Information Security Policy
Purpose
This policy outlines PhysioPlay’s commitment to safeguarding digital assets, infrastructure, and information. It establishes the standards for responsible use of technology, management of data and intellectual property, and protection against unauthorised access, fraud, malware, or other cyber threats. It also sets expectations for responsible use and care of all organisational Information & Communication Technology (ICT) equipment and systems.
Policy Background
Information and technology are essential to how we operate. With increasing risks such as cyberattacks, misuse of data, and poor digital hygiene, we require strong governance. This policy aligns with legal obligations and best practice frameworks to ensure our systems, data, and users are protected, and any misuse is addressed swiftly and appropriately.
Authority
This policy is issued under the authority of the Directors of PhysioPlay. It forms part of the organisation’s governance framework and supports compliance with applicable Commonwealth and state legislation, including but not limited to:
· Privacy Act 1988 (Cth)
· Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 (Cth)
· Copyright Act 1968 (Cth)
· Relevant state and territory records and privacy legislation
Company governance frameworks, policies, procedures, codes of conduct, and any relevant enterprise agreements or industrial instruments also apply.
Applicability/Scope
This policy applies to all employees, contractors, volunteers, labour-hire workers, board members and third parties who have access to PhysioPlay’s systems, equipment, data or software. It covers:
Use of all ICT assets, including laptops, headsets, phones, mobile devices and peripherals
Use of all internal networks, cloud systems, software and platforms
Management and sharing of digital content, files, and intellectual property
Remote access or hybrid working arrangements
Cybersecurity breaches, including viruses, spam, scams, phishing or data loss
Loss, damage or misuse of equipment or organisational data
Definitions
ICT Assets
Refers to all digital and technology-related equipment, software, data systems, and communication tools owned, leased, or managed by PhysioPlay. These assets are provided to enable employees and contractors to perform their work efficiently, securely, and in alignment with the organisation’s operational needs and legal obligations.
ICT Assets include, but are not limited to:
· Mobile devices – mobile phones, tablets, smart devices, and portable communication tools
· Computers and hardware – desktop computers, laptops, servers, docking stations, and data storage devices (e.g. USBs or external drives)
· Peripherals – monitors, dual screens, keyboards, mice, webcams, printers, and charging cables
· Audio-visual equipment – headsets, microphones, speakers, and earpods used for remote communication or hybrid meetings
· Networking and telephony equipment – modems, routers, desk phones, and other tools required to access internet and organisational systems
· Software and cloud systems – all licensed applications, enterprise software (e.g. Microsoft 365, CRMs), file-sharing platforms, antivirus and encryption software, and approved third-party systems
· Company-owned data and intellectual property stored or transmitted via the above systems
Information Asset
Any data or digital content that has value to the organisation, including customer or staff information, policies, records or intellectual property belonging to or managed by the organisation.
Cybersecurity Incident
Any event that compromises or threatens system integrity, confidentiality or availability (e.g. phishing, malware, ransomware).
Malware
Malicious software such as viruses, ransomware, spyware or Trojans designed to damage or disrupt systems.
Intellectual Property (IP)
Any creations of the mind - including documents, designs, policies, procedures, training materials and software, that belong to PhysioPlay.
Access Control
Limiting access to systems or data based on role, function and authorisation level.
Responsible Use
Using systems and devices lawfully, ethically, and in a way that protects data and avoids harm to others or the organisation.
Policy Objectives
The objectives of this policy are to:
Prevent unauthorised access or disclosure of sensitive data
Promote responsible use and care of ICT equipment and intellectual property
Ensure compliance with relevant legislation
Minimise cyber security risks and manage breaches effectively
Foster accountability in the management and use of all ICT resources
Policy Statements
PhysioPlay maintains that:
All ICT systems and data are organisational assets, not private property
All use must be lawful, respectful, and aligned with professional standards
Systems and devices may be monitored for compliance and security
Misuse, theft or damage of property will be investigated and may result in cost recovery, disciplinary action or reporting to authorities
Policy Requirements
A. Use of ICT Assets and Equipment
All employees, contractors, and authorised users are responsible for the appropriate care, use, and return of PhysioPlay ICT assets. This includes, but is not limited to: laptops, mobile phones, tablets, headsets, microphones, monitors, docking stations, keyboards, mice, chargers, and any other company-issued devices or accessories.
Users must:
Take reasonable care to prevent loss, damage, or misuse of equipment.
Secure devices at all times when not in use, including during travel and off-site work.
Use protective equipment (e.g. padded cases, screen protectors) where issued or advised.
Promptly report lost, stolen, damaged or malfunctioning equipment to ICT Services.
Return all ICT assets, accessories and passcodes in good working condition upon termination of employment or engagement.
The organisation reserves the right to seek recovery of repair or replacement costs where assets are lost, damaged, or misused due to gross negligence, intentional misuse, unauthorised modification, or failure to follow usage protocols. Disciplinary action may also apply, up to and including termination.
B. Acceptable Use of ICT Systems and Services
ICT systems must be used in a lawful, ethical, and professional manner that protects the interests of PhysioPlay, its employees, clients and partners.
Users must:
Access systems only for authorised, work-related purposes unless specific personal use is approved.
