Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryUser Access Management Policy
Contents & downloads
Purpose
This policy establishes Westlink Logistics’ requirements for managing user access to information systems, applications, and data. It ensures access is granted, modified, and revoked on a need-to-know and least privilege basis in accordance with the ISM, DISP, and ISO 27001:2022.
Scope
This policy applies to all Westlink Logistics information systems, cloud services, applications, and data repositories. It covers all users including directors, workers, contractors, and third parties with access to Westlink systems. It supplements TEC-POL-001 (Information Security Policy) with specific access management requirements.
Organisational Context
Westlink Logistics is a fully cloud-based Microsoft 365 organisation. Identity and access management is centred on Microsoft Entra ID (formerly Azure AD). The organisation holds DISP membership and handles information up to OFFICIAL:Sensitive, requiring access controls aligned with ISM requirements and Essential Eight Maturity Level 2 (restrict administrative privileges, application control).
The workforce includes office-based, field, and remote workers across multiple states, with contractors and third parties requiring varying levels of system access. JOSCAR pre-qualification requires demonstrated access management controls.
Policy Commitments
Westlink Logistics is committed to:
-
Managing the full account lifecycle: user accounts are created only on authorised request with manager approval, modified when roles change, suspended immediately on notification of leave or investigation, and revoked within one business day of termination or cessation of engagement.
-
Requiring multi-factor authentication (MFA) for all users on all cloud services, remote access, and systems processing OFFICIAL or OFFICIAL:Sensitive information. Passwords must meet minimum complexity and length requirements per ISM guidelines. Shared or generic accounts are prohibited.
-
Applying role-based access control with least privilege. Privileged and administrative access is restricted to named individuals, subject to enhanced logging, and reviewed quarterly. Separation of duties is applied to prevent any single user from controlling critical functions end-to-end.
-
Conducting formal access reviews at least every 12 months for all users, quarterly for privileged accounts, and immediately on role change, transfer, or termination. Access rights that are no longer required must be revoked promptly.
-
Maintaining access logs for all system authentication and authorisation events. Logs must be retained for the period specified by ISM and must be available for security incident investigation and compliance audit.
Responsibilities
| Role | Responsibility | When |
|---|---|---|
| Chief Executive Officer | Accountable for this policy. Ensures access management is resourced and effective. | Ongoing; annual management review |
| Security Officer (QHSE Manager) | Administers access controls in Entra ID. Conducts access reviews. Investigates access-related incidents. Reports on access management metrics. | On request; quarterly reviews; on incident |
| Managers and Supervisors | Authorise access requests for their workers. Notify the Security Officer of role changes, transfers, and terminations promptly. | On onboarding/change/exit |
| All Users | Protect credentials. Do not share accounts or passwords. Report suspected unauthorised access immediately. Complete MFA enrolment. | Ongoing; on suspicion |
Review
This policy is reviewed annually as part of the management review cycle, or when significant changes occur to the identity platform, ISM requirements, or following an access-related security incident. This policy is communicated to all users and is available to Defence and JOSCAR assessors on request.
Applicable Standards and Legislation
-
Australian Government Information Security Manual (ISM) — ACSC
-
Protective Security Policy Framework (PSPF)
-
Defence Industry Security Program (DISP) — Security Governance Framework
-
ISO/IEC 27001:2022 Information Security Management Systems — Requirements
-
ISO 9001:2015 Quality Management Systems — Requirements
Related Documents
-
TEC-POL-001 Information Security Policy
-
GOV-POL-015 Privacy Policy
-
DEF-POL-001 Security Policies and Plans
Compliance coverage — cited by 18 requirements across 4 frameworks
DSPF Principle 16 / Control 16.1 / Annex A(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| DSPF-A16.1-entry-cyber-01 | A16.1-entry-cyber-01 | Partial | User Access Management Policy addresses E8 mitigation strategy 6 (Restrict admin privileges) and strategy 5 (User application hardening — partial). |
Essential Eight Maturity Model — Maturity Level Two(13)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-01 | ML2-MFA-01 | Full | User Access Management Policy requires MFA for all users on all cloud services and remote access. | |
| E8-ML2-MFA-02 | ML2-MFA-02 | Partial | Medium | User Access Management Policy requires MFA for all users on cloud services; distinction between first-party and third-party services not explicitly addressed. |
| E8-ML2-MFA-03 | ML2-MFA-03 | Partial | Low | User Access Management Policy requires MFA broadly on cloud services. |
| E8-ML2-MFA-07 | ML2-MFA-07 | Full | User Access Management Policy requires MFA for all users; privileged access restricted to named individuals with enhanced logging. | |
| E8-ML2-MFA-08 | ML2-MFA-08 | Full | User Access Management Policy requires MFA for all users on all cloud services. | |
| E8-ML2-MFA-09 | ML2-MFA-09 | Partial | Medium | User Access Management Policy requires MFA; specific factor-type combinations not stipulated. |
| E8-ML2-MFA-13 | ML2-MFA-13 | Partial | Medium | User Access Management Policy requires access logs for all system authentication and authorisation events, retained per ISM guidance. |
| E8-ML2-RAP-01 | ML2-RAP-01 | Partial | Medium | User Access Management Policy requires user accounts to be created only on authorised request with manager approval; privileged access restricted to named individuals. |
| E8-ML2-RAP-02 | ML2-RAP-02 | Partial | Medium | User Access Management Policy requires formal access reviews at least every 12 months for all users, and quarterly for privileged accounts. |
| E8-ML2-RAP-04 | ML2-RAP-04 | Partial | Medium | User Access Management Policy requires privileged access restricted to named individuals; shared or generic accounts are prohibited. |
| E8-ML2-RAP-06 | ML2-RAP-06 | Partial | Medium | User Access Management Policy applies least privilege with role-based access control. |
| E8-ML2-RAP-13 | ML2-RAP-13 | Partial | Medium | User Access Management Policy requires access logs for all system authentication and authorisation events; privileged access subject to enhanced logging. |
| E8-ML2-RAP-14 | ML2-RAP-14 | Partial | Medium | User Access Management Policy requires access logs for authentication and authorisation events. |
JOSCAR-AU 2026(3)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.11.5 | Q2.11.5 | Partial | High | User Access Management Policy. |
| JOSCAR-Q2.11.6 | Q2.11.6 | Full | User Access Management Policy. | |
| JOSCAR-Q2.11.19 | Q2.11.19 | Partial | High | User Access Management Policy addresses MFA. |
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP11-01 | APP 11.1 | Full | User Access Management Policy addresses access control (APP 11 unauthorised access dimension). |
Declared compliance references (18)
DSPF-A16.1-entry-cyber-01E8-ML2-MFA-01E8-ML2-MFA-02E8-ML2-MFA-03E8-ML2-MFA-07E8-ML2-MFA-08E8-ML2-MFA-09E8-ML2-MFA-13E8-ML2-RAP-01E8-ML2-RAP-02E8-ML2-RAP-04E8-ML2-RAP-06E8-ML2-RAP-13E8-ML2-RAP-14JOSCAR-Q2.11.19JOSCAR-Q2.11.5JOSCAR-Q2.11.6PRV-APP11-01
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 16/03/2026 | TEC-POL-002 | User Access Management Policy | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | New document — no prior version. Created to provide detailed access management requirements supplementing TEC-POL-001. |