This Cyber Security Policy has the following purposes:
Continually review and improve cyber security as the College’s IT environment and the real-world cyber security environment evolve.
Chief Operations Officer and IT Department
The risk of data theft, scams, and security breaches can have a detrimental impact on our organisation’s systems, and reputation. As a result, the College has created this policy to outline the security measures put in place to ensure information remains secure and protected.
This Cyber Security Policy has the following purposes:
Continually review and improve cyber security as the College’s IT environment and the real-world cyber security environment evolve.
The Cyber Security Policy applies to all the College’s permanent, and part-time employees, contractors, remote workers, volunteers, suppliers, interns, and/or any individuals with access to the College’s electronic systems, information, software, and/or hardware.
This Cyber Security Policy applies to all IT infrastructure owned or operated by the College, as well as IT infrastructure owned or operated by persons or organisations that interact with the College’s IT environment, either within that environment directly or remotely. This includes, but is not limited to:
These various infrastructure items are included in any reference to infrastructure, technology or equipment in this policy document.
The College: Eastern College of Australia
Confidential Data:
IT Application Software: Application software encompasses various types of software used within the organisation’s IT infrastructure, including but not limited to:
IT Network Hardware: network hardware including Firewalls, routers, switches, modems and WiFi devices.
IT System Hardware: IT hardware including computer equipment, servers, desktops, laptops, devices and accessories.
IT Network Software: Software that facilitates the operation and management of network devices, including but not limited to network device hardware operating systems, network management tools, and communication protocols.
IT System Software: Computer software essential for the operation of IT systems, including operating systems, device drivers, firmware, and BIOS.
Infrastructure: all items defined above; synonyms include “technology” and “equipment”
Malware: software that is specifically designed to disrupt, damage, or gain unauthorised access to computer systems
Mobile Devices: Portable communication devices including mobile phones, tablets, and other communication devices
Mobile Software: software installed on or used on Mobile Devices
Physical Facilities: physical facilities and locations in which IT infrastructure, as listed above, is stored, operated or used
All employees must be informed and aware of cybersecurity. To facilitate and foster this, the College provides Cyber Security Training, along with formal processes and procedures, and various other documentation related to cyber security. All personnel have a responsibility to be cyber security aware in the activities they perform for the College and to follow documented requirements.
To engage new employees internally, the College will:
All employees have a responsibility to report possible cyber security events as soon as possible after detecting such events. The reports should be directed to the Information Technology Manager or other appropriate personnel such as the Chief Operations Officer.
Cyber Security is the responsibility of the IT Department who are the primary point of responsibility for cyber security within the organisation and have the authority to make and implement cyber security related decisions. All personnel must follow any cyber security related directions given by the IT Department and other authorised personnel.
All employees must maintain appropriate confidentiality of the College’s information and activities to minimise the risk of inadvertently making the College vulnerable to a cyber-security event. Internet traffic may be monitored by the IT Department for the purposes of improved detection of threats and attacks, and that access to specific websites may be blocked if they are identified as a risk. Any attempt to circumvent the internet filtering is considered a breach of policy.
All infrastructure stored, operated, or used by any employee where that infrastructure interacts with the College IT environment must be approved for use by the IT Manager or their nominated delegate and used in accordance with this Cyber Security Policy. For this purpose, various policies, processes, procedures, checklists and other documents specify matters related to cyber security must be used as defined within those relevant documents.
All infrastructure must be known and approved by the IT Manager. This includes all existing infrastructure; and all new infrastructure that interacts with the College’s IT environment, including for guest or short-term users, must be approved before connecting to or integrating with the College’s IT environment. This includes, but is not limited to, all infrastructure as listed in Scope – Infrastructure, above.
All infrastructure must be securely configured as defined by the College. This includes, but is not limited to:
All infrastructure must be protected against cyber incidents. This includes, but is not limited to:
Where WiFi access is available, there must be a dedicated Guest network, separate from the main College network, that is used by all personnel who are external to College, except where functional or operational requirements necessitate otherwise (e.g. approved third-party maintenance). This Guest network must be configured with minimal access rights.
All infrastructure must be stored, operated and used only as approved by the College.
IT systems and applications will have controlled access aligned with the purpose of the program. The controls must include some form of authentication of the user (e.g., login). Where appropriate and possible, multi-factor authentication will be required.
IT systems and some applications will have controlled access using a login with a username and password. Passwords are recommended to adhere to the following standards:
Additionally, the College utilises a service to monitor and alert the IT department in the event that a breach related to a College email account is identified.
