Many of the rules, frameworks, and technical concepts we work with have specialist names. This page explains them in plain English. Use it whenever something on the site is unclear.
The legal requirements that shape what Australian organisations have to do for privacy, security, and operational resilience.
The law that governs how Australian organisations handle personal information. Sets the baseline rules for collecting, storing, using, and sharing data about individuals. Recent updates have raised the bar on what counts as a serious breach and what penalties apply.
The law that sets cyber and operational rules for organisations Australia depends on. Covers power, water, communications, transport, banking, healthcare, food and grocery, data storage, and other essential services.
The cyber security rule that banks, insurers, and super funds must follow. Issued by APRA, the financial sector regulator. Requires strong information security controls and prompt reporting of any material incident.
The operational risk rule that banks, insurers, and super funds must follow. Requires regulated organisations to manage risks, keep critical operations running through disruptions, and oversee any service providers they rely on.
The Australian government regulator for banks, insurers, and super funds. Sets the rules that apply to those organisations, including CPS 234 (cyber) and CPS 230 (operational risk).
Voluntary or buyer-required benchmarks that organisations adopt to prove their security, AI safety, or operational maturity.
The international standard for managing information security. Sets out how an organisation should run, monitor, and improve a security program. Many enterprise customers require their suppliers to be certified to it.
The international standard for managing AI systems. Sets out how an organisation should govern AI development, deployment, and ongoing use. The AI counterpart to ISO 27001.
The international standard for cyber security in industrial systems. Used by operators of factories, power plants, water utilities, transport networks, and similar systems where the technology controls physical processes.
The Australian Cyber Security Centre's baseline of eight cyber controls. Every Australian organisation is expected to have these in place: keeping software patched, blocking untrusted apps, enforcing multi-factor authentication, controlling user access, and so on.
The Australian government's voluntary standard for safe AI use. Practical guidance for organisations on how to govern AI development, set guardrails, and manage risk to people and society.
The Australian government's assessment scheme that confirms a service meets government security expectations. Cloud and managed services serving government agencies typically need an IRAP assessment.
The Australian Signals Directorate's framework for assessing hosting providers used by government. Determines whether a cloud or data centre is fit to host Australian Government data, particularly sensitive workloads.
The Australian Signals Directorate's reference for how government systems should be configured and operated securely. Used by government agencies and the providers that serve them.
The risk management plan that critical infrastructure operators must maintain under the SOCI Act. Covers cyber, supply chain, personnel, and physical risks. Operators must attest to it annually.
Concepts and approaches that come up across security, cloud, AI, and infrastructure work.
A structured way to find out what could go wrong with a system, before it does. Looks at who might want to attack, what they would target, and what damage they could do, so the right protections are built in from the start.
A security approach where no user or device is trusted just because it sits inside the company network. Every access request is verified, regardless of where it comes from. Replaces the old "trusted internal network" model.
A pre-built, secure cloud environment ready to host applications. Standardised so new workloads start safe and stay secure as they grow. Saves teams from rebuilding the foundations every time.
Practices that bring financial discipline to cloud spending. Makes sure cloud bills track to the business value being created, not just the systems being run.
The current strength of an organisation's security or compliance. The shape of how it would hold up if tested by an auditor or attacker. People speak of cyber posture, AI posture, cloud posture, and so on.
Formal, evidence-backed proof that an organisation meets a standard or rule. Often required by regulators, auditors, or customers. Goes beyond a claim by showing the evidence behind it.
AI systems that take actions on behalf of a user or organisation, not just answer questions. They can chain together steps, use tools, and pursue goals. Useful, but raise new safety and security questions.
The systems that control physical processes, like factory production lines, power generation, water treatment, or transport signalling. Distinct from IT (which runs office and business systems).
The senior executive accountable for an organisation's cyber security. Sets strategy, reports to the board, and answers for the program.
A very large cloud provider operating at global scale. The three most commonly used by Australian organisations are Amazon Web Services (AWS), Microsoft Azure, and Google Cloud.
Words we use to describe how Lumaris is engaged and what to expect from a Lumaris engagement.
An engagement where a senior partner-grade specialist leads the work, not a junior. The principal stays present from first conversation to final handover. Sets the tone for accountability and quality.
Work, documents, or briefings prepared to the standard a board of directors expects. Decisions and rationale documented, risks named, options weighed, evidence attached.
An engagement priced and scoped upfront, with a fixed end date. Reduces buyer risk by setting clear limits on what will be done, for what price, by when.
A part-time or shared Chief Information Security Officer. Used by organisations that need security leadership but do not yet need a full-time executive in the role.
We'll add it. The point of this page is to make the rest of the site usable.