100% found this document useful (1 vote)
237 views5 pages

CQUniversity Cybersecurity Policy Overview

This document outlines CQUniversity's cybersecurity management policy. The policy aims to safeguard confidentiality, integrity and availability of the University's information and communication technology assets. It applies to employees, students, contractors and others using university resources. The policy is based on international cybersecurity standards and Queensland government policies. It establishes cybersecurity principles and defines responsibilities to embed security practices across the University's activities. Fifteen policy domains are identified to govern security controls aligned with standards.

Uploaded by

dinar rosandy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
237 views5 pages

CQUniversity Cybersecurity Policy Overview

This document outlines CQUniversity's cybersecurity management policy. The policy aims to safeguard confidentiality, integrity and availability of the University's information and communication technology assets. It applies to employees, students, contractors and others using university resources. The policy is based on international cybersecurity standards and Queensland government policies. It establishes cybersecurity principles and defines responsibilities to embed security practices across the University's activities. Fifteen policy domains are identified to govern security controls aligned with standards.

Uploaded by

dinar rosandy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Scope
  • Purpose
  • Cybersecurity principles
  • Policy Statement
  • Supporting policies
  • Related Legislation and Documents
  • Responsibilities
  • Compliance, monitoring and review
  • Approval and Review Details
  • Feedback

CYBERSECURITY MANAGEMENT POLICY

CONTENTS
1 PURPOSE ............................................................................................................................................................. 1
2 SCOPE .................................................................................................................................................................. 1
3 POLICY STATEMENT .......................................................................................................................................... 1
Cybersecurity principles ........................................................................................................................................ 2
Supporting policy domains .................................................................................................................................... 2
4 RESPONSIBILITIES ............................................................................................................................................. 4
Compliance, monitoring and review ...................................................................................................................... 4
Reporting ............................................................................................................................................................... 4
Records management ........................................................................................................................................... 4
5 DEFINITIONS ....................................................................................................................................................... 4
Terms and definitions ............................................................................................................................................ 4
6 RELATED LEGISLATION AND DOCUMENTS .................................................................................................... 4
7 FEEDBACK ........................................................................................................................................................... 5
8 APPROVAL AND REVIEW DETAILS ................................................................................................................... 5

1 PURPOSE
1.1 This policy outlines how CQUniversity will manage and mitigate security risks to safeguard the
confidentiality, integrity and availability of University information and communication technology assets and
environment.

2 SCOPE
2.1 This policy applies to:
• the University as a corporate entity
• employees, students, and Council and Committee members of CQUniversity
• employees and students of the PT CQU Executive Business Training Centre, and
• other individuals working on the University’s behalf or using University-owned ICT resources including
contractors, service providers, and other members of the University’s supply chain who are provided
access to the University systems or data as required to deliver contracted services.

3 POLICY STATEMENT
3.1 CQUniversity is committed to managing cybersecurity in accordance with University policy documents and
relevant laws and regulations.

3.2 The University is committed to the secure management of information and systems utilising a policy
framework based on the international standard for security management systems (i.e. ISO 27001), as
required by the Queensland Government Enterprise Architecture (QGEA) Information Security Policy
(IS18:2018). The University will manage cybersecurity risks and controls to the extent that there are clear
financial benefits to the University. Where the cost of control does not present an advantage over the
potential cost of risk, a deviation from IS18:2018 may be considered.

Cybersecurity Management Policy Effective Date: 19/01/2021


Reference Number: 725 Page 1 of 5

Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Cybersecurity principles
3.3 The University has adopted the following high-level cybersecurity principles to establish a sound foundation
for cybersecurity policies, procedures and practices. These principles are:
• Information, in whatever form, is of fundamental importance to the University and as such the University
will manage cybersecurity within a framework based on the internationally recognised Information
Security Management System Standard ISO 27001.
• Cybersecurity risks will be managed, taking into account broader University objectives, strategies and
priorities. A risk management approach will be used to identify, evaluate and mitigate risks for the
University’s systems and information assets. This is supported by the Risk Management Policy and
Enterprise Risk Management Framework and related risk management information.
• The requirements of the ISO 27001 Standard, the QGEA, and therefore this policy, are based on the
following three elements of cybersecurity:
o confidentiality: ensuring that information will be accessible only to those authorised to have access
o integrity: safeguarding the accuracy and completeness of information and processing methods, and
o availability: ensuring that authorised users will have access to information and associated assets when
required.
• Management will actively support cybersecurity within the organisational culture through clear direction,
demonstrated commitment, explicit assignment, and acknowledgment of cybersecurity responsibilities.
This will ensure cybersecurity management is embedded in University activities and processes.
• Continuity of operations will be heavily dependent upon the confidentiality, integrity and continued
availability of information and the means by which it is gathered, stored and processed, communicated
and reported. This is supported by the Information Assets Security Classification Policy.