Multi-Factor Authentication
Multi-Factor authentication is required where data or resources that can be accessed are of a sensitive or high value nature. When required, it will be implemented using only methods and technologies approved by IT Department.
IT networks will have controlled access aligned with the purposes of the College. The controls must include some form of authentication of the user (e.g., login). Where possible and appropriate multi-factor authentication will be required.
Remote access to infrastructure will be controlled – only approved personnel using approved remote access methods and technology will be permitted. As remote employees will be accessing the College’s accounts and systems from a distance, they are obliged to follow all data encryption, protection standards and settings, and ensure their private network is secure. Advice can be obtained from the IT Department.
Physical facilities will be protected as follows:
Employees have a responsibility to safeguard the Physical Facilities and Infrastructure of the College. They must abide by all physical access requirements for the College facilities and infrastructure.
The College recognises the security risks of transferring confidential data internally and/or externally. To minimise the chances of data theft, we instruct all employees to:
Backups are crucial defences against threats such as phishing, ransomware, and insider incidents. In case of data loss, backups are essential for restoring lost files and emails. Generally, the College’s backups are managed by the IT Department. However, employees using personal devices should coordinate backup storage options with the IT Team.
To safeguard the College from data loss and protect its reputation, employees must:
These measures help ensure that critical data can be recovered effectively in the event of an incident.
Updates, sometimes called patches, are released by manufacturers and producers of software from time-to-time, usually quite regularly. All infrastructure, most notably IT systems and applications, as well as network devices, must be updated with appropriate updates and patches provided by the manufacturers and suppliers of the infrastructure as soon as possible. Where possible and operationally practical, updates should be applied automatically and therefore incumbent on staff members to download and reset their computer devices accordingly for automatic updates. Staff members should refrain from disabling or delaying updates for extended periods.
Above and beyond normal updates from time-to-time, major new releases of software are made available by software manufacturers and producers. Most notable are major releases of operating systems (e.g. Microsoft Windows 8.1 to Windows 10). The following apply:
Refer Data Breach Policy for details on data breaches and cyber security incident management.
This policy applies in conjunction with the following policies:

Chief Operations Officer and IT Department
The risk of data theft, scams, and security breaches can have a detrimental impact on our organisation’s systems, and reputation. As a result, the College has created this policy to outline the security measures put in place to ensure information remains secure and protected.
This Cyber Security Policy has the following purposes:
Continually review and improve cyber security as the College’s IT environment and the real-world cyber security environment evolve.
The Cyber Security Policy applies to all the College’s permanent, and part-time employees, contractors, remote workers, volunteers, suppliers, interns, and/or any individuals with access to the College’s electronic systems, information, software, and/or hardware.
This Cyber Security Policy applies to all IT infrastructure owned or operated by the College, as well as IT infrastructure owned or operated by persons or organisations that interact with the College’s IT environment, either within that environment directly or remotely. This includes, but is not limited to:
These various infrastructure items are included in any reference to infrastructure, technology or equipment in this policy document.
The College: Eastern College of Australia
Confidential Data:
IT Application Software: Application software encompasses various types of software used within the organisation’s IT infrastructure, including but not limited to:
IT Network Hardware: network hardware including Firewalls, routers, switches, modems and WiFi devices.
IT System Hardware: IT hardware including computer equipment, servers, desktops, laptops, devices and accessories.
IT Network Software: Software that facilitates the operation and management of network devices, including but not limited to network device hardware operating systems, network management tools, and communication protocols.
IT System Software: Computer software essential for the operation of IT systems, including operating systems, device drivers, firmware, and BIOS.
Infrastructure: all items defined above; synonyms include “technology” and “equipment”
Malware: software that is specifically designed to disrupt, damage, or gain unauthorised access to computer systems
Mobile Devices: Portable communication devices including mobile phones, tablets, and other communication devices
Mobile Software: software installed on or used on Mobile Devices
Physical Facilities: physical facilities and locations in which IT infrastructure, as listed above, is stored, operated or used
All employees must be informed and aware of cybersecurity. To facilitate and foster this, the College provides Cyber Security Training, along with formal processes and procedures, and various other documentation related to cyber security. All personnel have a responsibility to be cyber security aware in the activities they perform for the College and to follow documented requirements.
To engage new employees internally, the College will:
All employees have a responsibility to report possible cyber security events as soon as possible after detecting such events. The reports should be directed to the Information Technology Manager or other appropriate personnel such as the Chief Operations Officer.
