Hong Kong Government – IT Security Policy & Guidelines | 香港政府 – 資訊保安政策及指引 | 资讯保安政策及指南

Latest update | 最近更新  : 2025.05 

下列文件包括以下兩文三語版本  :  English | 繁體中文 |  简体中文 
Name DescriptionURL/Version/Date
 
[i] SRAA Guidelines
  
Practice Guide for Security Risk Assessment & Audit (ISPG-SM01)This document provides the practical guidance and reference for security risk assessment & audit in the Government.
ISPG-SM01
Version 2.2
August 2026
[ii] Core Policy Document and Guidelines
  
Baseline IT Security Policy
(S17)
outlines the mandatory minimum security requirements for the protection of government’s information systems and data assets.S17
Version 8.2
April 2025
IT Security Guidelines
(G3)
elaborates on the policy requirements and sets the implementation standard on the security requirements specified in the Baseline IT Security Policy.
G3
Version 10.2
April 2025
[iii] Additional Guidelines supporting Policy and SRAA
  
Practice Guide for Information Security Incident Handling
(ISPG-SM02)
provides the practical guidance and reference for handling information security incidents in the Government.ISPG-SM02
Version 1.8
February 2025
Practice Guide for Information Security Incident Handling
(ISPG-SM03)
provides the practical guidance and reference for the secure use of mobile devices and development of mobile apps in the Government.ISPG-SM03
Version 2.1
July 2024
Practice Guide for Information Security Incident Handling
(ISPG-SM04)
provides the practical guidance and reference for the secure adoption of cloud computing technology in the Government.ISPG-SM04
Version 2.1
July 2024
Practice Guide for Internet of Things Securityprovides the practical guidance and reference for the secure adoption of Internet of Things (“IoT”) technology in the Government.IoT
Version 1.2
July 2024
Practice Guide for Social Media Securityprovides the practical guidance and reference for secure management and use of social media in the Government.Social Media
Version 1.2
July 2024
Practice Guide for Wi-Fi Securityprovides the practical guidance and reference for secure design, management and operation of Wi-Fi network in the Government.Wi-Fi
Version 1.2
July 2024
Practice Guide for IT Security Threat Managementprovides the practical guidance and reference for IT security threat management in the Government.
Threat-Mgmt
Version 1.1
July 2024
 
[i] SRAA 保安風險評估及審計實務指引
  
保安風險評估及審計實務指引
(ISPG-SM01)
為政府的保安風險評估及審計工作提供實務指引和參考。ISPG-SM01
第2.2版
2026年8月
[ii] 保安要求及實施標準
  
基準資訊科技保安政策
(S17)
概述為保護政府內部資訊系統及數據資產而訂定的強制性基本保安要求。
S17
第8.2版
2025年4月
資訊科技保安指引
(G3)
闡釋對《基準資訊科技保安政策》的要求及制定相關的實施標準。
G3
第10.2版
2025年4月
[iii] 其他保安實務指引
  
資訊保安事故處理實務指引
(ISPG-SM02)
為在政府內處理資訊保安事故提供實務指引和參考。
ISPG-SM02
第1.8版
2025年2月
流動保安實務指引
(ISPG-SM03)
為在政府內安全使用流動裝置及開發流動應用程式提供實務指引和參考。
ISPG-SM03
第2.1版
2024年7月
雲端運算保安實務指引
(ISPG-SM04)
為在政府內安全採用雲端運算技術提供實務指引和參考。
ISPG-SM04
第2.1版
2024年7月
物聯網保安實務指引為在政府內安全採用物聯網技術提供實務指引和參考。
IoT
第1.2版
2024年7月
社交媒體保安實務指引為在政府內安全管理及使用社交媒體提供實務指引和參考。
Social Media
第1.2版
2024年7月
Wi-Fi 保安實務指引為在政府內安全設計、管理和操作 Wi-Fi 網絡提供實務指引和參考。
Wi-Fi
第1.2版
2024年7月
資訊科技保安威脅管理實務指引為在政府內安全採用資訊保安威脅管理提供實務指引和參考。
Threat-Mgmt
第1.1版
2024年7月
  
SRAA 安全风险评估及审计实务指南
  
安全风险评估及审计实务指南
(ISPG-SM01)
为政府的安全风险评估及审计工作提供实务指南和参考。ISPG-SM01
第2.2版
2026年8月
安全政策及实施标准
  
基准信息技术安全政策
(S17)
概述为保护政府内部信息系统及数据资产而订定的强制性基本保安要求。
S17
第8.2版
2025年4月
信息技术安全指南
(G3)
阐释对《基准信息技术安全政策》的要求及制定相关的实施标准。
G3
第10.2版
2025年7月
其他供实务指南
  
信息安全事故处理实务指南
(ISPG-SM02)
为在政府內处理信息安全事故提供实务指南和参考。
ISPG-SM02
第1.8版
2025年2月
流动安全实务指南
(ISPG-SM03)
为在政府内安全使用流动装置及开发流动应用程序提供实务指南和参考。
ISPG-SM03
第2.1版
2024年7月
云端运算安全实务指南
(ISPG-SM04)
为在政府内安全采用云端运算技术提供实务指南和参考。
ISPG-SM04
第2.1版
2024年7月
物联网安全实务指南为在政府内安全采用物联网技术提供实务指南和参考。
IoT
第1.2版
2024年7月
社交媒体安全实务指南为在政府内安全管理及使用社交媒体提供实务指南和参考。
Social Media
第1.2版
2024年7月
Wi-Fi 安全实务指南为在政府内安全设计、管理和操作 Wi-Fi 网络提供实务指南和参考。
Wi-Fi
第1.2版
2024年7月
信息技术安全威胁管理实务指南为在政府内安全采用信息技术安全威胁管理提供实务指南和参考。
Threat-Mgmt
第1.1版
2024年7月

Back to Top | 回頁首