Supporting policy domains

3.4 This policy has defined 15 policy domains aligned with ISO 27001:2013 as listed below. These domains are
subject areas in which management controls are defined, applied and governed by one or more local Digital
Services Directorate documents and are contained in the Information Security Management System (ISMS).
The following table describes these domains.

Policy Domain Summary


Information The ISMS provides the framework of principles, policies, standards and guidelines
Security for the effective management of Information and Technology (IT) Security Risk.
Management
System (ISMS)
Access controls Methods and controls to manage logical access to sensitive data to protect
confidentiality of information as well as integrity and availability requirements.
Access requirements are assessed against the Queensland Government
Authentication Framework and the Information Assets Security Classification Policy.
Access to University information and systems must be:
• attributable to a uniquely identifiable individual who is responsible for actions
performed with their system account
• based on the requirements of the individual's role
• authorised formally by asset owners, routinely revalidated, removed if no longer
required, and managed by passwords and multifactor authentication (MFA)
according to the Information and Communications Technology Passwords
Procedure.

Cybersecurity Management Policy Effective Date: 19/01/2021


Reference Number: 725 Page 2 of 5

Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Communications Methods and controls to manage the secure transmission of information to ensure
Security confidentiality of sensitive data and to minimise the risk of data loss or leakage.
Systems and networks will be segregated according to their respective
cybersecurity risks and use appropriate control mechanisms such as firewalls,
gateways, physical isolation, and encryption.
Operations Methods and controls that balance the need for IT operations professionals to have
Security privileged access to systems and networks with the requirement to maintain secure
access and confidentiality of data. Management and operation of computers and
networks shall be, commensurate with the business risk and value of the
information assets. Access into networks will be granted on an individual user and
application basis using authorised devices and secured pathways.
Physical and Appropriate physical controls will protect information assets against loss, physical
Environmental abuse, unauthorised access and environmental hazards. These will include
Security perimeter security controls, physical access controls, intruder detection controls, fire
protection controls, flood protection controls, and power protection controls.
Supplier The University will implement security controls and processes to manage supplier
Relationships access to information assets. Suppliers and vendors will be given access privileges
only at the level required to deliver contracted services and contracts must comply
with cybersecurity policies.
Systems Cybersecurity controls will be specified and included as an integral part of the
Acquisition and software development and implementation process.
Secure Security requirements will be identified prior to the development or procurement of
Development IT systems, documented in business requirements, validated and tested prior to
implementation, and regularly throughout the systems lifecycle.
Cryptography Methods and controls for ensuring data will be secured during transmission, or
storage through appropriate encryption processes. Includes methods and
processes for managing keys, software and other artefacts.
Incident The University will apply a consistent and effective approach to the management of
Management cybersecurity incidents. Procedures that define the course of action when a
cybersecurity incident is identified will be documented and made available to all
employees.
Business The application of business continuity management will minimise disruption to
Continuity University operations, defining the approach to resilience, disaster recovery and
general contingency controls. Continuity plans will align with the University’s
Business Continuity Management Framework.
Human Resources The University will establish processes and responsibilities relating to cybersecurity
during the recruitment process, employment and separation. Security checks will be
conducted prior to employment. All employees will receive cybersecurity awareness
training upon induction, and at least annually thereafter.
Project Project proposals must include a high-level risk assessment and review of the types
Management and confidentiality levels of information the project will utilise and manage. New
systems will be reviewed by a Cybersecurity Officer prior to implementation via the
change management process.
Asset IT assets, including hardware, software and data will be identified and classified and
Management asset inventories will be maintained. The University will classify and handle all
information assets in accordance with the Queensland Government Information
Security Classification Framework (Section 2). The University will dispose of public
records in accordance with the University Sector Retention and Disposal Schedule
on the Queensland State Archives website, as or in accordance with the Public
Records Act 2002 (Qld). Refer to the Records Management Policy and Procedure
on the process for disposing records.
Data Assurance The University will ensure that all reasonable steps are taken to monitor, review and
audit cybersecurity effectiveness. This will include the assignment of cybersecurity
roles, maintenance of policies and processes and reporting of non-compliance.

