Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibrarySocial Media Usage Policy
Contents & downloads
Purpose
This policy establishes Westlink Logistics’ requirements for the appropriate use of social media. It protects the organisation’s reputation, safeguards confidential and security-classified information, mitigates social engineering risks, and ensures compliance with information security obligations under the ISM and DISP frameworks.
Scope
This policy applies to all Westlink Logistics directors, workers, contractors, and labour hire workers. It covers all social media platforms including Facebook, LinkedIn, X, Instagram, TikTok, YouTube, Reddit, online forums, blogs, and messaging platforms with public-facing features. It applies to both business and personal use where there is a connection to Westlink’s operations, clients, or personnel.
Organisational Context
Westlink Logistics operates heavy haulage, project logistics, and maritime services across Australia, primarily supporting defence, government, resources, and infrastructure sectors. Workers may have access to security-classified information, client-sensitive project details, and operational information that could be exploited through social engineering if disclosed on social media.
The organisation holds DISP membership requiring personnel security standards, and is subject to JOSCAR pre-qualification including information security requirements. Social media usage is a recognised vector for insider threat, social engineering, and inadvertent disclosure of classified or sensitive information.
Policy Commitments
Westlink Logistics requires that:
-
No confidential business information, client details, contract specifics, project locations, cargo descriptions, vessel movements, or information classified under the PSPF or DISP is disclosed on social media. No photographs or videos from operational sites or client facilities are posted without prior written approval.
-
Workers holding or seeking Australian Government security clearances exercise heightened caution. Social media activity may be considered during security vetting and ongoing suitability assessments under DISP personnel security requirements.
-
Workers limit work-related information visible on personal social media profiles, configure privacy settings to restrict visibility, and treat unsolicited connection requests from unknown individuals with caution, reporting suspicious contacts to the QHSE Manager.
-
Official Westlink social media accounts are managed only by authorised personnel. When expressing personal opinions online, workers must make clear the views are their own and not those of Westlink Logistics.
-
Westlink may monitor use of social media on company devices and networks for security and compliance purposes. Breaches may result in disciplinary action and, where security-classified information is involved, referral to relevant authorities.
Responsibilities
| Role | Responsibility | When |
|---|---|---|
| Chief Executive Officer | Accountable for this policy. Ensures social media practices are consistent with information security and DISP obligations. | Ongoing; annual management review |
| QHSE Manager | Implements this policy. Provides social media awareness training. Investigates reported breaches. Maintains records of social media security incidents. | Ongoing; on report received |
| Managers and Supervisors | Ensure their teams are aware of social media risks and comply with this policy. Approve site photography requests where authorised. | Ongoing; on request |
| All Workers and Contractors | Exercise sound judgement in social media activity. Comply with this policy. Report suspected security incidents or suspicious contacts. | Ongoing; on suspicion |
Review
This policy is reviewed annually as part of the management review cycle, or following a social media security incident, significant change to ISM or DISP requirements, or emergence of new platforms presenting novel risks. This policy is communicated to all workers at induction and is available on the WMS.
Applicable Standards and Legislation
-
Australian Government Information Security Manual (ISM) — ACSC
-
Defence Industry Security Program (DISP) — Security Governance Framework
-
Protective Security Policy Framework (PSPF)
-
Fair Work Act 2009 (Cth)
-
Privacy Act 1988 (Cth)
-
ISO 9001:2015 Quality Management Systems — Requirements
Related Documents
-
TEC-POL-001 Information Security Policy
-
GOV-POL-006 Workplace Behaviour Policy
-
GOV-POL-015 Privacy Policy
-
DEF-POL-001 Security Policies and Plans
Compliance coverage — cited by 11 requirements across 4 frameworks
DSPF Principle 16 / Control 16.1 / Annex A(3)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| DSPF-A16.1-entry-gov-04 | A16.1-entry-gov-04 | Full | §Policy CommitmentsSocial Media Usage Policy — commits to social engineering awareness. | |
| DSPF-A16.1-entry-gov-08 | A16.1-entry-gov-08 | Partial | §Organisational ContextSocial Media Usage Policy — commits to classified information risk. | |
| DSPF-A16.1-L1-pers-01 | A16.1-L1-pers-01 | Not Applicable | §Organisational ContextSocial Media Usage Policy — commits to classified information risk; clearance holder heightened caution. |
ISO 9001:2015(6)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-5.1.1-01 | 5.1.1 | Partial | Low | §ResponsibilitiesSocial Media Usage Policy — commits to CEO accountable for policy. |
| ISO9001-2015-5.2.2-01 | 5.2.2 | Partial | §ReviewSocial Media Usage Policy — commits to Available on WMS. | |
| ISO9001-2015-5.3-01 | 5.3 | Full | §ResponsibilitiesSocial Media Usage Policy — commits to training and incident management. | |
| ISO9001-2015-7.3-01 | 7.3 | Full | Social Media Policy covers one aspect of awareness. | |
| ISO9001-2015-7.4-01 | 7.4 | Full | §ScopeSocial Media Usage Policy — commits to Available on WMS; all platforms, business and personal use; official accounts and personal opinions. | |
| ISO9001-2015-9.3.1-01 | 9.3.1 | Full | §ReviewSocial Media Usage Policy — commits to Annual review. |
JOSCAR-AU 2026(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.11.11 | Q2.11.11 | Full | §Policy CommitmentsSocial Media Usage Policy — commits to social engineering awareness; training and incident management. |
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP11-01 | APP 11.1 | Full | §Policy CommitmentsSocial Media Usage Policy — commits to monitoring and consequences. |
Declared compliance references (11)
DSPF-A16.1-L1-pers-01DSPF-A16.1-entry-gov-04DSPF-A16.1-entry-gov-08ISO9001-2015-5.1.1-01ISO9001-2015-5.2.2-01ISO9001-2015-5.3-01ISO9001-2015-7.3-01ISO9001-2015-7.4-01ISO9001-2015-9.3.1-01JOSCAR-Q2.11.11PRV-APP11-01
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 24/05/2021 | WLK-GBL-GOV-POL-016 | Social Media Usage Policy | CEO (JDG) | CEO (JDG) |
| 2 | 09/03/2026 | GOV-POL-016 | Social Media Usage Policy | FTM (CF) | CEO (JDG) |
| 3 | 16/03/2026 | GOV-POL-016 | Social Media Usage Policy | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 3 | Added Organisational Context section — identifies insider threat and social engineering as key risks given Westlink's access to classified/sensitive information in defence work.• Consolidated 5 sub-headed sections (General, DISP, Social Engineering, Personal Use, Monitoring) into 5 focused policy commitments. Detailed guidance belongs in a social media procedure or security awareness training.• Merged photography prohibition into the information disclosure commitment — single prohibition covering all forms of unauthorised disclosure.• Responsibilities converted from paragraphs to 3-column table — added site photography approval authority for managers.• Updated terminology: 'employee' to 'worker' throughout.• Curated cross-references — retained TEC-POL-001 (InfoSec), GOV-POL-006 (Behaviour), DEF-POL-001 (SPP). Added GOV-POL-015 (Privacy). Removed people-policy cluster refs (009, 010, 011, 014) and operational docs (HR-PRO-001, TEC-PRO-001) as not directly relevant to social media.• Removed JOSCAR as standalone applicable standard — retained in org context.• Added requirements traceability matrix. |