Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryInformation Security Policy
Contents & downloads
Purpose
This policy establishes Westlink Logistics’ framework for protecting the confidentiality, integrity, and availability of all information assets. It supports compliance with the Defence Industry Security Program (DISP), the Australian Government Information Security Manual (ISM), the Protective Security Policy Framework (PSPF), and JOSCAR information security requirements.
Scope
This policy applies to all Westlink Logistics directors, officers, workers, contractors, and third parties who access, process, store, or transmit information on behalf of the organisation. It covers all information assets regardless of format, including electronic data, physical documents, verbal communications, and information held by third-party service providers.
Organisational Context
Westlink Logistics operates heavy haulage, project logistics, and maritime services across Australia, primarily supporting defence, government, resources, and infrastructure sectors. The organisation handles OFFICIAL and OFFICIAL:Sensitive information from Defence and government clients and is authorised under DISP to handle information up to OFFICIAL:Sensitive.
Westlink is a fully cloud-based Microsoft 365 organisation with no on-premises infrastructure. The information security framework is aligned with ISO 27001:2022, Essential Eight Maturity Level 2, and ISM controls appropriate to the OFFICIAL:Sensitive ceiling. JOSCAR pre-qualification requires demonstrated information security controls and cyber security maturity.
Policy Commitments
Westlink Logistics is committed to:
-
Classifying and handling all information per the PSPF protective marking scheme (UNOFFICIAL, OFFICIAL, OFFICIAL:Sensitive). Information above OFFICIAL:Sensitive must not be stored, processed, or transmitted on Westlink systems without Defence Security Authority approval. Personnel must apply correct markings at creation.
-
Controlling access to information on a need-to-know and least privilege basis. Multi-factor authentication is mandatory for all remote access, cloud services, privileged accounts, and systems processing OFFICIAL:Sensitive information. Access rights are reviewed at least every 12 months and revoked on role change or termination.
-
Requiring pre-employment screening proportionate to information sensitivity. Personnel accessing Defence classified information must hold an appropriate AGSVA security clearance sponsored through DISP. All workers must complete information security awareness training at commencement and annually.
-
Maintaining ICT security controls aligned with Essential Eight ML2 and ISM requirements: endpoint protection, patch management (critical/high within 48 hours for internet-facing systems), encryption of data at rest and in transit (TLS 1.2+), regular backups with restoration testing, and restricted use of removable media.
-
Reporting all security incidents immediately to the Security Officer. Incidents involving Defence classified information must be reported to the Defence Industry Security Office per DISP timeframes. Data breaches involving personal information are managed per GOV-POL-015 and the NDB scheme. Ransomware or cyber extortion payments made by or on behalf of Westlink are reported to the Australian Signals Directorate via ReportCyber within 72 hours of payment in accordance with Cyber Security Act 2024 (Cth) Part 3.
-
Assessing third parties and suppliers for information security risk before engagement. Contracts must include security requirements commensurate with information classification. Third parties handling OFFICIAL:Sensitive must hold DISP membership or equivalent accreditation.
Responsibilities
| Role | Responsibility | When |
|---|---|---|
| Chief Executive Officer | Accountable for information security governance. Ensures adequate resources for the information security framework. | Ongoing; annual management review |
| Security Officer (QHSE Manager) | Day-to-day information security management. Risk assessment, incident response, DISP reporting, compliance monitoring, awareness training, and security clearance administration. | Ongoing; on incident; quarterly reporting |
| Managers and Supervisors | Implement information security controls within their areas. Ensure workers understand classification and handling requirements. | Ongoing; on new project/engagement |
| All Workers, Contractors, and Third Parties | Comply with this policy. Apply correct classification markings. Report security incidents immediately. Complete required training. | Ongoing; on incident |
Review
This policy is reviewed annually as part of the management review cycle, or when significant changes occur to the threat environment, ISM, PSPF, DISP requirements, or following a significant security incident. This policy is communicated to all workers and is available to Defence, JOSCAR assessors, and other stakeholders on request.