Cybersecurity Management Policy Effective Date: 19/01/2021


Reference Number: 725 Page 3 of 5

Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Data Breach The University has formal processes in place to manage a data breach and the
Reporting mandatory notifications that are required under the Privacy Amendment (Notifiable
Data Breaches) Act 2017 (Cwlth).

4 RESPONSIBILITIES

Compliance, monitoring and review


4.1 The Deputy Vice-President (Digital Services) is responsible for implementing, monitoring, reviewing and
ensuring compliance with this policy.

4.2 Individual responsibility for implementation of components of this policy will be allocated to the Deputy
Director Technology and Cybersecurity.

4.3 All University employees have a responsibility under this policy:


• Executives should provide oversight and set the strategy
• Managers should ensure compliance
• Digital Services Directorate have control over implementation and other operational responsibilities, and
• all employees should be aware of the requirements and escalate identified incidents.

4.4 This policy will be reviewed annually to ensure accuracy and compliance.

Reporting
4.5 No additional reporting is required.

Records management
4.6 Employees must manage records in accordance with the Records Management Policy and Procedure. This
includes retaining these records in a recognised University recordkeeping information system.

4.7 University records must be retained for the minimum periods specified in the University Sector Retention and
Disposal Schedule on the Queensland State Archives website. Before disposing of any records, approval
must sought through the Records Management Office (email records@[Link]).

5 DEFINITIONS
5.1 Terms not defined in this document may be in the University glossary.

Terms and definitions


Employee: any person employed by CQUniversity or its controlled entities on a permanent, fixed-term or
casual basis.

Information Security Management System (ISMS): a systematic approach to managing sensitive


University information so that it remains secure. It includes people, processes and IT systems by applying a
risk management process.

6 RELATED LEGISLATION AND DOCUMENTS


Australian Standards:
• AS/NZS ISO/IEC 27001 Information technology -- Security techniques – Information security
management systems
• AS/NZS ISO/IEC 27002 Information technology – Security techniques – Code of practice for information
security management
Business Continuity Planning and Incident Management Policy and Procedure

Cybersecurity Management Policy Effective Date: 19/01/2021


Reference Number: 725 Page 4 of 5

Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C
Enterprise Risk Management Framework
Information and Communications Technology Passwords Procedure
Information Assets Security Classification Policy
Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cwlth)
Queensland Government Enterprise Architecture - Policies, Standards and Guidelines:
• IS 13: Procurement and Disposal of ICT Products and Services Policy
• IS 18:2018 Information Security Policy
• IS 33: Information Access and Use Policy
• IS 38: Use of ICT Services, Facilities and Devices Policy
• IS 44: Information Asset Custodianship Policy
• Queensland Government Authentication Framework
• Records Governance Policy
Risk Management Policy

7 FEEDBACK
7.1 Feedback about this document can be emailed to policy@[Link].

8 APPROVAL AND REVIEW DETAILS


Approval and Review Details
Approval Authority Vice-Chancellor and President
Delegated Approval Authority Vice-President (Global Development)
Advisory Committee N/A
Administrator Deputy Vice-President (Digital Services)
Next Review Date 14/09/2021

Approval and Amendment Details


History
Original Approval Authority and Date Council 01/05/2007
Amendment Authority and Date Updated 27/03/2015 to include references to the Information Security Strategy.
Updated on 14/09/2009; Director IT approved changes to Governance and
procedures 10/03/2010; Vice-Chancellor and President 29/11/2010 Vice-
Chancellor and President 13/05/2015; Vice-Chancellor and President
6/06/2018; Deputy Vice-President (Digital Services) 14/09/2020; Editorial
amendment 19/01/2021.
Notes This document consolidated and replaced the Information Security Policy and
Information Security Procedure (11/03/2010), Information Security
Management Policy and Information Security Management Principles
(29/11/2010) and the Information Security Management Policy and Procedure
(13/05/2015). This document was formerly known as the Information Security
Management Policy and Procedure (06/06/2018).

