Information Security Policy
v4.1
Purpose. This policy establishes how CAQA Nova Digital Systems protects the confidentiality, integrity and availability of its own and its clients' information and systems.
1.Purpose and scope
Nova holds privileged access to the systems of around 140 client organisations and to the personal information of thousands of their users. This policy sets the security commitments of the business and applies to all staff, contractors and systems, whether Nova owned or client owned, wherever work is performed. It is the top level document of the information security management system aligned with ISO 27001.
2.Security principles
Access will be granted on the principle of least privilege and reviewed quarterly. Systems will be configured securely by default, patched within the timeframes in the patching standard and monitored for security events. The business will maintain controls aligned with the Australian Cyber Security Centre's Essential Eight for its own environment and will report each client's maturity against the same model.
- Least privilege access with quarterly reviews
- Multi-factor authentication on every privileged and remote account
- Application control and patching of applications and operating systems
- Restriction of administrative privileges and macros
- Daily backups with tested restores
3.Responsibilities
The Chief Executive Officer is accountable for this policy and for the resourcing of security controls. The Cyber Security Lead owns the security standards and incident response. Team leads must ensure their staff follow the standards. Every worker must protect credentials, report suspected incidents immediately and complete annual security awareness training.
4.Client data and privileged access
Client credentials must be stored only in the approved password vault and must never be written in tickets, chat or email. Privileged access to client systems will be logged and used only for authorised work recorded in a ticket or change. Client data must not be copied to personal devices or unapproved cloud services.
5.Incident reporting
Any suspected security incident, including lost devices, phishing that was clicked, unexpected access or malware alerts, must be reported to the Cyber Security team within one hour of discovery and recorded in the Security Incident Register. Incidents will be handled under the Cyber Security Incident Response Procedure, and data breaches will be assessed under the Privacy Act 1988 notifiable data breaches scheme.
6.Compliance and review
Compliance with this policy will be checked by internal audit twice a year and by an external review annually. Breaches of this policy will be treated as misconduct. The policy will be reviewed annually or after any significant incident.