Applicable Standards and Legislation
-
Australian Government Information Security Manual (ISM) — ACSC
-
Protective Security Policy Framework (PSPF)
-
Defence Industry Security Program (DISP) — Security Governance Framework
-
ISO/IEC 27001:2022 Information Security Management Systems — Requirements
-
Privacy Act 1988 (Cth)
-
Cyber Security Act 2024 (Cth) — No. 98, 2024
-
ISO 9001:2015 Quality Management Systems — Requirements
Related Documents
-
TEC-POL-002 User Access Management Policy
-
GOV-POL-015 Privacy Policy
-
GOV-POL-016 Social Media Usage Policy
-
DEF-POL-001 Security Policies and Plans
-
QHSE-PRO-001 Hazard and Incident Reporting and Investigation Procedure
Compliance coverage — cited by 38 requirements across 5 frameworks
Cyber Security Act 2024 (Cth)(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| CSA-RR-02 | Cyber Security Act 2024 s.27 (mandatory ransomware payment report) | Full | §Policy CommitmentsInformation Security Policy — commits to security incident response. |
DSPF Principle 16 / Control 16.1 / Annex A(5)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| DSPF-C16.1-ongoing-01 | C16.1-ongoing-01 | Partial | Information Security Policy aligns with ISM. | |
| DSPF-C16.1-ongoing-02 | C16.1-ongoing-02 | Partial | §Policy CommitmentsInformation Security Policy — commits to security incident response. | |
| DSPF-A16.1-entry-gov-04 | A16.1-entry-gov-04 | Full | §ResponsibilitiesInformation Security Policy — commits to day-to-day management and DISP. | |
| DSPF-A16.1-entry-pers-01 | A16.1-entry-pers-01 | Full | §Policy CommitmentsInformation Security Policy — commits to personnel security and clearances. | |
| DSPF-A16.1-entry-cyber-01 | A16.1-entry-cyber-01 | Partial | Information Security Policy references ISM/E8 alignment at policy level. |
Essential Eight Maturity Model — Maturity Level Two(14)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| E8-ML2-PA-06 | ML2-PA-06 | Full | Information Security Policy commits to patch management (critical/high within 48 hours for internet-facing systems) — aligns with this ML2 control but specific cadence procedure not yet issued (TEC-PRO-001 planned). | |
| E8-ML2-PA-07 | ML2-PA-07 | Partial | High | Information Security Policy commits to patch management for internet-facing systems; non-critical two-week cadence not spelled out at control level. |
| E8-ML2-POS-07 | ML2-POS-07 | Partial | High | Information Security Policy commits to patch management generally; workstation one-month cadence not spelled out explicitly. |
| E8-ML2-MFA-01 | ML2-MFA-01 | Full | Information Security Policy mandates MFA for all remote access, cloud services, privileged accounts, and systems processing OFFICIAL:Sensitive. | |
| E8-ML2-MFA-02 | ML2-MFA-02 | Partial | Medium | §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA). |
| E8-ML2-MFA-07 | ML2-MFA-07 | Full | Information Security Policy mandates MFA for privileged accounts. | |
| E8-ML2-MFA-17 | ML2-MFA-17 | Full | Information Security Policy requires reporting all security incidents immediately to the Security Officer. | |
| E8-ML2-RAP-01 | ML2-RAP-01 | Partial | Medium | §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA). |
| E8-ML2-RAP-02 | ML2-RAP-02 | Partial | Medium | §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA). |
| E8-ML2-RAP-18 | ML2-RAP-18 | Full | Information Security Policy requires reporting all security incidents immediately to the Security Officer. | |
| E8-ML2-AC-12 | ML2-AC-12 | Full | Information Security Policy requires reporting all security incidents immediately to the Security Officer. | |
| E8-ML2-UAH-20 | ML2-UAH-20 | Full | Information Security Policy requires reporting all security incidents immediately to the Security Officer. | |
| E8-ML2-BAK-01 | ML2-BAK-01 | Partial | High | Information Security Policy commits to regular backups with restoration testing as part of ICT security controls aligned with Essential Eight ML2. |
| E8-ML2-BAK-03 | ML2-BAK-03 | Partial | Medium | Information Security Policy references encrypted storage and Microsoft geo-redundant multi-region hosting per organisational context. |
JOSCAR-AU 2026(14)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q1.4.7 | Q1.4.7 | Full | Information Security Policy governs handling of confidential and personal data. | |
| JOSCAR-Q1.4.10 | Q1.4.10 | Full | Information Security Policy defines the Westlink tenancy boundary; no customer system integration is in scope. | |
| JOSCAR-Q2.9.13 | Q2.9.13 | Partial | Medium | Information Security Policy — ICT security risk management. |
