Hong Kong Information Security Group

Assessment Methodology

Versioned, inspectable rules for Trust Reviews and HKISG IT Awards — with AI security treated as a first-class domain, not a footnote.

Methodology v2026.2

What we measure — and what we refuse to sell

HKISG scores organisational and product trust for Hong Kong buyers and boards. Membership funds capacity and queue access. No payment can alter a score, star band, TrustScore, or published finding.v2026.2 expands the rubric so classical cyber controls and AI-era risks are assessed in one coherent frame.

Assessment programmes

Two public programmes, one integrity rule: evidence over narrative.

Programme A

Trust Reviews

Organisation-level trust posture against a 100-point scorecard, mapped to TrustScore / star bands, with dated scope notes and practitioner feedback where collected.

Programme B

IT Awards

Time-boxed white-hat assessment of a nominated product or service — including GenAI, agentic, and AI-security products — with published stars only when the band is met.

Trust Review — 100-point scorecard

Six weighted domains. AI security is scored alongside governance, protection, detection, supply chain, and evidence — not bolted on after the fact.

15pts

Governance & accountability

Board-level ownership, risk appetite language, policy enforcement in practice, escalation paths to executives, and clear accountability for cyber and AI outcomes — not shelfware policies.

18pts

Protective controls

Identity and access (MFA / phishing-resistant where feasible), asset inventory, vulnerability handling, network and cloud hardening, backup immutability, and secure configuration baselines.

18pts

Detection & response

Telemetry coverage, SOC or MSSP playbooks, escalation SLAs, tabletop and live exercise recency, forensics readiness, and how AI-assisted alerts are validated by humans before high-impact action.

18pts

AI security & model governance

Model and GenAI inventory, prompt/agent abuse testing, training and RAG data controls, third-party LLM diligence, human oversight for high-stakes outputs, deepfake/social-engineering resilience, and AI incident runbooks.

14pts

Supplier & resilience

Third-party assurance, concentration risk, realistic RTO/RPO, continuity tests, cloud/SaaS exit plans, and whether critical AI vendors have contractual security and data-handling commitments.

17pts

Evidence quality

Recency, completeness, reproducibility, and operational proof. Points are not awarded for aspirational roadmaps or undated screenshots. AI claims require versioned model/system records where in scope.

Domain weights always total 100. If AI is formally out of scope after inventory verification, the 18 AI points are redistributed proportionally across the remaining domains for that review only — and the public page states the redistribution.

Trust Reviews may also publish a separate public website hygiene grade (passive TLS / security-header observation of the organisation’s public site). That grade is a buyer lens — not a penetration-test certification and not a substitute for the six-domain scorecard.

AI security lenses

Inside the AI Security & Model Governance domain, assessors apply these lenses. They also inform IT Awards testing when a nominated product embeds or sells AI.

Inventory & ownership

Named owners for every production model, GenAI app, agent, and embedded AI feature — including shadow IT discoveries during the review window.

Abuse & adversarial testing

Prompt injection, jailbreak, tool-calling abuse, retrieval poisoning, and adversarial evasion against any AI security controls claimed in marketing.

Data & model integrity

Training/fine-tune/RAG data provenance, access controls, retention, redaction, and whether customer data can leak into shared model contexts.

Autonomy & human oversight

Where agents or automated decisions can change access, money, or customer outcomes — and the human approval gates that must fire first.

Third-party LLM / API risk

Provider diligence, residency options, subprocessors, rate-limit and key hygiene, and fallback when a frontier model provider degrades or is blocked.

AI-assisted defence & offence

How the organisation uses AI in SOC/IR without over-trusting it — and how it defends against AI-accelerated phishing, credential stuffing, and recon.

Cross-cutting aspects

Every Trust Review also samples these operating aspects. Findings map into the six domains rather than creating parallel scores.

Identity & zero trust

Least privilege, step-up authentication, session hygiene, and segmentation assumptions that survive remote and hybrid work.

Data protection & PDPO

Lawful use, retention, cross-border transfer awareness, breach notification readiness, and privacy impact thinking for AI features that process personal data.

Cloud & SaaS posture

Shared-responsibility clarity, admin plane hardening, logging export, and misconfiguration debt that attackers actually exploit.

Secure development

Threat modelling, dependency hygiene, secrets handling, release gates, and how GenAI coding assistants are constrained in production pipelines.

Supply chain & third parties

Vendor onboarding evidence, update integrity, MSP/MSSP access paths, and AI API providers treated as in-scope suppliers.

