ICT Information Management and Security Policy
ICT Information Management and Security Policy
Policy
1 Purpose
To ensure that Information Security measures are in place, commensurate with their Information
Asset classification, to protect Information Assets, Information and Communication Technology
(ICT) Assets and Information Systems within the University ICT environment against
unauthorised use or accidental modification, loss or release; and assist the University mitigate
any damage or liability arising from the use of these Information Assets and Information
Systems for purposes contrary to the University's policies and relevant Regulatory Compliance
Instrument.
2 Scope
This policy applies to all Employees, Researchers, University Members and Students (hereafter
referred to as 'users') who have access to the University's Information Assets and related
Information Systems.
3 Policy Statement
The University is committed to the management of risks associated with ICT Assets and
Information Systems and the reduction of ICT security incidents. This policy provides the
governance framework for Information management and security within the University and
defines the University policy in all aspects of Information Security as stipulated under the
relevant Information standards.
4 Principles
4.1 Internal governance
Information Security governance arrangements are established and endorsed by the University
ICT Strategy Board and assisted by other relevant University committees. The implementation,
maintenance and control of operational Information Security is the responsibility of ICT
Services. The ICT Cyber Security Committee is responsible for monitoring and recommending
Information Security strategy, controls and associated operational security matters.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
All Information System users are responsible for familiarising themselves with this policy and
related policies and procedures, as appropriate to their role within the University. Effective
communication of this ICT Information Management and Security Policy, and all associated
policies and procedures, form part of this ongoing commitment to Information Security
governance and is critical to ensuring that ICT Assets and Information Assets are protected
from unauthorised use, accidental modification, loss or release.
In the event of a cyber breach such as, but not limited to, malware, computer hacking,
ransomware, or denial of service attack, the Chief Digital Information Officer is authorised to
implement a range of measures, including removal of individual access to the network and
removal of ICT Assets and ICT Systems from the network to minimise the risk of loss or misuse
of Information Assets.
Availability - ensuring that authorised users have access to Information when required
Compliant Use - ensuring that the University meets all Regulatory Compliance
Instruments and contractual obligations
Responsible Use - ensuring that appropriate controls are in place so that users have
access to accurate, relevant and timely Information but that users of the University's ICT
resources do not adversely affect other users or other Information Systems.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
reasonably:
2. develop and implement an Information Security Plan, ensuring alignment with the
University business planning, general security plan and risk assessment findings
The University will meet its data retention obligations under the Telecommunications
(Interception and Access) Amendment (Data Retention) Act 2015 (section 187) recognising that
the University will rely on the 'immediate circle' exclusion for any relevant services provided only
to persons who are 'inherently connected to the functions of the University'.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
4.7 People Portfolio management
The University will implement measures to minimise the risk of loss or misuse of Information
Assets by ensuring that Security Safeguards are incorporated into University People Portfolio
management, including the development of supporting policies and processes. The University at
a minimum will reasonably:
1. implement induction and ongoing training and security awareness programs to ensure
that all Employees are aware of and acknowledge this policy and related policies and
procedures on Information Security and security responsibilities
2. document and assign security roles and responsibilities where Employees have access
to security classified Information or perform specific security related roles, and ensure
that security requirements are addressed in recruitment and selection and in job
descriptions
3. develop and implement procedures for the separation of Employees from, or relocation
within, the University.
1. building and entry controls for areas used in the processing and storage of security
classified ICT Information are established and maintained, consistent with the
Information Asset and Security Classification Procedure
2. all ICT Assets that store or process Information are located in Secure Areas with control
mechanisms in place to restrict access to authorised personnel only
3. Policies, procedures and processes are implemented to monitor and protect the use
and/or maintenance of Information Assets and mobile ICT Assets away from University
premises
4. Policies, procedures and processes are implemented for the secure disposal or reuse of
ICT Assets, commensurate with the Information Asset's security classification level.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
consistently, in accordance with the level of required security. The University at a minimum will
reasonably ensure that:
1. operational change control procedures and release management control procedures are
implemented to ensure that changes to Information processing facilities or Systems are
appropriately approved and managed
3. adequate controls are defined and implemented to mitigate the impact of threats and
vulnerabilities to the network, including the prevention, detection, removal and reporting
of attacks of malicious code on all ICT Assets
4. Systems maintenance processes and procedures, including operator and audit/ fault
logs, media handling procedures, Information backup procedures and archiving, will be
implemented
5. methods for exchanging Information within the University, outside the University, through
online services, and/or with third parties, will be consistent with the Queensland
Government Information Security Classification Framework (QGISCF) and the Network
Transmission Security Assurance Framework (NTSAF) and University policies and
procedures
7. each Employee must use the University authorised and supplied communications
methods, including electronic mail, when transacting official University business
8. the Student Communication Policy and related policies and procedures cover Handling
Personal Student Information Policy and Procedure, Student Communication Procedure,
Use of Electronic Mail Procedure establish the framework for all electronic
communications with Students.
1. access will be provided to users for the purpose of carrying out work, study or other
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
activities as agreed with the University
2. access will be granted on the 'least privilege' principle in which each user is granted the
most restricted set of privileges needed for the performance of the relevant tasks
4. access to the University network and Information Systems requires specific authorisation
and each user must be assigned an individually unique personal identification code and
secure means of authentication
5. access to shared ICT Assets in teaching and research laboratories may be subject to
shared access management rules as agreed by the University
7. 'restricted access' and 'authorised use only' warnings must be displayed upon access to
all Systems which have this capability
8. access to all emails, documents, University network, and Information Systems will be
terminated upon departure from the University.
