{"module":"pspf-requirements-list","request":{"country":"au","standard":"pspf","release":"2024-10","publication":"au-pspf"},"response":{"domains":[{"label":"Part One","symbol":"GOV","title":"Governance","content":[{"content":"[ul][li]Whole of Government Protective Security Roles[\/li][li]Entity Protective Security Roles and Responsibilities[\/li][li]Security Planning, Incidents and Training[\/li][li]Protective Security Reporting[\/li][\/ul]"}]},{"label":"Part Two","symbol":"RISK","title":"Risk","content":[{"content":"[ul][li]Security Risk Management[\/li][li]Third Party Risk Management[\/li][li]Countering Foreign Interference and Espionage[\/li][li]Contingency Planning[\/li][\/ul]"}]},{"label":"Part Three","symbol":"INFO","title":"Information","content":[{"content":"[ul][li]Classifications and Caveats[\/li][li]Information Holdings[\/li][li]Information Disposal[\/li][li]Information Sharing[\/li][\/ul]"}]},{"label":"Part Four","symbol":"TECH","title":"Technology","content":[{"content":"[ul][li]Technology Lifecycle Management[\/li][li]Cyber Security Strategies[\/li][li]Cyber Security Programs[\/li][\/ul]"}]},{"label":"Part Five","symbol":"PER","title":"Personnel","content":[{"content":"[ul][li]Pre-Employment Eligibility[\/li][li]Access to Resources[\/li][li]Security Vetting Process[\/li][li]High Office Holders and their Support Staff[\/li][li]Maintenance and Ongoing Assessment[\/li][li]Separation[\/li][\/ul]"}]},{"label":"Part Six","symbol":"PHYS","title":"Physical","content":[{"content":"[ul][li]Physical Security Lifecycle[\/li][li]Security Zones[\/li][li]Physical Security Measures and Controls[\/li][li]Event Security[\/li][\/ul]"}]}],"markings":[{"symbol":"U","label":"UNOFFICIAL","impact_level":"0","impact_statement":"No business impact","damage_statement":"No damage. This information does not form part of official duty.","color":""},{"symbol":"O","label":"OFFICIAL","impact_level":"1","impact_statement":"Low business impact","damage_statement":"No or insignificant damage. This is the majority of routine information.","color":""},{"symbol":"O:S","label":"OFFICIAL: Sensitive","impact_level":"2","impact_statement":"Low to medium business impact","damage_statement":" Limited damage to an individual, organisation or government generally if compromised.","color":""},{"symbol":"P","label":"PROTECTED","impact_level":"3","impact_statement":"High business impact","damage_statement":"Damage to the national interest, organisations or individuals.","color":""},{"symbol":"S","label":"SECRET","impact_level":"4","impact_statement":"Extreme business impact","damage_statement":"Serious damage to the national interest, organisations or individuals.","color":""},{"symbol":"TS","label":"TOP SECRET","impact_level":"5","impact_statement":"Catastrophic business impact","damage_statement":"Exceptionally grave damage to the national interest, organisations or individuals.","color":""}],"applicability":[{"symbol":"ALL","description":"An entity, organisation or provider required to apply the PSPF"},{"symbol":"TAE","description":"Technical Authority Entity"},{"symbol":"DOS","description":"Department of State"},{"symbol":"AVA","description":"Authorised Vetting Agency"},{"symbol":"SSPE","description":"Shared Services Provider Entity"},{"symbol":"NCCE","description":"Non-Corporate Commonwealth Entity"},{"symbol":"CCE","description":"Corporate Commonwealth Entity"},{"symbol":"CC","description":"Commonwealth Company"},{"symbol":"NGO","description":"Non-Government Organisation"}],"framework":{"domain":[{"type":"domain","label":"Part One","name":"GOV","title":"Governance","block":[{"content":"[ul][li]Whole of Government Protective Security Roles[\/li][li]Entity Protective Security Roles and Responsibilities[\/li][li]Security Planning, Incidents and Training[\/li][li]Protective Security Reporting[\/li][\/ul]"}],"child":[{"type":"part","ident":"1","title":"Whole of Government Protective Security Roles","block":[],"child":[{"type":"chapter","ident":"1.1","title":"Departments of State","block":[{"content":"[p]Departments of State (DOS) are established by the Governor-General to conduct the core aspects of government operations. Departments of State encompass the lead entity in each portfolio, as detailed in the Department of Finance's Flipchart of Commonwealth entities and companies. These entities are denoted as DOS in the requirement ribbon[\/p]"},{"requirement":{"identifier":"pspf-0001","index":"0001.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"DOS","content":[{"content":"[p]The Department of State supports portfolio entities to achieve and maintain an acceptable level of protective security through advice and guidance on government security.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"1.2","title":"Department of Home Affairs","block":[{"content":"[p] In accordance with the Administrative Orders, the Department of Home Affairs is responsible for the administration of the PSPF. This includes responsibility for managing and coordinating policy responses to systemic security risks to government.[\/p]"}],"child":[{"type":"section","ident":"1.2.1","title":"Protective Security Directions","block":[{"content":"[p]The PSPF provides that, having considered advice from key Technical Authority Entities, the Secretary of the Department of Home Affairs may issue a Direction to Accountable Authorities to manage an unacceptable protective security risk to the Australian Government.[\/p]"},{"content":"[p]Accountable Authorities of entities that are subject to the PGPA Act must adhere to any Protective Security Directions issued by the Secretary of the Department of Home Affairs.[\/p]"},{"content":"[p]Accountable Authorities are responsible for ensuring that non-government organisations and third-party service providers who are subject to PSPF requirements under relevant deeds or agreements adhere to Protective Security Directions.[\/p]"},{"content":"[p]Protective Security Directions are made available on the PSPF website (unless security classified). Entity Chief Security Officers and Chief Information Security Officers are notified when Protective Security Directions are issued.[\/p]"},{"requirement":{"identifier":"pspf-0002","index":"0002.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority complies with all Protective Security Directions.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"1.3","title":"Technical Authority Entities","block":[{"content":"[p]Technical Authorities Entities are entities that have additional accountabilities to provide domain-specific security advice, technical standards or intelligence services in support of Australian Government protective security outcomes. These entities are denoted as TAE in the requirement ribbon.[\/p]"},{"content":"[p]See PSPF Guidelines for the current list of Technical Authority Entities.[\/p]"},{"requirement":{"identifier":"pspf-0003","index":"0003.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"TAE","content":[{"content":"[p]The Technical Authority Entity provides technical advice and guidance to support entities to achieve and maintain an acceptable level of protective security.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"1.4","title":"Shared Service Provider Entities","block":[{"content":"[p]Shared Service Provider Entities (SSPE) are non-corporate Commonwealth entities that provide corporate or technical services to other entities under an agreement or arrangement. These entities are denoted as SSPE in the requirement ribbon.[\/p]"},{"content":"[p]Existing partnership and shared-service arrangements must have clearly defined accountability, responsibilities and agreed processes for responding to change and incident management. These should be periodically reviewed to ensure accountabilities and responsibilities remain suitable and appropriate.[\/p]"},{"content":"[p]Supported entities may outsource responsibility for specific functions under shared-services or partnership arrangements, provided the Accountable Authority of the shared service provider entity agrees, but the Accountable Authority of the supported entity remains responsible for the overall security of their entity.[\/p]"},{"requirement":{"identifier":"pspf-0004","index":"0004.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"SSPE","content":[{"content":"[p]The Shared Service Provider Entity supplies security services that help relevant entities achieve and maintain an acceptable level of security.[\/p]"}]}},{"requirement":{"identifier":"pspf-0005","index":"0005.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"SSPE","content":[{"content":"[p]The Shared Service Provider Entity develops, implements and maintains documented responsibilities and accountabilities for partnerships or security service arrangements with other entities.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"1.5","title":"Authorised Vetting Agencies","block":[{"content":"[p] Security vetting is conducted to ensure personnel are eligible and suitable to access security classified government information and resources. These functions may only be performed by vetting agencies authorised to assess, process and grant security clearances (Baseline up to and including Positive Vetting security clearances) for Australian Government entities. Authorised Vetting Agencies (AVA) entities are denoted as AVA in the requirement ribbon.[\/p]"},{"content":"[p]See PSPF Guidelines for the list of Authorised Vetting Agencies.[\/p]"}],"child":[{"type":"section","ident":"1.5.1","title":"TOP SECRET-Privileged Access Authority","block":[{"content":"[p]Only the TOP SECRET-Privileged Access (TS-PA) Authority is authorised to implement requirements of the TS-PA Standard, issue TS-PA security clearances and manage the ongoing suitability of TS-PA security clearance holders.[\/p]"},{"content":"[p]This includes, but is not limited to, assessing information provided by sponsoring entities and other sources (including changes of circumstances), and conducting annual clearance reviews of all TS-PA security clearances, reviews for cause, and revalidation of TS-PA security clearances.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"1.6","title":"Sponsoring Entities","block":[{"content":"[p]Australian Government entities are authorised to sponsor Australian Government security clearances. Entities that sponsor security clearances are known as 'Sponsoring Entities' and have additional responsibilities in the vetting process and the ongoing management of security cleared personnel.[\/p]"},{"content":"[p]The Australian Government may also authorise non-government organisations to sponsor security clearances. See Sponsoring Security Clearances and PSPF Guidelines for details.[\/p]"},{"content":"[p]State and territory government agencies are also authorised to sponsor security clearances.