Human & deepfake risk

Verification rituals for payment and access changes, executive impersonation drills, and staff awareness tuned to AI-generated voice/video fraud in Hong Kong.

Star bands & TrustScore

Rubric points map to public star bands. Trust Reviews may also publish a TrustScore (0.0–5.0) with a qualitative label (for example Excellent). We do not award participation trophies.

  • 5 stars (90–100): Reference-grade maturity for the agreed scope — including AI controls where applicable.
  • 4 stars (80–89): Strong, verifiable controls with limited, actively managed gaps.
  • 3 stars (70–79): Credible baseline; continuous improvement still material.
  • Below 70: No public star. The organisation receives a private remediation roadmap before retest.

IT Awards — white-hat testing

Nominated platforms face a time-boxed assessment against a written scope. The panel validates attack-path resistance, not marketing claims. For AI-bearing products, testing explicitly includes abuse cases that classical appsec checklists miss.

  • Public-facing exposure and attack-surface reduction
  • Authentication integrity and authorisation bypass resistance
  • Vulnerability disclosure handling and fix cadence
  • Operational recovery evidence under simulated stress
  • AI product extras: prompt/agent abuse, unsafe tool use, data exfiltration via model channels, content integrity, and oversight failures

An award means high resistance during the test window for the stated scope. It does not certify the permanent absence of vulnerabilities or model failures.

Hong Kong operating context

Rubric language is written for operators who face local and cross-border pressure: bilingual customer channels, dense SaaS estates, financial and logistics concentration, and rapid GenAI adoption. Assessors expect evidence that fits this market — for example deepfake-enabled payment fraud drills, regional data handling notes, and HKCERT-aligned patch urgency — not generic global checklist theatre.

Process lifecycle

  1. Scope lock — systems, vendors, AI assets, and exclusions written before scoring starts.
  2. Conflict declaration — assessors and reviewers declare interests; rotation applies.
  3. Evidence intake — operational artefacts preferred over policy-only packs.
  4. Scoring & challenge — draft findings; factual challenge window before publication.
  5. Public record — dated score, scope, limitations, methodology version, expiry.
  6. Retest / expiry — 12-month default life; earlier reassessment on material change.

Expiry, retest & corrections

  • 12-month expiry: Trust Reviews expire after 12 months unless a dated retest renews them. Material architecture, ownership, or AI-stack changes can force earlier reassessment.
  • Change history: Each public profile keeps a visible revision trail.
  • Factual corrections: Corrections add dated notes; they do not silently rewrite the original score.

Version history

  • v2026.2 (current): Adds AI Security & Model Governance as a scored domain; publishes AI lenses and cross-cutting aspects; clarifies N/A redistribution rules.
  • v2026.1: Five-domain organisational scorecard and IT Awards white-hat baseline.

Review Governance RulesBrowse Trust Reviews

Frequently asked questions

Can we see the full rubric before applying?
Yes. Domain weights, AI lenses, star bands, and evidence expectations are published on this page. Private assessor worksheets stay internal — criteria are not secret.
What evidence counts toward points?
Recent, reproducible, operational proof — not policy PDFs alone. The Evidence quality domain (12 points) scores recency, completeness, and reproducibility. AI systems additionally require model inventory, oversight records, and abuse-test notes where in scope.
How do IT Awards differ from Trust Reviews?
Trust Reviews score organisational trust posture across six domains (including AI security) plus practitioner feedback. IT Awards apply time-boxed white-hat testing to nominated products or services — including GenAI / agentic products when nominated. Both use published bands; neither is purchasable through membership alone.
Is AI assessment mandatory even if we do not use AI?
If the agreed scope has no AI systems, AI assistants, or AI-assisted security tooling, the AI Security domain is scored as not applicable and its weight is redistributed proportionally across the other domains for that review. Declaring “no AI” without an inventory check fails Evidence quality.
Which AI threats does HKISG emphasise for Hong Kong?
Prompt injection and agent tool abuse, training/RAG data leakage, deepfake-enabled social engineering, third-party LLM and API supply chain risk, biased or ungoverned automated decisions affecting customers, and AI-assisted attack automation against identity and edge systems.
How does this relate to PDPO and Hong Kong regulators?
Methodology domains map to practical controls buyers and boards ask about under the Personal Data (Privacy) Ordinance, sector guidance, and HKCERT-style hygiene. HKISG scores are not a legal opinion or regulatory certification — they are an independent, dated trust signal.