CYBERSECURITY MANAGEMENT POLICY
CONTENTS
1 PURPOSE ............................................................................................................................................................. 1
2 SCOPE .................................................................................................................................................................. 1
3 POLICY STATEMENT .......................................................................................................................................... 1
Cybersecurity principles ........................................................................................................................................ 2
Supporting policy domains .................................................................................................................................... 2
4 RESPONSIBILITIES ............................................................................................................................................. 4
Compliance, monitoring and review ...................................................................................................................... 4
Reporting ............................................................................................................................................................... 4
Records management ........................................................................................................................................... 4
5 DEFINITIONS ....................................................................................................................................................... 4
Terms and definitions ............................................................................................................................................ 4
6 RELATED LEGISLATION AND DOCUMENTS .................................................................................................... 4
7 FEEDBACK ........................................................................................................................................................... 5
8 APPROVAL AND REVIEW DETAILS ................................................................................................................... 5
1 PURPOSE
1.1 This policy outlines how CQUniversity will manage and mitigate security risks to safeguard the
confidentiality, integrity and availability of University information and communication technology assets and
environment.
2 SCOPE
2.1 This policy applies to:
• the University as a corporate entity
• employees, students, and Council and Committee members of CQUniversity
• employees and students of the PT CQU Executive Business Training Centre, and
• other individuals working on the University’s behalf or using University-owned ICT resources including
contractors, service providers, and other members of the University’s supply chain who are provided
access to the University systems or data as required to deliver contracted services.
3 POLICY STATEMENT
3.1 CQUniversity is committed to managing cybersecurity in accordance with University policy documents and
relevant laws and regulations.
3.2 The University is committed to the secure management of information and systems utilising a policy
framework based on the international standard for security management systems (i.e. ISO 27001), as
required by the Queensland Government Enterprise Architecture (QGEA) Information Security Policy
(IS18:2018). The University will manage cybersecurity risks and controls to the extent that there are clear
financial benefits to the University. Where the cost of control does not present an advantage over the
potential cost of risk, a deviation from IS18:2018 may be considered.
Cybersecurity Management Policy Effective Date: 19/01/2021
Reference Number: 725 Page 1 of 5
Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Cybersecurity principles
3.3 The University has adopted the following high-level cybersecurity principles to establish a sound foundation
for cybersecurity policies, procedures and practices. These principles are:
• Information, in whatever form, is of fundamental importance to the University and as such the University
will manage cybersecurity within a framework based on the internationally recognised Information
Security Management System Standard ISO 27001.
• Cybersecurity risks will be managed, taking into account broader University objectives, strategies and
priorities. A risk management approach will be used to identify, evaluate and mitigate risks for the
University’s systems and information assets. This is supported by the Risk Management Policy and
Enterprise Risk Management Framework and related risk management information.
• The requirements of the ISO 27001 Standard, the QGEA, and therefore this policy, are based on the
following three elements of cybersecurity:
o confidentiality: ensuring that information will be accessible only to those authorised to have access
o integrity: safeguarding the accuracy and completeness of information and processing methods, and
o availability: ensuring that authorised users will have access to information and associated assets when
required.
• Management will actively support cybersecurity within the organisational culture through clear direction,
demonstrated commitment, explicit assignment, and acknowledgment of cybersecurity responsibilities.
This will ensure cybersecurity management is embedded in University activities and processes.
• Continuity of operations will be heavily dependent upon the confidentiality, integrity and continued
availability of information and the means by which it is gathered, stored and processed, communicated
and reported. This is supported by the Information Assets Security Classification Policy.
Supporting policy domains
3.4 This policy has defined 15 policy domains aligned with ISO 27001:2013 as listed below. These domains are
subject areas in which management controls are defined, applied and governed by one or more local Digital
Services Directorate documents and are contained in the Information Security Management System (ISMS).
The following table describes these domains.