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"2","title":"Entity Protective Security Roles and Responsibilities","block":[],"child":[{"type":"chapter","ident":"2.1","title":"Accountable Authority","block":[{"content":"[p]The Accountable Authority of a Commonwealth entity is defined under section 12 of the PGPA Act as the person or group of persons responsible for, and with control over, the entity's operations.[\/p]"},{"content":"[p]The Accountable Authority has overall responsibility for the protective security of their entity's people, information and resources, both domestically and internationally.[\/p]"},{"content":"[ul][li]People - employees and contractors, including secondees and any service provider that an entity engages. It also includes anyone who is given access to Australian Government resources held by the entity as part of entity sharing initiatives.[\/li][li]Information - physical documents\/papers, electronic\/digital data or intellectual information (knowledge) that is owned, managed or maintained by the entity. It includes details of methodologies, classified military\/intelligence activities or operations, diplomatic discussions and negotiations.[\/li][li]Resources - including applications\/technology systems\/mobile devices that process, store or communicate official and security classified information\/data, tangible assets, equipment, facilities, buildings and other spaces\/places, elements of infrastructure and intangible assets such as data centres.[\/li][\/ul]"},{"content":"[p]To achieve this they are responsible for implementing the PSPF mandatory requirements and standards and having effective protective security arrangements in place. The Accountable Authority is also responsible for implementing any Protective Security Directions issued by the Secretary of the Department of Home Affairs. See Protective Security Directions.[\/p]"},{"content":"[p]With support from their Chief Security Officer and Chief Information Security Officer, the Accountable Authority has overall responsibility for managing the entity's security risks including determining their entity's tolerance to security risks and how to identify, assess and prioritise risks to people, information and resources. They must also consider how these decisions will impact other entities and whole of government security. [\/p]"},{"content":"[p]It is critical that the Accountable Authority establishes arrangements to ensure the Chief Security Officer and the Chief Information Security Officer work together to ensure a consistent approach to protective security across the entity and to achieve the entity's security objectives.[\/p]"},{"content":"[p]Other mandatory requirements for the Accountable Authority are denoted through this policy.[\/p]"},{"requirement":{"identifier":"pspf-0006","index":"0006.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority is answerable to their minister for the entity's protective security.[\/p]"}]}},{"requirement":{"identifier":"pspf-0007","index":"0007.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority is responsible for managing the security risks of their entity.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"2.2","title":"Chief Security Officer","block":[{"content":"[p]The Chief Security Officer (CSO) is a Senior Executive Service (SES) officer responsible for oversight of the entity's protective security arrangements, with support from the Chief Information Security Officer on cyber security arrangements. Where an entity has fewer than 100 employees the Accountable Authority may appoint their CSO at the Executive Level 2 (EL2), providing the EL2 reports directly to the Accountable Authority on security matters, and has sufficient authority and capability to perform the responsibilities of the CSO role.[\/p]"},{"content":"[p]The CSO answers to the Accountable Authority and supports them by providing strategic oversight of protective security matters to assist with the continuous delivery of business operations.[\/p]"},{"content":"[p]The CSO establishes and maintains security arrangements that are tailored to the scale, complexity and risk profile of the entity and its people, information and resources. The intention is that as a single senior officer with central oversight and responsibility for security arrangements in the entity, they have the flexibility to delegate the day-to-day activities of protective security where required. The CSO is also responsible for fostering a culture where personnel have a high degree of security awareness, reinforced through practices that embed security into entity operations.[\/p]"},{"requirement":{"identifier":"pspf-0008","index":"0008.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]A Chief Security Officer is appointed and empowered to oversee the entity's protective security arrangements.[\/p]"}]}},{"requirement":{"identifier":"pspf-0009","index":"0009.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Chief Security Officer is a Senior Executive Service officer and holds a minimum security clearance of Negative Vetting 1.[\/p]"}]}},{"requirement":{"identifier":"pspf-0010","index":"0010.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Chief Security Officer is accountable to the Accountable Authority for protective security matters.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"2.3","title":"Chief Information Security Officer","block":[{"content":"[p] The Chief Information Security Officer (CISO) is accountable to the Accountability Authority and supports the CSO by providing cyber security leadership for the entity, incorporating information technology and operational technology. This includes responsibility for the entity's cyber security strategy and uplift plan and implementing the Australian Signals Directorate's Information Security Manual and Strategies to Mitigate Cyber Security Incidents.[\/p]"},{"content":"[p]If the CISO does not report directly to the CSO, they should work closely with the CSO and keep them informed, to ensure a holistic approach to security is maintained and cyber security does not become siloed from other security arrangements. This approach allows the CSO to retain a complete view of protective security across the entity.[\/p]"},{"content":"[p]The CISO may be located in another entity where the entity's cyber security services are wholly provided through a shared services arrangement with another entity. In such cases, the supported entity's Accountable Authority and CSO is required to establish suitable arrangements to retain visibility of cyber security matters.[\/p]"},{"content":"[p] The CISO needs to possess the appropriate capability, leadership experience and technical skills to perform the role and make informed cyber security decisions for the entity.[\/p]"},{"requirement":{"identifier":"pspf-0011","index":"0011.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]A Chief Information Security Officer is appointed to oversee the entity's cyber security program, including information technology and operational technology.[\/p]"}]}},{"requirement":{"identifier":"pspf-0012","index":"0012.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Chief Information Security Officer has the appropriate capability and experience and holds a minimum security clearance of Negative Vetting 1.[\/p]"}]}},{"requirement":{"identifier":"pspf-0013","index":"0013.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Chief Information Security Officer is accountable to the Accountable Authority for cyber security.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"2.4","title":"Security Practitioners","block":[{"content":"[p] Security practitioners perform security functions or specialist services to support the CSO and CISO in the day-to-day functions of protective security.[\/p]"},{"content":"[p]While not mandated, the CSO and CISO have the flexibility to delegate the day-to-day activities of protective security to security practitioners and to perform specialist services.[\/p]"},{"requirement":{"identifier":"pspf-0014","index":"0014.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Where appointed, security practitioners are appropriately skilled, empowered and resourced to perform their designated functions.[\/p]"}]}},{"requirement":{"identifier":"pspf-0015","index":"0015.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Where appointed, security practitioners have access to training across government to maintain and upskill on new and emerging security issues.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"2.5","title":"Security Governance","block":[{"content":"[p]Under the Public Governance, Performance and Accountability Rule 2014, entities are required to have an audit committee to review systems of risk oversight and management. Audit committees perform an important role in oversight of risk management, including security risks.[\/p]"},{"content":"[p]The Accountable Authority determines the entity's governance arrangements and ensures they are commensurate with the entity's size, complexity and risk environment.[\/p]"},{"requirement":{"identifier":"pspf-0016","index":"0016.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority approves security governance arrangements that are tailored to the entity's size, complexity and risk environment.[\/p]"}]}}],"child":[{"type":"section","ident":"1.5.1","title":"Security Email Address","block":[{"content":"[p]Each entity must establish, maintain and monitor a dedicated security email address and provide this address to the Department of Home Affairs (PSPF@homeaffairs.gov.au). The Department will use this address to provide entities with security-related policy advice, notifications and information and will blind copy the CSO, and where relevant the CISO.[\/p]"},{"content":"[p]Entities are to ensure this information is distributed to the relevant people and functions across the entity, including the CSO, CISO, Departmental Security Unit, Personnel Security team, Physical Security Teams, personnel involved in security reporting or incident management, and any other relevant security-related personnel or teams.[\/p]"},{"requirement":{"identifier":"pspf-0017","index":"0017.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]A dedicated security email address is established and monitored as the central conduit for distribution of protective security-related information across the entity.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"3","title":"Security Planning, Incidents and Training","block":[],"child":[{"type":"chapter","ident":"3.1","title":"Security Planning","block":[{"content":"[p]Security planning is unified and holistic, as part of a security life cycle approach. Entity security plans address all domains of protective security.