Cyber Security Policy resources

Policy resources

Cyber security policy resources for Australian organisations.

Plain English cyber security policy guidance for organisations that need practical rules for people, systems, suppliers and incident response.

Discuss tailored policy support Explore cyber governance

A practical starting point

A cyber security policy should be useful to the people who have to follow it. AICS resources are written for Australian organisations that need clear internal rules without starting from a foreign template or a document that is too technical to implement.

The aim is to help boards, managers, staff and advisers understand the minimum expectations for protecting information, reporting incidents and using systems responsibly.

What the resources cover

Acceptable use

Clear expectations for using business systems, email, internet access, cloud services and work devices.

Incident reporting

Plain English guidance on when staff should report suspicious emails, account compromise, data loss or cyber incidents.

Access control

Practical rules for passwords, multi-factor authentication, privileged access and account lifecycle management.

Data handling

Policy wording for storing, sharing, retaining and disposing of sensitive business and client information.

BYOD and remote work

Guidance for personal devices, remote access, mobile security and working away from the office.

Supplier risk

Questions and controls for third-party systems, outsourced services and vendors that handle business data.

Use the resources sensibly

Template wording is only a starting point. Each organisation needs to consider its own systems, regulatory obligations, client data, staff capability and risk appetite before adopting a policy.

AICS can assist where a policy needs to be tailored, where a board requires a governance framework, or where an organisation needs help turning policy wording into practical controls.

Need a policy that fits your organisation?

AICS can help convert plain English policy resources into a tailored cyber security governance framework for your environment.

Request policy support