Policy Domain Summary
Information The ISMS provides the framework of principles, policies, standards and guidelines
Security for the effective management of Information and Technology (IT) Security Risk.
Management
System (ISMS)
Access controls Methods and controls to manage logical access to sensitive data to protect
confidentiality of information as well as integrity and availability requirements.
Access requirements are assessed against the Queensland Government
Authentication Framework and the Information Assets Security Classification Policy.
Access to University information and systems must be:
• attributable to a uniquely identifiable individual who is responsible for actions
performed with their system account
• based on the requirements of the individual's role
• authorised formally by asset owners, routinely revalidated, removed if no longer
required, and managed by passwords and multifactor authentication (MFA)
according to the Information and Communications Technology Passwords
Procedure.
Cybersecurity Management Policy Effective Date: 19/01/2021
Reference Number: 725 Page 2 of 5
Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Communications Methods and controls to manage the secure transmission of information to ensure
Security confidentiality of sensitive data and to minimise the risk of data loss or leakage.
Systems and networks will be segregated according to their respective
cybersecurity risks and use appropriate control mechanisms such as firewalls,
gateways, physical isolation, and encryption.
Operations Methods and controls that balance the need for IT operations professionals to have
Security privileged access to systems and networks with the requirement to maintain secure
access and confidentiality of data. Management and operation of computers and
networks shall be, commensurate with the business risk and value of the
information assets. Access into networks will be granted on an individual user and
application basis using authorised devices and secured pathways.
Physical and Appropriate physical controls will protect information assets against loss, physical
Environmental abuse, unauthorised access and environmental hazards. These will include
Security perimeter security controls, physical access controls, intruder detection controls, fire
protection controls, flood protection controls, and power protection controls.
Supplier The University will implement security controls and processes to manage supplier
Relationships access to information assets. Suppliers and vendors will be given access privileges
only at the level required to deliver contracted services and contracts must comply
with cybersecurity policies.
Systems Cybersecurity controls will be specified and included as an integral part of the
Acquisition and software development and implementation process.
Secure Security requirements will be identified prior to the development or procurement of
Development IT systems, documented in business requirements, validated and tested prior to
implementation, and regularly throughout the systems lifecycle.
Cryptography Methods and controls for ensuring data will be secured during transmission, or
storage through appropriate encryption processes. Includes methods and
processes for managing keys, software and other artefacts.
Incident The University will apply a consistent and effective approach to the management of
Management cybersecurity incidents. Procedures that define the course of action when a
cybersecurity incident is identified will be documented and made available to all
employees.
Business The application of business continuity management will minimise disruption to
Continuity University operations, defining the approach to resilience, disaster recovery and
general contingency controls. Continuity plans will align with the University’s
Business Continuity Management Framework.
Human Resources The University will establish processes and responsibilities relating to cybersecurity
during the recruitment process, employment and separation. Security checks will be
conducted prior to employment. All employees will receive cybersecurity awareness
training upon induction, and at least annually thereafter.
Project Project proposals must include a high-level risk assessment and review of the types
Management and confidentiality levels of information the project will utilise and manage. New
systems will be reviewed by a Cybersecurity Officer prior to implementation via the
change management process.
Asset IT assets, including hardware, software and data will be identified and classified and
Management asset inventories will be maintained. The University will classify and handle all
information assets in accordance with the Queensland Government Information
Security Classification Framework (Section 2). The University will dispose of public
records in accordance with the University Sector Retention and Disposal Schedule
on the Queensland State Archives website, as or in accordance with the Public
Records Act 2002 (Qld). Refer to the Records Management Policy and Procedure
on the process for disposing records.
Data Assurance The University will ensure that all reasonable steps are taken to monitor, review and
audit cybersecurity effectiveness. This will include the assignment of cybersecurity
roles, maintenance of policies and processes and reporting of non-compliance.
Cybersecurity Management Policy Effective Date: 19/01/2021
Reference Number: 725 Page 3 of 5
Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Data Breach The University has formal processes in place to manage a data breach and the
Reporting mandatory notifications that are required under the Privacy Amendment (Notifiable
Data Breaches) Act 2017 (Cwlth).