[\/p]"},{"content":"[p]Security planning establishes the strategic direction and sets out the expectations for the efficient and effective security management practices in the entity. The plan also articulates how security risks will be managed effectively and consistently across the entity to adapt to change, minimise damage and disruption, and build resilience.[\/p]"},{"content":"[lt]A security plan is used to identify and manage risks and assist decision-making by:[\/lt][ul][li]adapting to change while safeguarding the delivery of core business and services[\/li][li]improving resilience to threats, vulnerabilities and emerging challenges, and[\/li][li]driving protective security performance improvements.[\/li][\/ul]"},{"content":"[p]Each entity's security plan will be different but the plan must include the mandatory elements listed in Table 1.[\/p]"},{"content":"[p]Where a single security plan is not practicable due to the entity's size or complexity of business, entities may develop an overarching security plan that is approved by the Accountable Authority, supported by more detailed plans (referred to as supporting security plans), approved by the CSO or CISO (for cyber security plans), or their delegate.[\/p]"},{"table":"[table name='Table 1' title='Security Plan Mandatory Elements'][head][cell]Plan component[\/cell][cell]Mandatory elements[\/cell][\/head][row][cell]Security goals and objectives[\/cell][cell]The security plan must detail the entity's security goals and strategic objectives, including how security risk management intersects with and supports broader business objectives and priorities.[\/cell][\/row][row][cell]Security risk environment[\/cell][cell]The security plan must detail the environment in which the entity operates; the threats, risks and vulnerabilities that impact the protection of the entity's people, information and resources.\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Risk tolerance[\/cell][cell]The security plan must detail the entity's tolerance to security risks, agreed by the Accountable Authority (see 5.1). Each entity's level of tolerance for risk will vary depending on the level of potential damage to the Australian Government or to the entity.[\/cell][\/row][row][cell]Security capability[\/cell][cell]The security plan must detail the maturity of the entity's capability to manage security risks.[\/cell][\/row][row][cell]Security risk management strategies[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Implications of risk decisions[\/cell][cell]The security plan must detail how information on the entity's risk management decisions will be shared with other entities that are, or may be, impacted by those decisions (see 5.2)[\/cell][\/row][row][cell]PSPF implementation[\/cell][cell]The security plan must the detail entity's strategies to deliver against the PSPF requirements and standards.[\/cell][\/row][row][cell]PSPF Directions[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Critical people and resources[\/cell][cell]The security plan must identify people and resources that are critical to the ongoing operation of the entity and the national interest. It must detail the protections applied to safeguard these resources to support the continuity of the entity's core business. Resources covers information, systems, assets and facilities.[\/cell][\/row][row][cell]Threat levels[\/cell][cell]The security plan must be calibrated to the security environment in which the entity operates, including the National Terrorism Threat Level and relevant ASIO reporting related to espionage, foreign interference or sabotage threats. The plan should promote flexibility and scalable security controls which can be calibrated to changes in the security environment.[\/cell][\/row][row][cell]Incident management plan[\/cell][cell]The security plan must detail entity's security incident management plan covering the procedures to ensure security incidents are identified, managed and responded to.[\/cell][\/row][row][cell]Monitoring and improvement[\/cell][cell]The security plan must detail the entity's monitoring arrangements and plans to uplift protective security improvement in areas of insufficient implementation.[\/cell][\/row][row][cell]Review[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][\/table]"},{"requirement":{"identifier":"pspf-0018","index":"0018.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]A security plan is developed, implemented and maintained to address the mandatory elements of the plan.[\/p]"}]}}],"child":[{"type":"section","ident":"3.1.1","title":"Security Plan Responsibilities","block":[{"content":"[p]The Accountable Authority has overall responsibility for managing the entity's security risks, with support from their CSO, CISO and where established, the security governance committee.[\/p]"},{"content":"[p]This obligation extends to determining their entity's tolerance to security risks and ensuring appropriate measures are in place to identify, assess and prioritise risks to people, information and resources. The Accountable Authority must also consider how these decisions will impact other entities and whole of government security.[\/p]"},{"content":"[p]The Accountable Authority must approve the entity's annual review of the security plan.[\/p]"},{"content":"[p]The CSO defines the strategic direction and allocation of resources to deliver the strategy, strengthen operations and improve the entity's security maturity in order to make sound decisions about security planning.[\/p]"},{"requirement":{"identifier":"pspf-0019","index":"0019.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority approves the entity's security plan.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"3.1.2","title":"Security Plan Review","block":[{"content":"[p]Entities must consider their security plan (and any supporting plans) annually to decide whether updates are required. Entities must also undertake a formal review of the plan at least every two years to ensure the plan is sufficient to manage the entity's security risks, able to adapt to changes in the entity's risk or operating environment, a change in the National Terrorism Threat Level or an emerging threat that alters the entity's business impact level.[\/p]"},{"content":"[p]A security plan is a 'living' document and requires review and adjustment to ensure the goals and management of security risks keep pace with changes in the entity and with emerging threats. Security plans are best developed by a person who also has an understanding of the entity's strategic goals and objectives and the appropriate level of security risk management knowledge and expertise.[\/p]"},{"content":"[p]Entities determine how the review of the security plan (and supporting security plans) is conducted, that is the process used to review the plan. The security plan must be approved by the Accountable Authority and may be reviewed by the CSO, CISO, or appointed security practitioner, an external security consultant or through a security governance oversight committee for larger or more complex business operations.[\/p]"},{"requirement":{"identifier":"pspf-0020","index":"0020.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The security plan is considered annually and reviewed at least every two years to confirm its adequacy and ability to adapt to shifts in the entity's risk, threat or operating environment.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"3.2","title":"Security Practices and Procedures","block":[{"content":"[p]Protective security practices and procedures reflect the entity's implementation of, and compliance with, the PSPF requirements and standards. Entities must develop practices and procedures to cover all elements of protective security consistent with the PSPF requirements and standards.[\/p]"},{"content":"[p]Protective security practices detail the entity's general approach to security tasks and activities. Protective security procedures set clear guidelines for entity personnel to follow and perform work functions safely, in accordance with the PSPF requirements and standards, and any additional entity requirements.[\/p]"},{"content":"[p]The CSO is responsible for the protective security practices and procedures, other than for cyber security, which are the responsibility of the CISO.[\/p]"},{"requirement":{"identifier":"pspf-0021","index":"0021.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Procedures are developed, implemented and maintained to ensure all elements of the entity's security plan are achieved.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"3.3","title":"Continuous Monitoring and Improvement","block":[{"content":"[p]Monitoring security maturity is an ongoing process and involves routine assessment of the entity's security capability, performance against a set of indicators and compliance with the PSPF requirements and standards.[\/p]"},{"content":"[p]Achieving and maintain compliance with the PSPF requirements and standards requires effective monitoring of the entity's security posture and a continuous cycle of improvement. These arrangements also assist the entity to respond to changes in its threat environment and respond to emerging security risks.[\/p]"},{"content":"[p]The entity security plan must detail the entity's monitoring arrangements and plans to uplift protective security improvement in areas of insufficient implementation.[\/p]"},{"requirement":{"identifier":"pspf-0022","index":"0022.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Develop, establish and implement security monitoring arrangements to identify the effectiveness of the entity's security plan and establish a continuous cycle of improvement.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"3.4","title":"Positive Security Culture","block":[{"content":"[p] A positive security culture is vital to effectively and securely delivering Australian Government business and safeguarding information for which the entity is the trusted custodian. It is an effective method of reducing the threat to the entity, its people, information and resources. In addition to keeping an entity and its personnel safe, a strong and healthy security culture helps to increase internal and external trust, embed consistent positive behaviour and support personnel to engage productively with risk.[\/p]"},{"content":"[p]The Accountable Authority and Chief Security Officer are ultimately responsible for fostering a positive security culture. They are supported by the Chief Information Security Officer and security practitioners to promote a culture where personnel value, use and protect entity information and resources appropriately.[\/p]"},{"requirement":{"identifier":"pspf-0023","index":"0023.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority and Chief Security Officer develops, implements and maintains a program to foster a positive security culture in the entity and support the secure delivery of government business.