Cybersecurity Management Policy Effective Date: 19/01/2021


Reference Number: 725 Page 5 of 5

Once PRINTED, this is an UNCONTROLLED DOCUMENT. Refer to Policy Site for latest version.
CQUniversity CRICOS Provider Code: 00219C

Common questions

Powered by AI

Business continuity is integrated into CQUniversity's cybersecurity strategy through the application of business continuity management, which minimizes operational disruptions. This integration is supported by aligning continuity plans with the university’s Business Continuity Management Framework. It outlines resilience strategies, disaster recovery plans, and contingency controls to ensure operational resilience against cybersecurity threats .

CQUniversity maintains operational continuity through a robust approach to managing the confidentiality, integrity, and availability of information. This is achieved by supporting continuity planning with the Information Assets Security Classification Policy and aligning continuity plans with the university's Business Continuity Management Framework. These measures ensure resilience, disaster recovery, and adherence to general contingency controls .

CQUniversity ensures accountability among employees for actions regarding ICT resources through the implementation of access controls. Each user's system account is uniquely identifiable, demanding accountability for actions performed. Access is regulated by the requirements of roles, formally authorized by asset owners, and regularly revalidated. Managed access is supported by passwords and multifactor authentication, as detailed in the Information and Communications Technology Passwords Procedure .

The purpose of cybersecurity incident management procedures at CQUniversity is to provide a consistent and effective response strategy when a cybersecurity incident is identified. These procedures are documented and accessible to all employees, ensuring that there is a predetermined course of action and clarity on roles and responsibilities when potential breaches occur .

Information is considered of fundamental importance to CQUniversity as it plays a crucial role in the functioning and operational continuity of the institution. The university manages cybersecurity risks by adhering to international standards like ISO 27001 for Information Security Management Systems, which provides a framework for risk management. They evaluate and mitigate risks considering the broader university objectives and resource allocation, supported by the Risk Management Policy and Enterprise Risk Management Framework .

Physical and environmental security controls are integral to CQUniversity's cybersecurity framework as they protect information assets from loss, unauthorized access, and environmental hazards. Specific measures include perimeter security, physical access controls, intruder detection systems, and environmental protections like fire, flood, and power protection controls .

Cybersecurity management is embedded within CQUniversity's organizational culture through clear directives, demonstrated commitment, explicit assignment, and acknowledgment of responsibilities by management. This proactive approach involves integrating cybersecurity responsibilities into all university activities and procedures, reinforcing the importance of cybersecurity within the institution's culture .

CQUniversity ensures compliance in managing supplier relationships by implementing security controls that regulate supplier access to information assets. Suppliers are granted access only to the extent necessary for delivering contractual services. These access privileges must adhere to the university's cybersecurity policies, ensuring that contracts align with these standards to mitigate risks associated with third-party access .

CQUniversity's cybersecurity policy aligns with the Queensland Government Enterprise Architecture (QGEA) by implementing the requirements of the QGEA Information Security Policy (IS18:2018). This involves adopting standards such as ISO 27001 for creating secure management systems and emphasizing confidentiality, integrity, and availability. The university also manages cybersecurity within these frameworks only to the extent that it offers financial advantages, allowing deviations when cost-benefit analysis deems appropriate .

CQUniversity's data breach reporting process involves structured procedures to manage data breaches and mandatory notifications. This process is aligned with legislative requirements under the Privacy Amendment (Notifiable Data Breaches) Act 2017. The policy ensures thorough management of breach incidents, thereby maintaining compliance with the legal framework for privacy and data protection .

Cybersecurity Management Policy  
Effective Date: 19/01/2021 
Reference Number: 725  
Page 1 of 5 
 
Once PRINTED, this is an
Cybersecurity Management Policy  
Effective Date: 19/01/2021 
Reference Number: 725  
Page 2 of 5 
 
Once PRINTED, this is an
Cybersecurity Management Policy  
Effective Date: 19/01/2021 
Reference Number: 725  
Page 3 of 5 
 
Once PRINTED, this is an
Cybersecurity Management Policy  
Effective Date: 19/01/2021 
Reference Number: 725  
Page 4 of 5 
 
Once PRINTED, this is an
(https://www.cqu.edu.au/policy) (https://www.cqu.edu.au/policy)Cybersecurity Management Policy  
Effective Date: 19/01/2021

You might also like