Cyber security policy resources for Australian organisations.
Plain English cyber security policy guidance for organisations that need practical rules for people, systems, suppliers and incident response.
A practical starting point
A cyber security policy should be useful to the people who have to follow it. AICS resources are written for Australian organisations that need clear internal rules without starting from a foreign template or a document that is too technical to implement.
The aim is to help boards, managers, staff and advisers understand the minimum expectations for protecting information, reporting incidents and using systems responsibly.
What the resources cover
Acceptable use
Clear expectations for using business systems, email, internet access, cloud services and work devices.
Incident reporting
Plain English guidance on when staff should report suspicious emails, account compromise, data loss or cyber incidents.
Access control
Practical rules for passwords, multi-factor authentication, privileged access and account lifecycle management.
Data handling
Policy wording for storing, sharing, retaining and disposing of sensitive business and client information.
BYOD and remote work
Guidance for personal devices, remote access, mobile security and working away from the office.
Supplier risk
Questions and controls for third-party systems, outsourced services and vendors that handle business data.
Use the resources sensibly
Template wording is only a starting point. Each organisation needs to consider its own systems, regulatory obligations, client data, staff capability and risk appetite before adopting a policy.
AICS can assist where a policy needs to be tailored, where a board requires a governance framework, or where an organisation needs help turning policy wording into practical controls.
Need a policy that fits your organisation?
AICS can help convert plain English policy resources into a tailored cyber security governance framework for your environment.