Cyber Security is the responsibility of the IT Department who are the primary point of responsibility for cyber security within the organisation and have the authority to make and implement cyber security related decisions. All personnel must follow any cyber security related directions given by the IT Department and other authorised personnel.
All employees must maintain appropriate confidentiality of the College’s information and activities to minimise the risk of inadvertently making the College vulnerable to a cyber-security event. Internet traffic may be monitored by the IT Department for the purposes of improved detection of threats and attacks, and that access to specific websites may be blocked if they are identified as a risk. Any attempt to circumvent the internet filtering is considered a breach of policy.
All infrastructure stored, operated, or used by any employee where that infrastructure interacts with the College IT environment must be approved for use by the IT Manager or their nominated delegate and used in accordance with this Cyber Security Policy. For this purpose, various policies, processes, procedures, checklists and other documents specify matters related to cyber security must be used as defined within those relevant documents.
All infrastructure must be known and approved by the IT Manager. This includes all existing infrastructure; and all new infrastructure that interacts with the College’s IT environment, including for guest or short-term users, must be approved before connecting to or integrating with the College’s IT environment. This includes, but is not limited to, all infrastructure as listed in Scope – Infrastructure, above.
All infrastructure must be securely configured as defined by the College. This includes, but is not limited to:
All infrastructure must be protected against cyber incidents. This includes, but is not limited to:
Where WiFi access is available, there must be a dedicated Guest network, separate from the main College network, that is used by all personnel who are external to College, except where functional or operational requirements necessitate otherwise (e.g. approved third-party maintenance). This Guest network must be configured with minimal access rights.
All infrastructure must be stored, operated and used only as approved by the College.
IT systems and applications will have controlled access aligned with the purpose of the program. The controls must include some form of authentication of the user (e.g., login). Where appropriate and possible, multi-factor authentication will be required.
IT systems and some applications will have controlled access using a login with a username and password. Passwords are recommended to adhere to the following standards:
Additionally, the College utilises a service to monitor and alert the IT department in the event that a breach related to a College email account is identified.
Multi-Factor Authentication
Multi-Factor authentication is required where data or resources that can be accessed are of a sensitive or high value nature. When required, it will be implemented using only methods and technologies approved by IT Department.
IT networks will have controlled access aligned with the purposes of the College. The controls must include some form of authentication of the user (e.g., login). Where possible and appropriate multi-factor authentication will be required.
Remote access to infrastructure will be controlled – only approved personnel using approved remote access methods and technology will be permitted. As remote employees will be accessing the College’s accounts and systems from a distance, they are obliged to follow all data encryption, protection standards and settings, and ensure their private network is secure. Advice can be obtained from the IT Department.
Physical facilities will be protected as follows:
Employees have a responsibility to safeguard the Physical Facilities and Infrastructure of the College. They must abide by all physical access requirements for the College facilities and infrastructure.
The College recognises the security risks of transferring confidential data internally and/or externally. To minimise the chances of data theft, we instruct all employees to:
Backups are crucial defences against threats such as phishing, ransomware, and insider incidents. In case of data loss, backups are essential for restoring lost files and emails. Generally, the College’s backups are managed by the IT Department. However, employees using personal devices should coordinate backup storage options with the IT Team.
To safeguard the College from data loss and protect its reputation, employees must:
These measures help ensure that critical data can be recovered effectively in the event of an incident.
Updates, sometimes called patches, are released by manufacturers and producers of software from time-to-time, usually quite regularly. All infrastructure, most notably IT systems and applications, as well as network devices, must be updated with appropriate updates and patches provided by the manufacturers and suppliers of the infrastructure as soon as possible. Where possible and operationally practical, updates should be applied automatically and therefore incumbent on staff members to download and reset their computer devices accordingly for automatic updates. Staff members should refrain from disabling or delaying updates for extended periods.
Above and beyond normal updates from time-to-time, major new releases of software are made available by software manufacturers and producers. Most notable are major releases of operating systems (e.g. Microsoft Windows 8.1 to Windows 10). The following apply:
Refer Data Breach Policy for details on data breaches and cyber security incident management.
This policy applies in conjunction with the following policies:
Policy Portal
ABN: 61 551 855 405 | ACN: 641 764 785 | RTO No. 22065 | HE No. PRV12149 | CRICOS: 03853H
Copyright Eastern College Australia 2021