Hong Kong Information Security Group

Knowledge Base

Advisories and structured security knowledge for Hong Kong — durable reference beyond the first 48 hours of an alert.

Structured knowledge for operators

When the initial crisis passes, teams still need a canonical write-up: affected systems, mitigations, ownership, and Hong Kong context. The knowledge base holds those entries — sourced, dated, and aligned with HKISG editorial standards.

Bulletins start the clock. The knowledge base keeps the playbook.Knowledge programme design

When to use the knowledge base

  • Building internal runbooks that reference neutral, dated HKISG advisories.
  • Onboarding analysts who missed the original bulletin window.
  • Scoping vendor discussions with cited risk context instead of forwarded screenshots.
  • Preparing Trust Review evidence on how advisories were actioned.

Editorial integrity

Entries identify primary sources, show publication dates, and retain corrections. Analysis is labelled as analysis. For active exploitation, always cross-checkbulletins and HKCERT.

Frequently asked questions

How is the knowledge base different from bulletins?
Bulletins prioritise time-sensitive early warning with risk labels. Knowledge-base entries are structured advisories designed to remain useful after the initial alert window — ideal for runbooks and training libraries.
Who should maintain knowledge-base links internally?
Assign a security or IT owner to review entries quarterly, map them to your asset inventory, and archive links that no longer apply to your estate.
Are knowledge-base entries vendor endorsements?
No. Entries cite sources and describe risks or controls in neutral language. HKISG does not endorse products unless a separate, dated Trust Review or award supports the claim.
Can we cite entries in compliance documentation?
Yes, with attribution and date. Entries are educational advisories — supplement, not replace, formal audit opinions, regulatory filings, or HKCERT coordination.