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"3.5","title":"Security Awareness Training","block":[{"content":"[p]Security awareness training is a vital element of fostering a positive security culture and ensuring personnel understand their protective security responsibilities and any entity-specific security obligations. It also embeds good security processes and supports the consistent application of protective security practices and procedures across the entity.[\/p]"},{"content":"[lt]Security awareness training is most effective when it:[\/lt][ul][li]is championed and practiced by senior leadership,[\/li][li]delivers an ongoing security awareness program to inform and regularly remind individuals of security responsibilities, issues and concerns,[\/li][li]briefs personnel on the access privileges and prohibitions attached to their security clearance level prior to being given access, or when required in the security clearance renewal cycle,[\/li][li]ensures that personnel who have specific security duties receive appropriate and up-to-date training,[\/li][li]fulfils security clearance renewal briefing requirements for all personnel and contracted service providers who hold a security clearance of Negative Vetting 1 or higher,[\/li][li]fulfils security clearance requirements and training obligations detailed in the TS-PA Standard,[\/li][li]clearly communicates to all personnel, including contractors, the entity's protective security practices and procedures, and[\/li][li]Provides all personnel including contractors with a clear understanding of the security environment in which the entity operates and the security threats relevant to their roles and responsibilities.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0024","index":"0024.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Security awareness training is provided to personnel, including contractors, at engagement and annually thereafter.[\/p]"}]}},{"requirement":{"identifier":"pspf-0025","index":"0025.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Targeted security training is provided to personnel, including contractors, in specialist or high-risk positions.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"3.6","title":"Security Incidents","block":[{"content":"[p]Security incident management is the process of identifying, managing, recording and analysing any irregular or adverse activities or events, threats and behaviours in a timely manner. Effective monitoring of security incidents is fundamental to good security management. In turn, good security management contains the effects of a security incident and enables recovery as quickly as possible.[\/p]"},{"content":"[lt]A security incident is defined as an:[\/lt][ul][li]action, whether deliberate, reckless, negligent or accidental that fails to meet protective security requirements or entity-specific protective security practices and procedures that results in, or may result in, the loss, damage, corruption or disclosure of official information or resources,[\/li][li]attempt to gain unauthorised access to official information or resources,[\/li][li]approach from anybody seeking unauthorised access to official resources, or[\/li][li]event that harms, or may harm the security of Australian Government people, information or resources.[\/li][\/ul]"},{"content":"[lt]A security incident becomes reportable where it is a:[\/lt][ul][li]specified significant security incident that due to its nature is considered to be significant or it meets external incident reporting or referral obligations, or[\/li][li]significant business impact level security incident that due to the assessed severity of the potential or actual consequences or damage to Australian Government security classified people, information or resources, the national interest, an organisation or individuals, is considered to be significant. A significant security incident is generally serious or complex and is likely to have wide ranging and critical consequences for the entity and\/or the Australian Government.[\/li][\/ul]"}],"child":[{"type":"section","ident":"3.6.1","title":"Security Incident Management Procedures","block":[{"content":"[p]A security incident management plan can increase the likelihood of successfully planning for, detecting and responding to malicious activity, insider threat and security incidents. The CSO, with support from the CISO for cyber security incidents, is responsible for establishing a security incident management plan, including consequence management, and incorporating into the entity's business continuity arrangements to ensure that business-critical people, operations, systems and services are supported appropriately in the event of an incident or disaster.[\/p]"},{"content":"[p]Establishing security exercises as part of security planning can increase the success of the entity's procedures for detecting and responding to security incidents, including cyber security incidents and incidents caused by trusted insiders.[\/p]"},{"content":"[p]A security exercise tests the entity's preparedness to detect, respond to and recover from all types of security incidents. It also tests whether the entity's security incident management plans and procedures are appropriate and effective.[\/p]"},{"content":"[p]See Externally Reportable Security Incidents and Referral Obligations.[\/p]"},{"content":"[p]Responsibility for investigating, responding to and reporting on security incidents sits with the CSO, with support from the CISO for cyber security incidents. The CSO develops, implements and maintains procedures to ensure security incidents are responded to and, where required appropriately investigated. The CSO also undertakes regular exercises of these arrangements.[\/p]"},{"content":"[p]Information gathered on security incidents and investigations assists the CSO, or CISO (for cyber incidents), to determine the adequacy of protective security practices, measure security culture, highlight vulnerabilities in security awareness training and inform security improvement activities.[\/p]"},{"content":"[p]The CSO and CISO are accountable to the Accountable Authority for the management of security incidents, exercises and investigations, in accordance with the PSPF and any other regulatory requirements.[\/p]"},{"requirement":{"identifier":"pspf-0026","index":"0026.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Procedures are developed, implemented and maintained to ensure security incidents are managed and responded to.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"3.6.2","title":"Coordination of Cyber Security Incidents","block":[{"content":"[p]The National Cyber Security Coordinator coordinates responses to major cyber incidents, whole of government incident preparedness efforts, and strengthens Australian Government cyber security response capability, in accordance with (AGCMF).[\/p]"},{"content":"[p]The National Cyber Security Committee (NCSC) is the mechanism for inter-jurisdictional coordination for cyber security incident response. If a national cyber security incident escalates in impact and severity, the response may require escalation in accordance with existing national crisis management arrangements. This occurs in collaboration with the National Cyber Security Coordinator and the National Emergency Management Agency, to ensure that consequence management is activated as appropriate.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"3.6.3","title":"Security Incident Management and Exercises","block":[{"content":"[p]A security incident management plan can increase the likelihood of successfully planning for, detecting and responding to malicious activity, insider threat and security incidents. The CSO, with support from the CISO for cyber security incidents, is responsible for establishing a security incident management plan, including consequence management, and incorporating into the entity's business continuity arrangements to ensure that business-critical people, operations, systems and services are supported appropriately in the event of an incident or disaster.[\/p]"},{"content":"[p]Establishing security exercises as part of security planning can increase the success of the entity's procedures for detecting and responding to security incidents, including cyber security incidents and incidents caused by trusted insiders.[\/p]"},{"content":"[p]A security exercise tests the entity's preparedness to detect, respond to and recover from all types of security incidents. It also tests whether the entity's security incident management plans and procedures are appropriate and effective.[\/p]"},{"requirement":{"identifier":"pspf-0027","index":"0027.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p] Security incident management and response plans are incorporated into the entity's business continuity arrangements.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"3.6.4","title":"Externally Reportable Security Incidents and Referral Obligations","block":[{"content":"[p]Entities must report any significant or reportable security incidents to the relevant authority.[\/p]"},{"content":"[lt]Relevant authorities fall broadly into three categories:[\/lt][ul][li]authorities able to assist with advice, containment or remediation,[\/li][li]authorities with policy or legislative responsibility, and[\/li][li]others who may be impacted by the security incident.[\/li][\/ul]"},{"content":"[p]The purpose of this reporting obligation is to ensure the entity receives assistance with containment and\/or remediation, regardless of whether the incident is considered 'significant' or not, or to comply with obligations to report to specific authorities. It further ensures the relevant authority is aware of the types and numbers of security incidents occurring with their area of responsibility.[\/p]"},{"content":"[p]The mandatory externally reportable security incidents and referral obligations are listed in Table 2. This is not an exhaustive list and there may be other legislative requirements or Government policy obligations for reporting security incidents. Some security incidents have more than one line of reporting and may require the entity to report to multiple relevant authorities.[\/p]"},{"content":"[p]Entities must report to the relevant authority within the set specific timeframes for reporting. If no timeframe is specified, then entities must report once they become aware that the security incident is occurring or has occurred.[\/p]"},{"requirement":{"identifier":"pspf-0028","index":"0028.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Procedures are developed, implemented and maintained to ensure security incidents are managed and responded to.