Information Security Policy
Intent
This Policy provides direction and oversight on how James Cook University (JCU; the University) safeguards the confidentiality, integrity and availability of its information management systems against security risks and threats.
This Policy addresses Higher Education Standards Framework (HESF) Standard 7.3.3(b).
Scope
This Policy applies to all Authorised Users of the University’s information management systems regardless of location, i.e. the University’s Australian and international campuses and study centres (including JCU Brisbane); whether during or after business hours or whether on JCU-owned or privately owned devices. This includes contractors and third-party service providers who may require access to JCU information management systems.
Definitions
Refer to the Digital Policy Glossary for a comprehensive list of definitions, terms and explanations relating to information security at JCU.
Policy
1. Policy Alignment
This Policy and it’s supporting processes align with the relevant legislative frameworks across JCU Corporate, and the Queensland Government Information Security Policy (IS 18:2018).
In implementing this Policy, the University adopts internationally recognised frameworks and standards including:
- ISO/IEC 27001 Information security, cybersecurity and privacy protection – Information security management systems – Requirements;
- ISO/IEC 27002 Information security, cybersecurity and privacy protection – Information security controls;
- National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), which is used as the University’s primary reference model for assessing information security maturity and guiding continuous improvement; and
- Australian Signals Directorate (ASD) Modern Defensible Architecture (MDA), which informs the University’s secure‑by‑design, Zero Trust and resilience‑focused approach to the design, implementation and operation of information systems.
2. Principles
2.1 Governance and Management: The University’s senior management is committed to providing direction, support and resources for information security in alignment with business, legal, statutory, regulatory, and contractual requirements. Information security decisions will be guided by the University’s documented risk appetite.
2.2 Security and Risk Management: The University adopts a proactive, risk informed approach to information security by anticipating potential threats and vulnerabilities informed by threat intelligence and vulnerability assessments and taking preventive measures to mitigate risks before they can be exploited.
2.3 Compliance and Continuous Improvement: The University is dedicated to regularly monitoring, measuring, analysing, and evaluating its information security performance. This continuous improvement approach ensures compliance with applicable laws, regulations, and contractual requirements while identifying areas for enhancement. Mandatory information security requirements and controls are defined through standards established under this Policy, supporting compliance, continuous improvement and effective management of information security risk within their applicable scope.
2.4 Access Control: The University’s approach to user access to information assets and systems is based on business need, risk and least privilege principles.
3. Objectives
To achieve these Principles, JCU will:
3.1 Integrate information security into JCU’s enterprise strategy to foster a culture of security and risk awareness at all organisational levels.
3.2 Integrate applicable requirements and control measures specified in IS 18:2018, ISO/IEC 27001 and ISO/IEC 27002 into JCU’s practices and processes (including policies, procedures, standards, guidelines and similar) with clearly defined roles and responsibilities.
3.3 Use metrics for Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to:
3.3.1 Provide management insight on organisation-wide cybersecurity and data privacy controls, including functions performed by third parties.
3.3.2 Predict optimal performance, ensure continued operations and identify areas for improvement.
3.3.3 Make informed decisions about changes and process improvements.
3.3.4 Monitor and report information security maturity to appropriate governance levels.
3.4 Utilise the Vice Chancellor’s Committee (VCC) for its management of information security functions and the Audit, Risk and Compliance Committee of Council (Australia) and the Board (Singapore) for its governance oversight of information security, cybersecurity and privacy protection.
3.5 Establish processes to ensure compliance requirements are identified, documented, managed, reported and reviewed at appropriate levels.
3.6 Promote a culture of continuous improvement and awareness through education, training and relevant resources (including documented procedures, standards, website, etc).
3.7 Maintain open communication channels for reporting security incidents and vulnerabilities.
3.8 Encourage and promote innovation in security measures and management.
3.9 Formalise and manage these objectives through an Information Security Management Framework and associated documents (including procedures, standards, playbooks, manuals, guidelines, etc).
4. Responsibilities
4.1 The Chief Information Officer (CIO) is the Accountable Officer delegated to lead the implementation, management, and reporting of information security across JCU Corporate, including the establishment, approval and oversight of information security standards under this policy.
4.2 All users of the University’s information management systems are responsible for information security in accordance with this Policy and its supporting procedures and mandatory standards.
4.3 Product Owners and Business Owners must ensure that systems under their control comply with this Policy and associated procedures and mandatory standards.
Related policy instruments
Information Security Standards
Cyber Incident Response Plan
Digital Technologies Acceptable Use Policy
General Data Protection Regulation (GDPR) Procedure
Information Privacy Statement and Collection Notice
Information Security - Management Review Procedure
Personal Information Data Breach Procedure
Requests for Access and Amendment to Personal Information Procedure
Risk Management Framework and Plan
Schedules/Appendices
Nil
Related documents and legislation
Australia:
Criminal Code Act (1995) (Cth)
Telecommunications (Interception and Access) Act 1979 (Cth)
Telecommunications Act 1997 (Cth)
Higher Education Standards Framework (Threshold Standards) 2021
Information Privacy Act 2009 (Qld)
Right to Information Act (Qld) 2009
Telecommunications Interception Act 2009 (Qld)
Queensland Right to Information Act 2009 (Qld)
Queensland Information Security Policy (IS18:2018)
Singapore:
Personal Data Protection Act 2012
Personal Data Protection Regulations 2021
Personal Data Protection (Notification of Data Breaches) Regulations 2021
Personal Data Protection (Do Not Call Registry) Regulations 2013
Personal Data Protection (Enforcement) Regulations 2021
Cybersecurity Act 2018
Computer Misuse Act
Public Sector (Governance) Act 2018
Other:
European Union’s General Data Protection Regulation
ISO/IEC 27001 Information security, cybersecurity and privacy protection – Information security management systems – Requirements
ISO/IEC 27002 Information security, cybersecurity and privacy protection – Information security controls
Administration
NOTE: Printed copies of this policy are uncontrolled, and currency can only be assured at the time of printing.
Approval Details
Policy Domain | Corporate Governance |
Policy Sub-domain | Risk, Assurance, Regulatory and Compliance |
Policy Custodian | Vice Chancellor |
Approval Authority | Council |
Date for next Major Review | 01/08/2029 |
Revision History
Version no. | Approval date | Approved by | Implementation date | Details | Author |
| 26-1 | 11/08/2026 | Council | 18/08/2026 | Major review to align policy with new mandatory standards and integrated NIST CSF content, enabling disestablishment of the Information Security Management Framework and associated procedures. | Information Security – Governance, Risk and Compliance Manager |
24-1 | 01/08/2024 | Council | 07/08/2024 | Policy established – replaces Cybersecurity Policy | Information Security – Governance, Risk and Compliance Manager |
Keywords | Information security, cyber security, cybersecurity, NIST, ISO27001, ISO27002, IT |
Contact person | Information Security – Governance, Risk and Compliance Manager |