Glossary
Clear definitions for security terms used across HKISG content — so engineers, risk owners, and boards speak the same language.
One vocabulary for the whole programme
Misaligned terms cause misaligned controls. HKISG maintains this glossary so bulletins, education, research, and assessment rubrics use consistent language — reducing friction between technical teams and governance audiences in Hong Kong.
If two teams define "incident" differently, your response plan is already broken.Glossary maintenance rule
How to use the glossary
- Link glossary entries in internal runbooks and vendor RFPs for shared definitions.
- Attach terms to board papers when introducing new controls or risk categories.
- Cross-reference wiki articles when a term needs framework-level context.
- Use alongside education modules for onboarding and refresher training.
Maintenance and trust
Definitions are reviewed on a scheduled cycle and updated when industry usage or HKISG programme language changes. Corrections are dated under Editorial Standards. The glossary is educational reference — not legal or regulatory text.
Terms A–Z
Definitions used across HKISG publications and programmes.
APT (Advanced Persistent Threat)
Authentication
Brute Force Attack
CISA
CISO
Chief Information Security Officer (CISO) — HKISG definition and how the role relates to Trust Reviews, AI security, and board briefings in Hong Kong.
CISSP
Cloud Security
Deepfake
Digital Forensics
Encryption
FIDO2 / Passkeys
Firewall
GDPR
Hackathon
HKCERT
HKCERT is Hong Kong’s Computer Emergency Response Team. How it differs from HKISG for cybersecurity incident coordination.
Incident Response
Key Management
LLM
Large language model (LLM) — definition and AI security considerations for Hong Kong organisations.
Malware
MSSP
Managed Security Service Provider (MSSP) — definition for Hong Kong buyers, and what HKISG expects when privilege is shared with a third party.
Network Segmentation
PCI DSS
PDPO
PDPO — Hong Kong’s Personal Data (Privacy) Ordinance. Relevance to AI systems, cybersecurity programmes, and HKISG Trust Reviews.
Phishing
Prompt Injection
Definition of prompt injection — an AI security attack that steers LLMs or agents via crafted inputs. Hong Kong operator notes from HKISG.
Ransomware
SIEM
Social Engineering
Threat Intelligence
Two-Factor Authentication (2FA)
Vulnerability Management
Web3 Security
Zero Trust Architecture
Frequently asked questions
- How are glossary terms chosen?
- Terms appear when they are used across HKISG bulletins, education, research, or assessment rubrics. The Editorial Council reviews definitions for accuracy and plain-language clarity.
- Can we suggest a new term?
- Members may propose additions via contact. Proposals need a cited source and proposed definition — marketing neologisms without industry usage are declined.
- Do definitions match regulatory text exactly?
- Glossary entries explain terms in operator language. For statutory definitions — for example under the PDPO — consult official sources such as PCPD.
- How does the glossary relate to wiki articles?
- Glossary entries are concise definitions. Wiki articles explore frameworks and practices in depth, often linking back to glossary terms.