[\/p]"}]}},{"table":"[table name='Table 2' title='Externally reportable security incidents and referral obligations'][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"3.7","title":"Security Investigations","block":[{"content":"[p]A security investigation is a formal process of examining the cause and extent of a security incident that has, or could have, caused harm to individuals, the entity, another entity or the national interest.[\/p]"},{"content":"[p]The were developed to ensure quality investigative practices and outcomes in entities.[\/p]"},{"content":"[p]Responsibility for investigating security incidents sits with the CSO, with support from the CISO for investigations into cyber security incidents.[\/p]"},{"content":"[p]Where a suspected security incident involves the compromise of security classified information or other resources that originate from, or are the responsibility of another entity, it is important to seek advice from the originating entity prior to instigating any investigation. The originating entity may have operational security requirements that need to be applied to the investigation. In some cases, it may be more appropriate that the originating or responsible entity carries out the investigation. This requirement should not prevent or delay any immediate action required to prevent further compromise of classified information.[\/p]"},{"content":"[p]See PSPF Guidelines for the security investigation process.[\/p]"},{"requirement":{"identifier":"pspf-0029","index":"0029.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Procedures are developed, implemented and maintained to investigate security incidents in accordance with the principles of the Australian Government Investigations Standards.[\/p]"}]}}],"child":[{"type":"section","ident":"3.7.1","title":"Procedural Fairness","block":[{"content":"[p] The principles of procedural fairness apply to all investigations. These principles require that individuals whose rights, interests or expectations are adversely affected, be informed of the case against them, that they be given an opportunity to be heard by an unbiased decision-maker, and to respond. This should be done in a manner that gives regard to national security considerations to the greatest extent practicable. Procedural fairness also applies to actions taken as the result of an investigation. Procedural fairness gives regard to ensuring the security integrity of any current or future investigation of the entity or of another entity.[\/p]"},{"requirement":{"identifier":"pspf-0030","index":"0030.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The principles of procedural fairness are applied to all security investigations, with due regard to national security considerations.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"4","title":"Protective Security Reporting","block":[],"child":[{"type":"chapter","ident":"4.1","title":"Security Reporting to Government","block":[{"content":"[lt]The Department of Home Affairs prepares two annual reports using the annual PSPF reporting data:[\/lt][ul][li]PSPF Assessment Report - consolidated report on the aggregated annual reporting data for the Minister for Home Affairs, Minister for Immigration and Multicultural Affairs, Minister for Cyber Security. This consolidated report is provided to entities and published on the PSPF website for public transparency.[\/li][li]PSPF Classified Assessment Report - provides the Government with entity-specific results and identifies entities not meeting the requirements and standards of the PSPF. This report also provides a heat map of protective security issues and vulnerabilities. This classified report is not made publicly available or provided to entities.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"chapter","ident":"","title":"Annual Protective Security Report","block":[{"content":"[p]Annual protective security reporting provides assurance to the Government that entities are complying with their security obligations, implementing sound and responsible protective security practices and identifying and mitigating security risks and vulnerabilities.[\/p]"}],"child":[{"type":"section","ident":"4.2.1","title":"Reporting to Ministers","block":[{"content":"[p]The Accountable Authority is responsible to their Minister for the protective security of their entity's people and resources, and must provide their Minister with an annual protective security report by December. If the entity reports to multiple Ministers, then each Minister is to receive a copy of the protective security report (or relevant extracts if that is more appropriate).[\/p]"},{"content":"[p]This report provides the Minister with assurance that entity is implementing sound and responsible protective security practices and demonstrating year on year improvement in security capability and maturity.[\/p]"},{"requirement":{"identifier":"pspf-0031","index":"0031.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The annual protective security report is provided to the entity's Minister.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"4.2.2","title":"Reporting to the Department of Home Affairs","block":[{"content":"[p]The Department of Home Affairs administers the PSPF on behalf of the Minister for Home Affairs, Minister for Immigration and Multicultural Affairs, Minister for Cyber Security.[\/p]"},{"content":"[lt]Entities must participate in the PSPF annual reporting process by completing and submitting an annual protective security report through:[\/lt][ul][li]PSPF Reporting Portal - for reports classified up to and including PROTECTED, and[\/li][li]Offline Reporting Template (submitted on the commensurate system) - for reports classified SECRET or TOP SECRET.[\/li][\/ul]"},{"content":"[p]The Department uses the annual reporting data to prepare two reports each year to Government.[\/p]"},{"content":"[p]See Security Reporting to Government.[\/p]"},{"requirement":{"identifier":"pspf-0032","index":"0032.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The annual protective security report is submitted to the Department of Home Affairs.[\/p]"}]}},{"requirement":{"identifier":"pspf-0033","index":"0033.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The Accountable Authority approves the entity's annual protective security report and confirms that they have verified the report's content.[\/p]"}]}}],"child":[{"type":"topic","ident":"4.2.2.1","title":"Protective Security Reporting Process","block":[{"content":"[p]Compliance with PSPF requirements is a fundamental element of effective and accountable governance. Compliance reporting is designed to provide reasonable assurance to the Government that entities have achieved their objective by implementing the mandatory elements of the PSPF to protect their people and resources.[\/p]"},{"content":"[lt]There are three reporting categories for each PSPF mandatory requirement:[\/lt][ul][li]Fully implemented[\/li][li]Risk managed, or[\/li][li]Not yet implemented.[\/li][\/ul]"},{"content":"[p]From these categories, the entity selects the response category that best reflects their level of implementation for the corresponding requirement. However, not all requirements will allow a risk managed response. For example implementation of PSPF Directions will require a 'Yes' or 'No' response, with a 'No' response prompting an explanation of why the Direction has not been met. The risk managed category is not intended to be enduring or long term, but rather allows the entity to put in place proportional mitigation arrangements until such time as the requirement can be fully implemented.[\/p]"},{"content":"[p]Entities employing a risk-managed approach to implementation are required to provide a summary of what prevented full implementation of the requirement during the reporting period and upload a risk management plan (or extract) detailing arrangements for managing the requirement, approved by the Accountable Authority or Chief Security Officer. The plan must be uploaded to proceed, otherwise a different reporting response ('Fully implemented' or 'Not yet implemented') must be selected.[\/p]"},{"content":"[p]See PSPF Guidelines for further information on reporting and reporting categories.[\/p]"}],"child":[],"stats":[]},{"type":"topic","ident":"4.2.2.2","title":"Protective Security Reporting Portal","block":[{"content":"[p]The PSPF Reporting Portal allows Commonwealth entities to complete and submit their annual protective security report online, access benchmarking reports at the conclusion of the reporting period, and access reports from the previous reporting period. The PSPF Reporting Portal is accredited to process, store and communicate information up to PROTECTED.[\/p]"},{"content":"[p]The entity's CSO is responsible for ensuring the entity meets the annual protective security reporting obligations. The role of the 'Submitter' in the PSPF reporting portal is automatically assigned to the CSO, however this role can be delegated to another suitable officer. The Submitter is the key contact for the entity's annual protective security report and is responsible for commencing and submitting the assessment.[\/p]"}],"child":[],"stats":[]},{"type":"topic","ident":"4.2.2.3","title":"Protective Security Reporting Quality Assurance","block":[{"content":"[p]The 2023-2030 Australian Cyber Security Strategy initiative to strengthen the security maturity of government entities includes a security assurance function to review the security maturity of Commonwealth entities.[\/p]"},{"content":"[p] Under this initiative, the Department of Home Affairs may undertake additional quality assurance of annual protective security reports submitted by entities. Where this occurs, the Department of Home Affairs will contact the CSO (or their delegate).[\/p]"},{"content":"[p]Annual PSPF reporting data and Cyber Security Survey data will be used to inform these reviews. These reviews will inform further evolution of our security frameworks and help government entities meet changes in the evolving threat landscape.[\/p]"},{"requirement":{"identifier":"pspf-0034","index":"0034.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]Entities cooperate with the Department of Home Affairs' assurance activities to review annual protective security reports.[\/p]"}]}}],"child":[],"stats":[]},{"type":"topic","ident":"4.2.2.4","title":"Sharing of Annual Security Reports","block":[{"content":"[lt]The annual PSPF reporting data is shared with:[\/lt][ul][li]Australian Signals Directorate to support its cyber uplift programs, development of technical guidance on areas of targeted improvement and to support the Annual Commonwealth Cyber Security Posture Report to Parliament.[\/li][li]Australian Security Intelligence Organisation to support its efforts to uplift government security capability.