Refrain from using ICT systems to store, transmit or access offensive, illegal, defamatory, pirated or inappropriate content.
Not download or install unauthorised applications or software.
Not disable, bypass or interfere with monitoring, firewall, antivirus or system security settings.
Avoid storing organisational data on personal devices, unless specifically authorised under a secure BYOD policy.
Use of email, internet, social media, and collaboration platforms must align with the organisation’s Code of Conduct and Digital Communication Standards. Misuse may result in disciplinary action or revocation of access.
C. Cyber Security, Passwords and Access Control
To maintain the integrity of organisational systems and protect against cyber threats, users must:
Use strong, unique passwords and change them regularly.
Never share passwords, credentials or personal access codes.
Enable multi-factor authentication (MFA) where available.
Lock screens when devices are left unattended.
Complete all required cybersecurity and information protection training.
Users are strictly prohibited from allowing others to use their login credentials or accessing systems under another person’s account.
D. Data Privacy, Confidentiality and Intellectual Property
All information created, stored or transmitted using organisational systems remains the property of PhysioPlay unless otherwise agreed in writing.
Users must:
Treat all personal, health, financial, and commercially sensitive data as confidential.
Only access confidential data where there is a genuine business need and within the scope of their role.
Use only approved file-sharing platforms and cloud services for data storage or transmission.
Not copy, reuse, export or disclose intellectual property externally without formal written approval.
Report any known or suspected privacy breaches or unauthorised disclosures immediately.
Breach of data protection obligations may result in disciplinary action and/or mandatory reporting under applicable privacy legislation (e.g. Notifiable Data Breaches Scheme under the Privacy Act 1988).
E. Incident and Breach Reporting
All suspected or actual ICT security incidents must be reported immediately to the designated cybersecurity contact.
Incidents include, but are not limited to:
Malware or virus alerts
Phishing attempts
Ransomware or cyber extortion
Unauthorised access or system compromise
Lost, stolen or tampered devices
Accidental data exposure or sending information to an incorrect recipient
The organisation reserves the right to restrict access, isolate devices, suspend accounts, or report incidents to external authorities (e.g. the Australian Cyber Security Centre or OAIC) in the event of a serious breach.
Eligibility Criteria
This policy applies to all personnel who are issued equipment or granted access to organisational networks, systems, or data. This includes employees, interns, casuals, contractors, and third-party vendors.
Policy Exemptions
Any exceptions must be approved by the Head of ICT with documented reasoning. Exceptions must be time-bound and reviewed periodically.
Roles and Responsibilities
Employees/Users
- Use organisational ICT assets and systems only for approved, lawful and ethical purposes.
- Take reasonable steps to protect devices and data under their control.
- Keep login credentials secure and avoid unauthorised sharing or installation of unapproved software.
- Promptly report any loss, damage, suspicious activity, data breach, or cyber threat.
- Participate in all required ICT security and privacy training programs.
Executive Leadership
- Ensure organisational compliance with legal and regulatory ICT obligations (e.g. Privacy Act 1988, state-based public records acts).
- Provide appropriate resources for implementation of ICT security systems and training.
- Foster a culture of accountability, transparency, and cyber risk awareness at the leadership level.
Managers/ Team Leaders
- Model appropriate ICT and information-handling behaviours in their teams.
- Ensure team members understand and adhere to policy requirements and complete relevant training.
- Ensure assets are stored, protected and returned appropriately for remote or hybrid workers.
- Report any potential breaches, device loss, or employee misuse to ICT Services or People & Culture.
ICT Services
- Develop, maintain and enforce policies, procedures, and protocols relating to information security, privacy and asset management.
- Monitor systems and infrastructure for vulnerabilities, threats, breaches, and non-compliance.
- Respond to and investigate reported ICT incidents or breaches in line with the incident management procedure.
- Provide training, technical support, and advice to all users on secure and compliant technology use.
- Manage ICT asset registers, system access logs, and password/authentication systems.
Policy Monitoring and Compliance
To ensure this policy remains effective, PhysioPlay will implement a robust approach to monitoring, auditing, and enforcing ICT compliance.
Monitoring Activities
System Audits: Regular audits will be conducted on ICT systems, access logs, device usage, and application controls.
Asset Reviews: An asset register will be maintained, and spot checks may occur to confirm the proper care and return of organisational equipment.
Security Monitoring: Automated tools may be used to detect unauthorised access, malware activity, or inappropriate system use.
Training Compliance: Completion of required cybersecurity or privacy modules will be monitored and enforced by ICT and People & Culture.
Incident Reporting and Analysis: All reported incidents will be reviewed, categorised and tracked to identify patterns and opportunities for improvement.
Enforcement and Consequences
Breaches of this policy — including failure to report incidents, careless use of equipment, unauthorised data sharing or misuse of systems — may result in disciplinary action up to and including termination of employment or contract.
Where loss or damage occurs due to wilful misconduct, gross negligence or failure to comply with reasonable care obligations, [Insert Organisation Name] may seek to recover repair or replacement costs via lawful means.
Significant data breaches may also trigger notification obligations to external regulators such as the Office of the Australian Information Commissioner (OAIC) or the Australian Cyber Security Centre (ACSC).
Review and Amendment
This policy is reviewed every 2 years or earlier in response to legislative or operational changes.