Glossary

The terms used across this site.

Many of the rules, frameworks, and technical concepts we work with have specialist names. This page explains them in plain English. Use it whenever something on the site is unclear.

— 01

Rules and laws.

The legal requirements that shape what Australian organisations have to do for privacy, security, and operational resilience.

Privacy ActPrivacy Act 1988

The law that governs how Australian organisations handle personal information. Sets the baseline rules for collecting, storing, using, and sharing data about individuals. Recent updates have raised the bar on what counts as a serious breach and what penalties apply.

SOCI ActSecurity of Critical Infrastructure Act

The law that sets cyber and operational rules for organisations Australia depends on. Covers power, water, communications, transport, banking, healthcare, food and grocery, data storage, and other essential services.

CPS 234APRA Prudential Standard CPS 234

The cyber security rule that banks, insurers, and super funds must follow. Issued by APRA, the financial sector regulator. Requires strong information security controls and prompt reporting of any material incident.

CPS 230APRA Prudential Standard CPS 230

The operational risk rule that banks, insurers, and super funds must follow. Requires regulated organisations to manage risks, keep critical operations running through disruptions, and oversee any service providers they rely on.

APRAAustralian Prudential Regulation Authority

The Australian government regulator for banks, insurers, and super funds. Sets the rules that apply to those organisations, including CPS 234 (cyber) and CPS 230 (operational risk).

— 02

Standards and frameworks.

Voluntary or buyer-required benchmarks that organisations adopt to prove their security, AI safety, or operational maturity.

ISO 27001ISO/IEC 27001

The international standard for managing information security. Sets out how an organisation should run, monitor, and improve a security program. Many enterprise customers require their suppliers to be certified to it.

ISO 42001AI Management System Standard

The international standard for managing AI systems. Sets out how an organisation should govern AI development, deployment, and ongoing use. The AI counterpart to ISO 27001.

IEC 62443

The international standard for cyber security in industrial systems. Used by operators of factories, power plants, water utilities, transport networks, and similar systems where the technology controls physical processes.

Essential Eight

The Australian Cyber Security Centre's baseline of eight cyber controls. Every Australian organisation is expected to have these in place: keeping software patched, blocking untrusted apps, enforcing multi-factor authentication, controlling user access, and so on.

AI Safety StandardVoluntary AI Safety Standard (Australia)

The Australian government's voluntary standard for safe AI use. Practical guidance for organisations on how to govern AI development, set guardrails, and manage risk to people and society.

IRAPInformation Security Registered Assessors Program

The Australian government's assessment scheme that confirms a service meets government security expectations. Cloud and managed services serving government agencies typically need an IRAP assessment.

ASD HCFASD Hosting Certification Framework

The Australian Signals Directorate's framework for assessing hosting providers used by government. Determines whether a cloud or data centre is fit to host Australian Government data, particularly sensitive workloads.

ISMInformation Security Manual

The Australian Signals Directorate's reference for how government systems should be configured and operated securely. Used by government agencies and the providers that serve them.

CIRMPCritical Infrastructure Risk Management Program

The risk management plan that critical infrastructure operators must maintain under the SOCI Act. Covers cyber, supply chain, personnel, and physical risks. Operators must attest to it annually.

— 03

Technical terms.

Concepts and approaches that come up across security, cloud, AI, and infrastructure work.

Threat modelling

A structured way to find out what could go wrong with a system, before it does. Looks at who might want to attack, what they would target, and what damage they could do, so the right protections are built in from the start.

Zero-trust

A security approach where no user or device is trusted just because it sits inside the company network. Every access request is verified, regardless of where it comes from. Replaces the old "trusted internal network" model.

Landing zone

A pre-built, secure cloud environment ready to host applications. Standardised so new workloads start safe and stay secure as they grow. Saves teams from rebuilding the foundations every time.

FinOps

Practices that bring financial discipline to cloud spending. Makes sure cloud bills track to the business value being created, not just the systems being run.

Posture

The current strength of an organisation's security or compliance. The shape of how it would hold up if tested by an auditor or attacker. People speak of cyber posture, AI posture, cloud posture, and so on.

Attestation

Formal, evidence-backed proof that an organisation meets a standard or rule. Often required by regulators, auditors, or customers. Goes beyond a claim by showing the evidence behind it.

Agentic AI

AI systems that take actions on behalf of a user or organisation, not just answer questions. They can chain together steps, use tools, and pursue goals. Useful, but raise new safety and security questions.

OTOperational technology

The systems that control physical processes, like factory production lines, power generation, water treatment, or transport signalling. Distinct from IT (which runs office and business systems).

CISOChief Information Security Officer

The senior executive accountable for an organisation's cyber security. Sets strategy, reports to the board, and answers for the program.

Hyperscaler

A very large cloud provider operating at global scale. The three most commonly used by Australian organisations are Amazon Web Services (AWS), Microsoft Azure, and Google Cloud.

— 04

Engagement terms.

Words we use to describe how Lumaris is engaged and what to expect from a Lumaris engagement.

Principal-led

An engagement where a senior partner-grade specialist leads the work, not a junior. The principal stays present from first conversation to final handover. Sets the tone for accountability and quality.

Board-ready

Work, documents, or briefings prepared to the standard a board of directors expects. Decisions and rationale documented, risks named, options weighed, evidence attached.

Fixed-fee, fixed-scope

An engagement priced and scoped upfront, with a fixed end date. Reduces buyer risk by setting clear limits on what will be done, for what price, by when.

Fractional CISO

A part-time or shared Chief Information Security Officer. Used by organisations that need security leadership but do not yet need a full-time executive in the role.

Something we missed?

If there's a term we use that isn't here, let us know.

We'll add it. The point of this page is to make the rest of the site usable.