[\/li][li]Australian National Audit Office when requested to support an audit and in line with its responsibilities under the Auditor-General Act 1997[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"chapter","ident":"4.3","title":"Reporting to the Australian Signals Directorate","block":[{"content":"[p]The Australian Signals Directorate's Australian Cyber Security Centre is the Australian Government's lead agency on national cyber security operational matters, including technical cyber security incident response and advice. Entities must report on cyber security matters by completing the Australian Signals Directorate's annual Cyber Security Survey.[\/p]"},{"content":"[p]The Australian Signals Directorate uses this reporting data to prepare the Commonwealth Cyber Security Posture Report to inform the Australian Parliament on the implementation of cyber security measures across the Australian Government.[\/p]"},{"requirement":{"identifier":"pspf-0035","index":"0035.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"GOV","applicability":"ALL","content":[{"content":"[p]The annual Cyber Security Survey is submitted to the Australian Signals Directorate.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"domain","label":"Part Two","name":"RISK","title":"Risk","block":[{"content":"[ul][li]Security Risk Management[\/li][li]Third Party Risk Management[\/li][li]Countering Foreign Interference and Espionage[\/li][li]Contingency Planning[\/li][\/ul]"}],"child":[{"type":"part","ident":"5","title":"Security Risk Management","block":[{"content":"[p]Overall accountability for security risk management rests with the Accountable Authority. Security risks form part of the entity's enterprise risk management framework, which is the set of components and arrangements in place to appropriately manage the entity's risks.[\/p]"},{"content":"[p]Under the , entities are required to have an audit committee to review systems of risk oversight and management. Audit committees perform an important role in oversight of risk management, including security risks.[\/p]"},{"content":"[p]The Department of Finance's sets out the principles and mandatory requirements for managing risk in undertaking the activities of government. The Commonwealth Risk Management Policy supports section 16 of the PGPA Act which states that the Accountable Authority of a Commonwealth entity must establish and maintain appropriate system of risk oversight, management and internal control for the entity.[\/p]"}],"child":[{"type":"chapter","ident":"5.1","title":"Security Risk Tolerance","block":[{"content":"[p]Risk tolerance is an informed decision by the Accountable Authority to accept a certain level of risk. Risk tolerance describes the acceptable risk, after treatments are in place, to achieve an objective or manage a category of risk. It is highly dependent on the entity's unique context and the Accountable Authority's judgement.[\/p]"},{"content":"[p]Risk tolerance is the practical application of risk appetite, which is the amount of risk the entity is willing to accept or retain within the tolerance levels established by the Accountable Authority and the scope of the PSPF standards to achieve its objectives.[\/p]"},{"content":"[lt]Risk tolerance includes:[\/lt][ul][li]expectations for mitigating, accepting and pursuing specific types of risk[\/li][li]boundaries and thresholds of acceptable risk taking, and[\/li][li]actions to be taken or consequences for acting beyond approved tolerance levels.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0036","index":"0036.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]The Accountable Authority determines their entity's tolerance for security risks and documents in the security plan.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"5.2","title":"Security Risk Management Process","block":[{"content":"[p]A security risk management process manages the entity's risks across all areas of security to determine the sources of threat and risk that could affect entity operations or the government. Security risk management is logical, systematic and transparent and forms part of the enterprise risk management process.[\/p]"},{"content":"[lt]The key elements of the security risk management process are:[\/lt][ul][\/ul]"},{"content":"[p]Security risk assessment is closely related to other entity risk assessment processes and should not be considered in isolation from other areas of risk.[\/p]"},{"requirement":{"identifier":"pspf-0037","index":"0037.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]A risk steward (or manager) is identified for each security risk or category of security risk, including shared risks.[\/p]"}]}},{"requirement":{"identifier":"pspf-0038","index":"0038.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]The Accountable Authority considers the impact that their security risk management decisions could potentially have on other entities, and shares information on risks where appropriate.[\/p]"}]}}],"child":[{"type":"section","ident":"5.2.1","title":"Security Risk","block":[{"content":"[p]A security risk is something that could result in the compromise, loss, unavailability or damage to information or assets, or cause harm to people.[\/p]"},{"content":"[lt]Security risk is the effect of uncertainty on objectives and is often measured in terms of its likelihood and consequences, where:[\/lt][ul][li]effect is a deviation from the expected and may be positive or negative, and[\/li][li]An objective has different aspects such as financial, health, safety and environmental goals, and can apply at multiple levels such as strategic, organisation-wide, project, product and process levels.[\/li][\/ul]"},{"content":"[p]The causes of security risks are generally people, systems, processes, procedures, crime, attacks or natural events.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"5.2.2","title":"Shared Security Risks","block":[{"content":"[p]Shared security risks are those that extend across entities, premises, the community, industry, international partners or other jurisdictions. They require high levels of cooperation between stakeholders to effectively understand and manage those risks.[\/p]"},{"content":"[p]Where shared risks are identified, it is important to develop clear roles and responsibilities.[\/p]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"6","title":"Third Party Risk Management","block":[],"child":[{"type":"chapter","ident":"6.1","title":"Procurement, Outsourcing and Contract Management","block":[{"content":"[p]The govern how entities procure goods and services and are designed to ensure the Government and taxpayers get value for money. Section 30 of the states that non-corporate Commonwealth entities must comply with the Commonwealth Procurement Rules when performing duties related to procurement.[\/p]"},{"content":"[p]The procurement of goods or services does not transfer the operational risk from the Commonwealth. When an entity outsources the provision of goods or services, accountability for the goods or service and associated delivery outcomes (including managing security risks) remains with the entity.[\/p]"},{"content":"[p]Procurement and outsourcing arrangements can offer benefits (e.g. scalability, performance, resilience and cost efficiency), however these arrangements come with additional security risks. The Commonwealth Procurement Rules state that entities must establish processes to assess and treat risks when conducting a procurement to reduce the likelihood of additional financial and non-financial costs to government.[\/p]"},{"content":"[p]An unacceptable level of risk is when the identified security risks cannot be mitigated to a reasonable or acceptable level, or the security risks to the Australian Government or its people, information or resources, are too great. This includes where the security risks cannot be quantified or are too complex to be calculated. In these circumstances, entities must seek alternative procurement arrangements and maintain a record of such decisions.[\/p]"},{"content":"[p]The CSO is responsible for the security risks arising from the entity's procurement, outsourcing and contract management arrangements, other than for cyber security which is the responsibility of the CISO. The CSO is also responsible for determining where identified security risks pose an unacceptable level of risk.[\/p]"},{"requirement":{"identifier":"pspf-0039","index":"0039.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p] The entity is accountable for the management of security risks arising from procuring goods and services and ensures procurement and contract decisions do not expose the entity or the Australian Government to an unacceptable level of risk.[\/p]"}]}},{"requirement":{"identifier":"pspf-0040","index":"0040.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Procurement, contracts and third-party outsourced arrangements, contain proportionate security terms and conditions to ensure service providers, contractors and subcontractors comply with relevant PSPF Requirements and avoid exposing the entity or the Australian Government to an unacceptable level of risk.[\/p]"}]}},{"requirement":{"identifier":"pspf-0041","index":"0041.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Entity ensures service providers, contractors and subcontractors comply with relevant PSPF Requirements as detailed by the entity.[\/p]"}]}},{"requirement":{"identifier":"pspf-0042","index":"0042.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Contractual security terms and conditions require service providers to report any actual or suspected security incidents to the entity, and follow reasonable direction from the entity arising from incident investigations.[\/p]"}]}}],"child":[{"type":"section","ident":"6.1.1","title":"Outsourced Services provided by Government Entities","block":[{"content":"[p]Government entities that perform the role of an outsourced managed service or cloud service provider must make any Infosec Registered Assessors Program (IRAP) assessment reports available to the government entities looking to consume their services. This allows consuming entities to meet their PSPF obligations while also managing any potential risk to their own security classified information and data when consuming such services.[\/p]"},{"requirement":{"identifier":"pspf-0043","index":"0043.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Government entities providing outsourced services provide IRAP assessment reports to the government entities consuming, or looking to consume, their services.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"6.1.2","title":"Ongoing Management of Security in Contracts","block":[{"content":"[p]Security environments and risks constantly change. Sound contract management provides ongoing oversight and management, and helps adherence to essential security requirements of contracts.[\/p]"},{"requirement":{"identifier":"pspf-0044","index":"0044.