Hong Kong Information Security Group

Glossary

Clear definitions for security terms used across HKISG content — so engineers, risk owners, and boards speak the same language.

One vocabulary for the whole programme

Misaligned terms cause misaligned controls. HKISG maintains this glossary so bulletins, education, research, and assessment rubrics use consistent language — reducing friction between technical teams and governance audiences in Hong Kong.

If two teams define "incident" differently, your response plan is already broken.Glossary maintenance rule

How to use the glossary

  • Link glossary entries in internal runbooks and vendor RFPs for shared definitions.
  • Attach terms to board papers when introducing new controls or risk categories.
  • Cross-reference wiki articles when a term needs framework-level context.
  • Use alongside education modules for onboarding and refresher training.

Maintenance and trust

Definitions are reviewed on a scheduled cycle and updated when industry usage or HKISG programme language changes. Corrections are dated under Editorial Standards. The glossary is educational reference — not legal or regulatory text.

Terms A–Z

Definitions used across HKISG publications and programmes.

Frequently asked questions

How are glossary terms chosen?
Terms appear when they are used across HKISG bulletins, education, research, or assessment rubrics. The Editorial Council reviews definitions for accuracy and plain-language clarity.
Can we suggest a new term?
Members may propose additions via contact. Proposals need a cited source and proposed definition — marketing neologisms without industry usage are declined.
Do definitions match regulatory text exactly?
Glossary entries explain terms in operator language. For statutory definitions — for example under the PDPO — consult official sources such as PCPD.
How does the glossary relate to wiki articles?
Glossary entries are concise definitions. Wiki articles explore frameworks and practices in depth, often linking back to glossary terms.