There is an obligation on Employees who are studying University Courses, who also have a
level of administration access to related University Systems, to contact the Course Coordinator
for the Course/s the Employee is studying to alert them to this fact. This also applies to
Employees with relationships to Students studying University Courses resulting in a perceived,
potential or actual conflict of interest, as identified in the Conflict of Interest Procedure. During
the course of their study, the Employee is not permitted to access the relevant Course
environments, or applicable Systems, using their administrator access.
The University requires users to keep user-level passwords confidential and change these
immediately if they suspect that their password has been comprised.
A Clear Desk and Clear Screen is required to reduce the risk of unauthorised access or damage
to Information Assets and ICT Assets.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
1. security requirements are addressed in the specifications, analysis and/or design
phases and internal and/or external audit are consulted when implementing new or
significant changes to financial or critical business Information Systems
2. Security Safeguards are established during all stages of System development, as well
as when new Systems are implemented and maintained in the operational environment
3. appropriate change control, acceptance and System testing, planning and migration
control measures are carried out when upgrading or installing software in the operational
environment
4. a patch management program for operating Systems, firmware and applications of all
ICT Assets is implemented to maintain vendor support, increase stability and reduce the
likelihood of threats being exploited.
1. establish and maintain an Information Security incident and response register and
record all incidents
2. ensure all Information Security incidents are reported and escalated (where applicable)
through appropriate management channels and/or authorities
3. ensure that incidents are investigated and apply formal disciplinary processes
4. ensure responsibilities and procedures for the timely reporting of security events and
incidents, including breaches, threats and security weaknesses, are communicated to all
University Members.
1. establish plans and processes to assess the risk and impact of the loss of Information
and ICT Assets on University business in the event of a disaster or security failure and
develop methods for reducing known risks to University Information and ICT Assets
2. ensure business continuity Information and ICT Asset disaster recovery plans are
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
maintained and tested to ensure Systems and Information are available and consistent
with agency business and service level requirements.
University Members should also refer to the Business Continuity Policy and Crisis Management
Policy.
1. all Information Security policies, procedures and processes, including contracts with ICT
third parties, are reviewed for compliance on a regular basis
2. all reporting obligations relating to ICT Security are complied with and managed
appropriately
3. all reasonable steps are taken to monitor, review and audit University Information
Security compliance, including the engagement of internal and/or external auditors and
specialist organisations where required.
This will be irrespective of whether the violation is internal (e.g. unauthorised access to
Information), external (e.g. unauthorised remote access to the University network by a non-
University Employee or Student), or where assistance is provided by a University Employee or
Student to provide unauthorised access to the University network.
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
The responsibility for protecting ICT resources and services is shared with all users who use
these services. The University will make all reasonable efforts to protect University Members
from possible ICT and computer-related dangers but cannot always protect University Members
from all potential threats. The University cannot guarantee to protect an individual against
exposure to material that may be offensive to them. University Members will be warned that
they may traverse or receive material that they find offensive.
5 References
Australian Government. (2015). Telecommunications (Interception and Access) Amendment
(Data Retention) Act 2015. Canberra, Australia: Australian Government Retrieved October 13,
2016 from [Link]
6 Schedules
This policy must be read in conjunction with its subordinate schedules as provided in the table
below.
7 Policy Information
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Data Breach Response Plan Schedule
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
General Retention and Disposal Schedule (GRDS) (Queensland
Government)
Policy Framework
Privacy Policy
Procurement Policy
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Records and Information Management Policy
Privacy Procedure
Website Procedure
Council
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Course
Course Coordinator
Employee
General Misconduct
Information
Information Asset
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Information Security
Information Systems
Researcher
Student
University
University Members
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Persons who include: Employees of the University whose conditions
of employment are covered by the UniSQ Enterprise Agreement
whether full time or fractional, continuing, fixed-term or casual,
including senior Employees whose conditions of employment are
covered by a written agreement or contract with the University;
members of the University Council and University Committees;
visiting, honorary and adjunct appointees; volunteers who contribute
to University activities or who act on behalf of the University; and
individuals who are granted access to University facilities or who are
engaged in providing services to the University, such as contractors or
consultants, where applicable.
Clear Desk
Clear desks at the end of each work day of all sensitive Information
Assets including documents and notes, business cards, and
removable media (e.g. USB memory sticks) to ensure a reduction of
the risk of information theft, fraud, or a security breach caused by
sensitive Information being left unattended and visible in plain view.
Clear Screen
Cyber Security
ICT Asset
Public Record
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Refer Public Records Act 2023.
Secure Area
Provides the highest integrity of access to, and audit of, Security
Classified Information Assets to ensure restricted distribution and to
assist in subsequent investigation if there is unauthorised disclosure
or loss of Information Assets. The essential physical security features
of a Secure Area include, but are not limited to:
Security Safeguards
System
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.
Keywords Information management and security
Record No 13/340PL
Failure to comply with this Policy or Policy Instrument may be considered as misconduct and the provisions of the relevant Policy or Procedure
applied. A hard copy of this electronic document is uncontrolled and may not be current as UniSQ the University regularly reviews and updates
its Policies and Policy Instruments. The latest controlled version can be found in the UniSQ’s Policy and Procedure Library.