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p] Contract security terms and conditions are monitored and reviewed to ensure the specified security controls, terms and conditions are implemented, operated and maintained by the contracted provider, including any subcontractors, over the life of a contract.[\/p]"}]}},{"requirement":{"identifier":"pspf-0045","index":"0045.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p] Contractual terms and conditions include appropriate security arrangements for the completion or termination of the contract.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"6.1.3","title":"Foreign Ownership, Control or Influence in Procurement","block":[{"content":"[p]As a result of the unprecedented levels of foreign interference targeting Australia, Australian Government entities that enter into commercial arrangements with organisations operating under Foreign Ownership, Control or Influence (FOCI) are at increased risk of foreign interference and espionage and must consider this risk as part of their obligations to mitigate security risks.[\/p]"},{"content":"[p]A contracted provider (organisation) may be operating under FOCI when a foreign interest has the power, direct or indirect, whether or not exercised, through the ownership of the organisation under the scope of its National Security Authority\/Designated Security Authority, by contractual arrangements or other means, to direct or decide matters affecting the management or operations of that organisation in a manner which may result in unauthorised access to classified information or adversely affect the performance of classified contracts or may otherwise be contrary to the interests of national security. In such cases, organisations may have to comply with directions that conflict with Australia's laws or interests, often granting a foreign government control over that business or access to its data holdings, and subsequently, entity data holdings. Not all instances of FOCI will create unacceptable security risks but security risks must be considered as part of all procurement and contract decisions involving providers operating under FOCI.[\/p]"},{"content":"[p]Robust due diligence must be undertaken when determining FOCI-related security risk. See for guidance on determining FOCI-related security risk.[\/p]"},{"content":"[p]The Commonwealth Procurement Rules state that all potential suppliers to government must be treated equitably and not discriminated against due to their size, degree of foreign ownership or affiliation, location, or origin of their goods and services. However, there are exceptions to this rule, particularly where jurisdictional security risks are introduced or the provider or service is subject to a foreign government's lawful or covert data collection without their customers' knowledge. Other exceptions may also include the provider or service facilitating foreign government access to customer systems, or a foreign government gaining an ability to influence decisions or activities to their benefit at the expense of Australia's national interest. It is also important to note foreign countries' laws could change with little warning, potentially presenting FOCI risks during the contract period.[\/p]"},{"content":"[p]Contact procurementagencyadvice@finance.gov.au for advice on applying the Commonwealth Procurement Rules in such circumstances.[\/p]"},{"content":"[p]See Countering Foreign Interference and Espionage.[\/p]"},{"requirement":{"identifier":"pspf-0046","index":"0046.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Procurement and contract decisions consider the security risks before engaging providers operating under foreign ownership, control or influence, and in response to any developments during the contract period that may give rise to foreign ownership, control or influence risks.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"6.2","title":"Third Party Risk Management Lifecycle","block":[{"content":"[p]Third party risk management is the process of identifying and addressing the security risks associated with third parties and understanding the lifecycle of third party relationships. A third party is any partner, consultant, vendor, service provider or supplier that provides a product or service to your entity or assists with its operations.[\/p]"},{"content":"[p]Identifying and managing jurisdictional, governance, privacy and security risks associated with the use of certain third party partners is crucial, particularly for application developers, ICT equipment manufacturers, service providers and other organisations involved in distribution channels. For example, outsourced cloud services may be located offshore and subject to lawful and covert data collection without their customers' knowledge. Risk can be reduced by selecting third parties that have committed to implementing and following secure-by-design and secure-by-default practices. See [\/p]"},{"content":"[p]Additionally, the use of offshore services introduces jurisdictional risks as foreign countries' laws could change with little warning. Finally, foreign owned suppliers operating in Australia may be subject to a foreign government's lawful access to data belonging to their customers.[\/p]"},{"content":"[p]See Foreign Ownership, Control or Influence in Procurement.[\/p]"},{"requirement":{"identifier":"pspf-0047","index":"0047.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p] Security risks arising from contractual arrangements for the provision of goods and services are managed, reassessed and adjusted over the life of a contract.[\/p]"}]}}],"child":[{"type":"chapter","ident":"6.2.1","title":"Vendor Risk Management","block":[{"content":"[p]Vendor risk management is the process of identifying, analysing, monitoring and mitigating the risks that may arise of using individual vendors, service providers and partners. All vendors are third parties, but not all third parties are vendors.[\/p]"},{"content":"[p]It is a legitimate procurement activity for vendors to seek additional information from government panels, for example, clarification of requirements in an AusTender Approach to Market notice. However, some vendors may seek to use this process to elicit unique or sensitive insights into government processes, priorities and systems for commercial advantage over other vendors.[\/p]"},{"content":"[p]Vendor risk management forms part of the third party risk management lifecycle.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"6.2.2","title":"Supply Chain Risk Management","block":[{"content":"[p]Supply chain risk management is the process of identifying, analysing, monitoring and mitigating supply chain-related risks. A supply chain is the flow of goods and services from internal or external suppliers through all stages of production and supply.[\/p]"},{"content":"[p]Supply chains can be large and complex and may involve multiple layers of suppliers. They may expose the entity to unforeseen vulnerabilities and disruptions at any point in the supply chain.[\/p]"},{"content":"[p]Supply chain risk management forms part of the third party risk management lifecycle and assessment of this is best conducted during the initial stages of procurement.[\/p]"},{"content":"[p]Entities must assess the source, reliability, and integrity of the suppliers and the supply chain of these strategic assets to ensure they comply with relevant laws and regulations, and the entity's security policies and standards. Diversifying the supply sources and reducing the dependency on single or dominant suppliers is advisable, as is enhancing the supply chain's resilience and redundancy in case of unexpected contingencies.[\/p]"},{"content":"[p]Supply chain risk management activities should be conducted during the earliest possible stage of procurement of applications, information technology (IT) equipment, operational technology (OT) equipment and services. Consider the security risks that may arise as systems, software and hardware are being designed, built, stored, delivered, installed, operated, maintained and decommissioned.[\/p]"},{"content":"[p]See Information Security Manual for guidance on cyber supply chain risk management.[\/p]"},{"requirement":{"identifier":"pspf-0048","index":"0048.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Secure and verifiable third-party vendors, providers, partners and associated services are used unless business operations require use, and the residual risks are managed and approved by the Chief Information Security Officer.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"7","title":"Countering Foreign Interference and Espionage","block":[{"content":"[p]Left unchecked, foreign interference can have a corrosive effect on our national security. It can weaken our free and open system of government, our social cohesion and our economic prosperity. The best defence against foreign interference and espionage is to limit vulnerabilities that can be exploited by foreign actors, and to arm people who are possible targets with the information they need to recognise and report it.[\/p]"},{"content":"[p]Attempts at foreign interference are occurring at all levels of government, in all states and territories. Foreign powers may seek to undermine the integrity of our democratic institutions. They may also attempt to cultivate or recruit officials at any level of government, to gain a coercive or clandestine influence over government decision-makers and access to sensitive government information.[\/p]"},{"content":"[lt]Appropriate due diligence is required to protect government people and resources from the risk of foreign interference, including:[\/lt][ul][li]Understanding relationships - knowing the people the entity works with and possible associations those people might have with foreign powers, their position on sensitive policy matters and any history they might have in terms of sensitive legal and ethical issues.[\/li][li]Being open and transparent in interactions and always acting with integrity - in accordance with the APS Values and Code of Conduct. Business decisions and relationships conducted in an open, lawful and transparent manner are less likely to present vulnerabilities for foreign actors to exploit.[\/li][li]Understanding the potential warning signs of foreign interference and how to make informed decisions to mitigate risks.[\/li][\/ul]"}],"child":[{"type":"chapter","ident":"7.1","title":"Recognising Foreign Interference and Espionage","block":[{"content":"[p]Foreign interference and espionage are the principal security concerns facing Australia.[\/p]"},{"content":"[p]Espionage is the theft of information or capabilities by someone acting on behalf of, or intending to provide information to, a foreign power or foreign political organisations that will prejudice Australia's national security, or advantage the national security of a foreign country. Espionage can target defence, political, industrial, foreign relations, commercial or other information or things that are usually otherwise unavailable to the foreign power.