4 RESPONSIBILITIES
Compliance, monitoring and review
4.1 The Deputy Vice-President (Digital Services) is responsible for implementing, monitoring, reviewing and
ensuring compliance with this policy.
4.2 Individual responsibility for implementation of components of this policy will be allocated to the Deputy
Director Technology and Cybersecurity.
4.3 All University employees have a responsibility under this policy:
• Executives should provide oversight and set the strategy
• Managers should ensure compliance
• Digital Services Directorate have control over implementation and other operational responsibilities, and
• all employees should be aware of the requirements and escalate identified incidents.
4.4 This policy will be reviewed annually to ensure accuracy and compliance.
Reporting
4.5 No additional reporting is required.
Records management
4.6 Employees must manage records in accordance with the Records Management Policy and Procedure. This
includes retaining these records in a recognised University recordkeeping information system.
4.7 University records must be retained for the minimum periods specified in the University Sector Retention and
Disposal Schedule on the Queensland State Archives website. Before disposing of any records, approval
must sought through the Records Management Office (email records@[Link]).
5 DEFINITIONS
5.1 Terms not defined in this document may be in the University glossary.
Terms and definitions
Employee: any person employed by CQUniversity or its controlled entities on a permanent, fixed-term or
casual basis.
Information Security Management System (ISMS): a systematic approach to managing sensitive
University information so that it remains secure. It includes people, processes and IT systems by applying a
risk management process.
6 RELATED LEGISLATION AND DOCUMENTS
Australian Standards:
• AS/NZS ISO/IEC 27001 Information technology -- Security techniques – Information security
management systems
• AS/NZS ISO/IEC 27002 Information technology – Security techniques – Code of practice for information
security management
Business Continuity Planning and Incident Management Policy and Procedure
Cybersecurity Management Policy Effective Date: 19/01/2021
Reference Number: 725 Page 4 of 5
Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Enterprise Risk Management Framework
Information and Communications Technology Passwords Procedure
Information Assets Security Classification Policy
Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cwlth)
Queensland Government Enterprise Architecture - Policies, Standards and Guidelines:
• IS 13: Procurement and Disposal of ICT Products and Services Policy
• IS 18:2018 Information Security Policy
• IS 33: Information Access and Use Policy
• IS 38: Use of ICT Services, Facilities and Devices Policy
• IS 44: Information Asset Custodianship Policy
• Queensland Government Authentication Framework
• Records Governance Policy
Risk Management Policy
7 FEEDBACK
7.1 Feedback about this document can be emailed to policy@[Link].
8 APPROVAL AND REVIEW DETAILS
Approval and Review Details
Approval Authority Vice-Chancellor and President
Delegated Approval Authority Vice-President (Global Development)
Advisory Committee N/A
Administrator Deputy Vice-President (Digital Services)
Next Review Date 14/09/2021
Approval and Amendment Details
History
Original Approval Authority and Date Council 01/05/2007
Amendment Authority and Date Updated 27/03/2015 to include references to the Information Security Strategy.
Updated on 14/09/2009; Director IT approved changes to Governance and
procedures 10/03/2010; Vice-Chancellor and President 29/11/2010 Vice-
Chancellor and President 13/05/2015; Vice-Chancellor and President
6/06/2018; Deputy Vice-President (Digital Services) 14/09/2020; Editorial
amendment 19/01/2021.
Notes This document consolidated and replaced the Information Security Policy and
Information Security Procedure (11/03/2010), Information Security
Management Policy and Information Security Management Principles
(29/11/2010) and the Information Security Management Policy and Procedure
(13/05/2015). This document was formerly known as the Information Security
Management Policy and Procedure (06/06/2018).
Cybersecurity Management Policy Effective Date: 19/01/2021
Reference Number: 725 Page 5 of 5
Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C