Policy Corporate Governance Information Security Policy

Information Security Policy


Print Friendly and PDFPrint Friendly

Intent

This Policy provides direction and oversight on how James Cook University (JCU; the University) safeguards the confidentiality, integrity and availability of its information management systems against security risks and threats.

This Policy addresses Higher Education Standards Framework (HESF) Standard 7.3.3(b).

Scope

This Policy applies to all Authorised Users of the University’s information management systems regardless of location, i.e. the University’s Australian and international campuses and study centres (including JCU Brisbane); whether during or after business hours or whether on JCU-owned or privately owned devices. This includes contractors and third-party service providers who may require access to JCU information management systems.

Definitions

Refer to the Digital Policy Glossary for a comprehensive list of definitions, terms and explanations relating to information security at JCU.

Policy

1. Policy Alignment

This Policy and it’s supporting processes align with the relevant legislative frameworks across JCU Corporate, and the Queensland Government Information Security Policy (IS 18:2018).

In implementing this Policy, the University adopts internationally recognised frameworks and standards including:

  • ISO/IEC 27001 Information security, cybersecurity and privacy protection – Information security management systems – Requirements;
  • ISO/IEC 27002 Information security, cybersecurity and privacy protection – Information security controls;
  • National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), which is used as the University’s primary reference model for assessing information security maturity and guiding continuous improvement; and
  • Australian Signals Directorate (ASD) Modern Defensible Architecture (MDA), which informs the University’s secure‑by‑design, Zero Trust and resilience‑focused approach to the design, implementation and operation of information systems.

2. Principles

2.1 Governance and Management: The University’s senior management is committed to providing direction, support and resources for information security in alignment with business, legal, statutory, regulatory, and contractual requirements. Information security decisions will be guided by the University’s documented risk appetite.

2.2 Security and Risk Management: The University adopts a proactive, risk informed approach to information security by anticipating potential threats and vulnerabilities informed by threat intelligence and vulnerability assessments and taking preventive measures to mitigate risks before they can be exploited.

2.3 Compliance and Continuous Improvement: The University is dedicated to regularly monitoring, measuring, analysing, and evaluating its information security performance. This continuous improvement approach ensures compliance with applicable laws, regulations, and contractual requirements while identifying areas for enhancement. Mandatory information security requirements and controls are defined through standards established under this Policy, supporting compliance, continuous improvement and effective management of information security risk within their applicable scope.

2.4 Access Control: The University’s approach to user access to information assets and systems is based on business need, risk and least privilege principles.

3. Objectives

To achieve these Principles, JCU will:

3.1 Integrate information security into JCU’s enterprise strategy to foster a culture of security and risk awareness at all organisational levels.

3.2 Integrate applicable requirements and control measures specified in IS 18:2018, ISO/IEC 27001 and ISO/IEC 27002 into JCU’s practices and processes (including policies, procedures, standards, guidelines and similar) with clearly defined roles and responsibilities.

3.3 Use metrics for Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to:

3.3.1 Provide management insight on organisation-wide cybersecurity and data privacy controls, including functions performed by third parties.

3.3.2 Predict optimal performance, ensure continued operations and identify areas for improvement.

3.3.3 Make informed decisions about changes and process improvements.

3.3.4 Monitor and report information security maturity to appropriate governance levels.

3.4 Utilise the Vice Chancellor’s Committee (VCC) for its management of information security functions and the Audit, Risk and Compliance Committee of Council (Australia) and the Board (Singapore) for its governance oversight of information security, cybersecurity and privacy protection.

3.5 Establish processes to ensure compliance requirements are identified, documented, managed, reported and reviewed at appropriate levels.

3.6 Promote a culture of continuous improvement and awareness through education, training and relevant resources (including documented procedures, standards, website, etc).

3.7 Maintain open communication channels for reporting security incidents and vulnerabilities.

3.8 Encourage and promote innovation in security measures and management.

3.9 Formalise and manage these objectives through an Information Security Management Framework and associated documents (including procedures, standards, playbooks, manuals, guidelines, etc).

4. Responsibilities

4.1 The Chief Information Officer (CIO) is the Accountable Officer delegated to lead the implementation, management, and reporting of information security across JCU Corporate, including the establishment, approval and oversight of information security standards under this policy.

4.2 All users of the University’s information management systems are responsible for information security in accordance with this Policy and its supporting procedures and mandatory standards.

4.3 Product Owners and Business Owners must ensure that systems under their control comply with this Policy and associated procedures and mandatory standards.

Related policy instruments

Information Security Standards

Compliance Policy

Cyber Incident Response Plan

Data Governance Policy

Digital Technologies Acceptable Use Policy

General Data Protection Regulation (GDPR) Procedure

Information Privacy Policy

Information Privacy Statement and Collection Notice

Information Security - Management Review Procedure

Personal Information Data Breach Procedure

Records Management Policy

Requests for Access and Amendment to Personal Information Procedure

Risk Management Policy

Risk Management Framework and Plan

Right to Information Policy

Staff Code of Conduct

Student Code of Conduct

Schedules/Appendices

Nil

Related documents and legislation

Australia:

Criminal Code Act (1995) (Cth)

Copyright Act 1968 (Cth)

Privacy Act 1988 (Cth)

Spam Act 2003 (Cth)

Telecommunications (Interception and Access) Act 1979 (Cth)

Telecommunications Act 1997 (Cth)

Higher Education Standards Framework (Threshold Standards) 2021

Information Privacy Act 2009 (Qld)

Public Records Act 2002 (Qld)

Right to Information Act (Qld) 2009

Telecommunications Interception Act 2009 (Qld)

Queensland Right to Information Act 2009 (Qld)

Queensland Information Security Policy (IS18:2018)

Singapore:

Personal Data Protection Act 2012

Personal Data Protection Regulations 2021

Personal Data Protection (Notification of Data Breaches) Regulations 2021

Personal Data Protection (Do Not Call Registry) Regulations 2013

Personal Data Protection (Enforcement) Regulations 2021

Cybersecurity Act 2018

Computer Misuse Act

Public Sector (Governance) Act 2018

Other:

European Union’s General Data Protection Regulation

ISO/IEC 27001 Information security, cybersecurity and privacy protection – Information security management systems – Requirements

ISO/IEC 27002 Information security, cybersecurity and privacy protection – Information security controls

Administration

NOTE: Printed copies of this policy are uncontrolled, and currency can only be assured at the time of printing.

Approval Details

Policy Domain

Corporate Governance

Policy Sub-domain

Risk, Assurance, Regulatory and Compliance

Policy Custodian

Vice Chancellor

Approval Authority

Council

Date for next Major Review

01/08/2029

Revision History

Version no.

Approval date

Approved by

Implementation date

Details

Author

26-1 11/08/2026 Council 18/08/2026

Major review to align policy with new mandatory standards and integrated NIST CSF content, enabling disestablishment of the Information Security Management Framework and associated procedures.

Information Security – Governance, Risk and Compliance Manager

24-1

01/08/2024

Council

07/08/2024

Policy established – replaces Cybersecurity Policy

Information Security – Governance, Risk and Compliance Manager

Keywords

Information security, cyber security, cybersecurity, NIST, ISO27001, ISO27002, IT

Contact person

Information Security – Governance, Risk and Compliance Manager