View Current

Information Security Policy

This is the current version of this document. There are no historic or future versions available for this document.

Section 1 - Overview

(1) This Policy sets out our commitment to protecting our information, information assets, products and services through appropriate governance, practices and controls.

(2) We recognise that effective information security is fundamental to maintaining the trust of our clients and other stakeholders, meeting our legal and contractual obligations, and supporting the reliable delivery of our products and services. We are committed to preserving the confidentiality, integrity and availability of our information and information assets through the implementation of security measures that are proportionate to the risks they address.

Top of Page

Section 2 - Scope

(3) This Policy applies to our information, information assets, products and services, and to all activities undertaken by or on our behalf that may affect their security.

Top of Page

Section 3 - Policy

(4) We will:

  1. protect the confidentiality, integrity and availability of our information and information assets through appropriate administrative, physical and technical controls;
  2. identify, assess and manage information security risks as part of our ongoing governance and operational activities;
  3. seek to eliminate information security risks wherever reasonably practicable and, where risks cannot reasonably be eliminated, implement controls to prevent, reduce or otherwise mitigate those risks, having regard to the nature of the risk, the level of the threat, applicable legal and contractual obligations, and relevant commercial considerations;
  4. implement information security controls that are proportionate to the level of risk presented to our information, information assets, products and services;
  5. ensure access to our information and information assets is authorised and limited to legitimate business requirements;
  6. protect confidential information and sensitive information from unauthorised access, use, disclosure, modification, loss or destruction;
  7. identify, assess and respond to vulnerabilities and security incidents in a timely and appropriate manner;
  8. undertake penetration tests and other security assurance activities appropriate to the level of risk presented by our products, services and information assets;
  9. maintain arrangements that support the continuity, resilience and recovery of our products, services and business operations following a security incident or other disruptive event;
  10. ensure our personnel understand their information security responsibilities and are supported in fulfilling those responsibilities;
  11. require third parties acting on our behalf to maintain information security practices appropriate to the services they provide and the risks they present; and
  12. monitor, review and continually improve our information security governance, practices and controls.
Top of Page

Section 4 - Procedures

(5) Refer to the Associated Information page for more information.

Top of Page

Section 5 - Guidelines

(6) Nil.

Part A - Definitions

(7) Definitions applicable to this Policy are contained in the Corporate Glossary.