

Australia

The Privacy Act 1988 scheme (since 22 February 2018) requiring covered organisations to notify the OAIC and affected individuals of eligible data breaches, after an assessment of up to 30 days.

NZISM · New Zealand Information Security Manual

New Zealand

The New Zealand Information Security Manual — the GCSB/NCSC's detailed security control baseline for government systems, widely used by business as a reference. Current version 3.9 (April 2025).

O

OAIC · Office of the Australian Information Commissioner

Australia

The Office of the Australian Information Commissioner — Australia's privacy regulator: administers the Privacy Act 1988 and the NDB scheme, and enforces the APPs.

OPC · Office of the Privacy Commissioner, Privacy Commissioner

New Zealand

New Zealand's Office of the Privacy Commissioner — the privacy regulator: administers the Privacy Act 2020, the IPPs, codes of practice like the Biometric Code, and breach notification via NotifyUs.

P

Passphrase

AU + NZ

A long password built from multiple words. Length beats complexity: modern guidance prefers long, unique passphrases over short passwords with forced symbols and routine expiry.

Patch management · patching

AU + NZ

Applying security updates to applications and operating systems within defined timeframes — with the tightest clocks (as short as 48 hours) for actively exploited critical vulnerabilities.

Privacy Act 1988

Australia

Australia's federal privacy law: the APPs, the NDB scheme, and the OAIC's enforcement powers. Substantially amended by the Privacy and Other Legislation Amendment Act 2024, with further tranches under discussion.

Privacy Act 2020

New Zealand

New Zealand's privacy law (in force 1 December 2020): the thirteen IPPs, mandatory notifiable privacy breach reporting, and the OPC's compliance powers. Amended in 2025 to add IPP 3A.

Privileged access · admin access, privileged account

AU + NZ

Accounts with elevated rights — administrators, domain and cloud-console access, service accounts. The keys to the kingdom: separated from daily-driver accounts, MFA-protected, logged and reviewed.

PSR · Protective Security Requirements

New Zealand

New Zealand's Protective Security Requirements — the government's policy framework covering security governance, personnel, physical and information security, referenced alongside the NZISM.

R

Ransomware · cyber extortion

AU + NZ

Malware that encrypts or steals data and demands payment. Defences lean on backups, patching, MFA and application control; in Australia, payments above the threshold must now be reported.

Ransomware payment reporting

Australia

The Cyber Security Act 2024 obligation (active 30 May 2025): businesses over the A$3 million turnover threshold that make or become aware of a ransomware payment must report it within 72 hours.

S

Security awareness training · awareness training

AU + NZ

Regular, role-relevant training on phishing, passwords, data handling and reporting — with records kept, because training logs are standard audit evidence.

Serious harm (AU) · serious harm test, serious harm

Australia

The NDB scheme's threshold: whether a reasonable person would conclude the breach is likely to result in serious harm — physical, psychological, emotional, financial or reputational — to affected individuals.

Serious harm (NZ) · section 113, serious harm

New Zealand

The Privacy Act 2020 threshold for notifiable privacy breaches, assessed using the section 113 factors — including the sensitivity of the information, who obtained it, and any protections in place.

Service account · API credential, machine account

AU + NZ

A non-human account used by systems and integrations. Because no person owns the login day-to-day, these need an assigned owner, long unique credentials, least privilege and rotation on staff exit.

SMB1001

Australia

A multi-tier cyber security standard for small and medium businesses published by Dynamic Standards International, with annual editions (current edition SMB1001:2026) and certification through accredited providers.

SOCI Act · Security of Critical Infrastructure Act 2018, SOCI

Australia

The Security of Critical Infrastructure Act 2018 — obligations for critical infrastructure assets: asset registration, incident reporting, the CIRMP risk-management program, and government assistance powers. Significantly amended in 2024.

Statutory tort for serious invasions of privacy · privacy tort, statutory tort

Australia

A cause of action commencing 10 June 2025 letting individuals sue for serious invasions of privacy — intrusion upon seclusion or misuse of information — where they had a reasonable expectation of privacy.

V

VERIFIED / INFERRED · verified, inferred

AU + NZ

This site's own evidence labels. VERIFIED: the claim is directly supported by the official source cited, in its own words. INFERRED: a reasonable reading of sourced material where the source doesn't state it in exactly those terms. Every claim carries one, so you can weigh it.

W

Workplace surveillance laws · surveillance notice

Australia

State laws (notably NSW and the ACT) requiring written notice — and in some cases a policy — before monitoring employees' computer use. The legal footing an acceptable use policy's monitoring clause has to respect.

Statutory definitions are simplified for plain English — the linked official source is the authoritative wording. How we verify →