Implementing Effective Security Measures
Set up a policy framework based on your organisation’s operational needs. Identify the assets to protect — personnel, information, physical assets, and services — that are necessary for ongoing operations. Conduct a risk assessment using Business Impact Levels (BILs) to inform the policies, plans, and processes. Consider other operational policies that could be affected. Record the policies, plans, and processes in one document or separate documents, but coordinate their development. Publish them on the intranet so the whole organisation is aware of them, and promote them. See security awareness training. Review them at least every two years to identify gaps and keep up with changes to risk factors.
Security policy covering governance, personnel, information, and assets
Section titled “Security policy covering governance, personnel, information, and assets”Your protective security policy mandates your organisation’s protective security plan and processes, meeting the requirements of the security system.
The Chief Executive or Agency Head, or their delegate, must approve the policy and ensure its enforcement. The Chief Security Officer (CSO) should actively monitor it.
The policy must cover four areas — governance, personnel, information, and protection. Each policy should explain why it is necessary and who authorised it.
Governance arrangements
Section titled “Governance arrangements”Governance arrangements outline how protective security relates to other operational governance, such as:
- Employee and public safety
- Security requirements in contracts
- Security management roles
- Business Impact Levels (BILs)
- Audit and compliance reporting
- Fraud risk management
- Handling foreign government information
- Policy exceptions
- Review and amendment processes
Personnel security policy
Section titled “Personnel security policy”The personnel security policy should include:
- Employee and contractor security checks
- Security clearance requirements, including managing clearances
- Emergency access to confidential materials
- Procedures for investigating and managing security incidents
Physical security policy
Section titled “Physical security policy”The physical security policy should address:
- Access to facilities by your people, visitors, and children — site-specific policies may be needed where facilities have different roles or risks
- The security and safety of your people — the security policy should align with other safety policies
- Working away from the office
- The physical security of your information
Develop your security plan and processes
Section titled “Develop your security plan and processes”Your protective security plan and processes must reduce security risks while allowing secure information sharing. They may be part of the security plan or stand-alone advice for staff.
The plan should be comprehensive. Consult staff across the organisation — the CSO, Chief Information Security Officer, Health and Safety Manager, IT Security Manager, Privacy Officer, property managers, and security managers or advisors — and get senior management’s support.
The plan’s objectives are to use risk assessments to identify areas of security risk and outline practical steps to minimise them. Develop separate site security plans for each site. Consider how you classify and protect the security plan, and the business impact if its confidentiality is compromised. Classify individual elements of the plan as appropriate.
The plan must cover four key areas: security of governance, personnel, information, and physical assets.
Governance arrangements
Section titled “Governance arrangements”Governance arrangements should include:
- Roles and responsibilities for security
- Contracting service providers and third-party security
- Business continuity and disaster recovery planning
- Increasing security in response to threats
- Reporting incidents and conducting investigations
- Audit and compliance reporting
- Fraud risk management
- Reviewing and amending plans
If other sections of the organisation manage governance in standalone plans, consult your security management personnel while developing them.
Personnel security arrangements
Section titled “Personnel security arrangements”Personnel security should include:
- Recruitment provisions in collaboration with Human Resource Management
- Police verification and clearance
- Contact reporting
- Security clearance management
- Ongoing security awareness training
Physical security arrangements
Section titled “Physical security arrangements”Physical security measures should include:
- Creating site security plans
- Ensuring the safety of personnel, visitors, and the public
- Securing information
- Protecting physical assets
- Implementing access control systems
- Installing security alarms
- Securing disaster recovery and alternative sites and establishing business continuity plans
- Establishing physical security for remote work and work away from the office
