Information Security Classification Policy: 1. Strategic Plan Theme and Compliance Obligation Supported 2. Purpose
Information Security Classification Policy: 1. Strategic Plan Theme and Compliance Obligation Supported 2. Purpose
2. PURPOSE
The Information Security Classification Policy provides a framework to assist members of the
University Community assess and label the sensitivity and importance of University information.
3. POLICY STATEMENT
3.1 All University information will be assigned an Information Security category so that it will be
managed and secured in a manner appropriate with its sensitivity and importance.
Information Security Categories
3.2 University Information will be assigned one the the following categories:
Public Information that has been authorised for public access and
circulation, or deemed public by legislation or routine disclosure. This
includes, but is not limited to, prospective students course outlines,
the academic calendar and Curtin's public website.
For Official Use Only Information intended for internal Curtin use only. This includes, but is
not limited to, staff meeting minutes, information on routine building
maintenance, room booking information.
Confidential: Legal Information relating to legal advice provided between Counsel and
their client.
Confidential:Personal Information that is for internal Curtin use only and, if released, could
be expected to cause limited damage to the University (according to
the University’s Risk Appetite), individuals, or Australia’s National
Interest. Used for information that is deemed sensitive personal
information as defined in the Australian Privacy Act 1988 or that
relates to staff or student discipline or other confidential human
resource matters.
Confidential Confidential information that does not meet the usage requirements
for the other categories listed in this table. This may include
information relating to research, commercial activities, University
committees and other matters.
4. SCOPE OF POLICY
This policy applies to the Curtin Community, including Council members, students, staff, University
Associates, Curtin controlled entities, and all persons participating in University business or activities,
including whether as a visitor, adjunct appointee, service provider, contractor or volunteer who
manages Curtin information.
5. DEFINITIONS
(Note: Commonly defined terms are located in the Curtin Common Definitions. Any defined terms below are
specific to this document)
Information Security Classification
A process where the creator of University Information assesses the sensitivity and importance of the
information and assigns a label to the information so that it can be managed or stored with
consideration to its sensitivity and importance.
Protective Labels
Protective Labels are physical or electronic labels attached to information that specify the Information
Security Category and level of sensitivity assigned to the information. The label indicates both the
level of damage that would result from the unauthorised release of the information and indicates
where information may require special handling and limited distribution.
University Information
Any information, irrespective of format, that is created, collected, generated, received, maintained or
used in the course of carrying out Curtin’s functions and activities or in the transaction of Curtin
business.
6. SUPPORTING PROCEDURES
N/A
7. RELATED DOCUMENTS/LINKS
State Records Act 2000
Evidence Act 1906
Freedom of Information Act 1992
Criminal Code 1913
Electronic Transactions Act 2011
Australian/International Records Management Standard ISO/AS 15489 Information Security
Management System ISO/IEC AS/NZS 27001
Information Management Policy
Information and Communication Technology (ICT) Appropriate Use Procedures
Curtin Information Statement
Australian Privacy Principles (under Commonwealth Privacy Act 1988)
Information Security Classification Decision Matrix
Information Security Classification Flowchart
G50-746-355 2
June 2020 (Admin)
Sue Aldenton, Associate Director, Curtin Information
Policy Compliance Officer
Management and Archives
REVISION HISTORY
Approved/ Approval /
Committee / Board /
Version Amended/ Date Resolution Key Changes & Notes
Executive Manager
Rescinded Number
Attachment A to Item 10
Planning and Management (previously titled Information
Approved 27/03/2018 PMC 31/18
Committee Security Classification Policy and
Procedures)
G50-746-355 3
June 2020 (Admin)