| JOSCAR-Q2.11.1 | Q2.11.1 | Full | Information Security Policy. | |
| JOSCAR-Q2.11.2 | Q2.11.2 | Partial | High | Information Security Policy aligns with ISM. |
| JOSCAR-Q2.11.5 | Q2.11.5 | Partial | High | Information Security Policy. |
| JOSCAR-Q2.11.5.2 | Q2.11.5.2 | Partial | Medium | Information Security Policy references classification. |
| JOSCAR-Q2.11.5.4 | Q2.11.5.4 | Full | Information Security Policy defines cyber security roles. | |
| JOSCAR-Q2.11.7 | Q2.11.7 | Partial | High | Information Security Policy commits to annual risk assessment. |
| JOSCAR-Q2.11.8 | Q2.11.8 | Partial | Medium | Information Security Policy references patch management at policy level but no dedicated Patching Policy / Procedure exists. |
| JOSCAR-Q2.11.11 | Q2.11.11 | Full | Information Security Policy requires security awareness training. | |
| JOSCAR-Q2.11.12 | Q2.11.12 | Full | Information Security Policy requires reporting of security incidents to the Security Officer. | |
| JOSCAR-Q2.11.20 | Q2.11.20 | Partial | Medium | Information Security Policy references backup at policy level. |
| JOSCAR-Q2.12.2.3 | Q2.12.2.3 | Full | Information Security Policy provides the technical controls that give effect to the safeguard commitment. |
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(4)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP11-01 | APP 11.1 | Full | Information Security Policy governs protective security controls (access management, encryption, incident response). Aligned with ISM/E8. | |
| PRV-APP11-03 | APP 11 / OAIC Guide | Partial | High | Addresses most OAIC-recommended controls. |
| PRV-NDB-01 | s.26WE — eligible data breach | Full | §Policy CommitmentsInformation Security Policy — commits to security incident response. | |
| PRV-NDB-02 | s.26WH, s.26WK, s.26WL — assessment, statement and notification | Full | §Policy CommitmentsInformation Security Policy — commits to security incident response. |
Declared compliance references (38)
CSA-RR-02DSPF-A16.1-entry-cyber-01DSPF-A16.1-entry-gov-04DSPF-A16.1-entry-pers-01DSPF-C16.1-ongoing-01DSPF-C16.1-ongoing-02E8-ML2-AC-12E8-ML2-BAK-01E8-ML2-BAK-03E8-ML2-MFA-01E8-ML2-MFA-02E8-ML2-MFA-07E8-ML2-MFA-17E8-ML2-PA-06E8-ML2-PA-07E8-ML2-POS-07E8-ML2-RAP-01E8-ML2-RAP-02E8-ML2-RAP-18E8-ML2-UAH-20JOSCAR-Q1.4.10JOSCAR-Q1.4.7JOSCAR-Q2.11.1JOSCAR-Q2.11.11JOSCAR-Q2.11.12JOSCAR-Q2.11.2JOSCAR-Q2.11.20JOSCAR-Q2.11.5JOSCAR-Q2.11.5.2JOSCAR-Q2.11.5.4JOSCAR-Q2.11.7JOSCAR-Q2.11.8JOSCAR-Q2.12.2.3JOSCAR-Q2.9.13PRV-APP11-01PRV-APP11-03PRV-NDB-01PRV-NDB-02
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 09/03/2026 | TEC-POL-001 | Information Security Policy | FTM (CF) | CEO (JDG) |
| 2 | 16/03/2026 | TEC-POL-001 | Information Security Policy | FTM (CF) | CEO (JDG) |
| 3 | 27/05/2026 | TEC-POL-001 | Information Security Policy | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 2 | Added Organisational Context section — identifies Westlink as fully cloud-based M365, OFFICIAL:Sensitive ceiling, Essential Eight ML2 target, and JOSCAR cyber maturity requirement.• Consolidated 10 sub-headed sections (Classification, Access Control, Personnel Security, Physical Security, ICT Security, Incident Response, Third Party, BCP/DR, Awareness) into 6 focused policy commitments. Detailed controls deferred to TEC-PRO-001 (Cyber Security Procedure) and future SSP.• Added Essential Eight ML2 reference in ICT commitment — aligns with DISP maturity requirements.• Responsibilities converted from paragraphs to 4-role table — Security Officer role explicitly assigned to QHSE Manager.• Removed BCP/DR and physical security as separate sections — BCP belongs in QHSE-PLN-002, physical security in future DEF-PRO-XXX. Retained security-relevant elements.• Updated terminology: 'employee' to 'worker' throughout.• Curated cross-references — retained TEC-POL-002, GOV-POL-015, GOV-POL-016, DEF-POL-001, QHSE-PRO-001. Removed training materials (DEF-PRE-001/002) and HR-PRO-001.• Removed JOSCAR as standalone standard — retained in org context.• Added requirements traceability matrix. |
| 3 | Added Cyber Security Act 2024 (Cth) Part 3 ransomware payment reporting commitment to bullet 5 (security incident reporting) — 72-hour Australian Signals Directorate notification via ReportCyber for any ransomware or cyber extortion payment.• Added Cyber Security Act 2024 (Cth) to Applicable Standards and Legislation. Closes Framing B audit finding F61 (CSA-RR-02 statutory coverage gap; in force 30/05/2025, full enforcement 01/01/2026; civil penalty $99,000 per body corporate failure). |