[\/p]"},{"content":"[p]Foreign interference are activities carried out by, or on behalf of, are directed or subsidised by, or are undertaken in active collaboration with, a foreign power and either involves a threat to a person, or are clandestine or deceptive and detrimental to Australia's interests. Foreign interference involves covertly shaping decision-making to the advantage of a foreign power, and is hostile to our national interests. It is not the same as a foreign state taking open and transparent action to influence deliberations of importance to them.[\/p]"},{"content":"[p]Foreign interference is not the same as foreign influence. All governments, including the Australian Government, seek to influence issues of importance to them. Australia is not concerned with foreign influence activity that is open and transparent and that respects our people, society and systems.[\/p]"},{"content":"[p]See ASIO's website for reporting on the domestic and international security environment.[\/p]"},{"content":"[p]Contact the Department of Foreign Affairs and Trade (security.training@dfat.gov.au) for advice on Foreign Intelligence Awareness Training for Australian Government personnel deployed or posted overseas.[\/p]"},{"content":"[p]See Foreign Ownership, Control or Influence in Procurement.[\/p]"},{"requirement":{"identifier":"pspf-0049","index":"0049.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Entities manage the security risks associated with engaging with foreign partners.[\/p]"}]}}],"child":[{"type":"section","ident":"7.1.1","title":"Foreign Delegations","block":[{"content":"[p]Visits by foreign delegations should be more highly scrutinised than other visitors as malign foreign actors and intelligence services may use visiting foreign delegations to gain access to entity facilities, personnel, information, or assets that are of intelligence interest.[\/p]"},{"content":"[p]These individuals or groups may undertake espionage or foreign interference on behalf of a foreign state actor.[\/p]"},{"content":"[p]Visits by foreign delegations must be managed to ensure their exposure to information, technology, capabilities or personnel does not result in unacceptable security risks. Staff responsible for escorting and managing foreign delegations must have the knowledge, confidence and experience necessary to manage security risks.[\/p]"},{"content":"[p]See Security Zones and Visitor Access Control.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"7.1.2","title":"International Agreements","block":[{"content":"[p]Australian Government security classified information and assets must not be shared with a foreign entity unless explicit legislative provisions, international agreements or arrangements for protection of classified information and assets are in place.[\/p]"},{"content":"[p]Vigilance is required when developing and entering into international agreements to avoid exposing Australian Government people, classified information or resources to foreign interference and espionage by a foreign entity or power.[\/p]"},{"content":"[p]See International Information Sharing.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"7.1.3","title":"Cultivation by a Foreign Actor","block":[{"content":"[p]Foreign actors - whether Government officials, intelligence officers or their proxies - will seek to make contact and develop relationships with Australian individuals to enable them to exert influence and pursue their objectives. Foreign actors and those assisting them may not be readily identifiable, nor may their links to foreign powers.[\/p]"},{"content":"[p]Foreign actors may attempt to manufacture circumstances and situations to create a sense of personal connection with, and obligation from, an individual to cause them to make decisions, or act in certain ways that support the interests of a foreign power.[\/p]"},{"content":"[lt]This is often done by engaging in activities to make targeted individuals feel a sense of reciprocity or indebtedness, such as providing:[\/lt][ul][li]gifts[\/li][li]donations[\/li][li]paid travel expenses[\/li][li]networking opportunities, and[\/li][li]preferential access to senior officials or business people.[\/li][\/ul]"},{"content":"[p]Gifts and benefits are often offered during official overseas trips or as part of foreign delegation visits to Australia. Accepting gifts or benefits may result in an actual or perceived conflict of interest, and at the extreme, can be construed as bribery.[\/p]"},{"content":"[p]Gifts may also present a security risk, particularly gifted chargers, removable media, wireless devices, internet connected devices, and radio frequency devices. There is the potential for malicious actors to plant malicious chips, software code or malware in order to collect data, compromise or gain unauthorised access to Australian Government information or systems. See www.cyber.gov.au for advice.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"7.1.4","title":"International Travel","block":[{"content":"[p]International travel (both personal and official) carries heightened risks for government personnel due to the nature of their work and access to Australian Government information. Government personnel may be targeted by foreign actors during official and personal international travel to obtain information or as part of cultivation operations.[\/p]"},{"content":"[p]It is significantly easier for foreign actors to operate in their home country, but many foreign actors are also active in countries other than their own. Australian Government information of interest to foreign actors is not limited to security classified information. It can also extend to any non-publicly available information that may confer an advantage on another country. This can include diplomatic, economic, trade, financial, commercial, technical and scientific information. Even information that may seem innocuous in isolation may be aggregated with other information to fill intelligence gaps or identify individuals for possible future targeting.[\/p]"},{"content":"[p]Foreign actors use a variety of methods to gain influence and\/or obtain information to use to their advantage. Many approaches or interactions with foreign actors are likely to be indistinguishable from normal networking opportunities, and may be designed to ingratiate the targeted individual or establish their complicity in benign activities. As such, it can be difficult for targeted individuals to know when they are engaging with foreign actors or their proxies.[\/p]"},{"content":"[p]Compromise of devices used to store or communicate official or classified Australian Government information pose the highest risk. Usage policies for these devices overseas should be calibrated to reduce this risk. Compromise of personal mobile devices can also provide foreign actors with access to sensitive information if they are used for business related communication, or access to personal information which may enable other targeting. For these reasons overseas travel policies and advice should include measures to reduce the risk that personal devices will be compromised.[\/p]"},{"content":"[p]To limit the risks of foreign interference and espionage during international travel, employees should always handle physical information appropriately, adopt good cyber hygiene practices, and only discuss classified matters in approved locations and via IT systems accredited to the classification level of the conversation.[\/p]"},{"content":"[p]See Minimum Protections and Handling Requirements, Security Classified Discussions and Working Remotely Outside of Australia (International), and Section 21.4.1.[\/p]"},{"content":"[p]Contact DFAT (security.training@dfat.gov.au) for security advice related to international travel for Australian Government personnel deployed or posted overseas.[\/p]"},{"content":"[p]Contact ASIO (outreach@asio.gov.au) for advice on reporting suspicious contact, foreign interference or threats to Australia's security while travelling overseas.[\/p]"},{"content":"[p]For more information on cyber security while travelling, visit the Australian Cyber Security Centre website [\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"7.1.5","title":"Protecting Personal Information","block":[{"content":"[p]Profiles on social media, recruitment and professional networking platforms can also be a vector for foreign actors to target individuals for potential cultivation and recruitment. Personal information online provides foreign actors with useful information to improve espionage and interference targeting.[\/p]"},{"content":"[p]Government employees who post details of clearance levels, position titles, projects and specialised systems on social media, could make themselves a more attractive target for foreign actors. Entity personnel should consider what personal information they choose to share, and the privacy settings applied to this information. Public visibility of personal information, including to other entity personnel, provide opportunities for foreign actors to tailor a more effective approaches - often seemingly innocent. Likewise, membership of employment related networking groups on social media sites, provide information on professional contacts and group activities, either social or operational, which can also be used by foreign actors for malign purposes.[\/p]"},{"content":"[p]All government officials must exercise caution in relation to the personal information they share about themselves in the online domain, to help mitigate the risks of espionage and foreign interference.[\/p]"},{"requirement":{"identifier":"pspf-0050","index":"0050.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Personnel do not publicise their security clearance level on social media platforms, including employment focused platforms such as LinkedIn.[\/p]"}]}},{"content":"[p]See Social Media Applications.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"7.2","title":"Countering Foreign Interference and Espionage","block":[{"content":"[p]Foreign interference can undermine the integrity of the Australian Government. Appropriate due diligence is required to protect the entity from the risk of foreign interference.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"7.3","title":"Insider Threat Programs","block":[{"content":"[p]Insider threat is when an insider intentionally or unintentionally uses their access to conduct activities that could cause harm or negatively affect an entity or its operations.[\/p]"},{"content":"[p]An insider is a current or former personnel (including contractors) who has, or had, legitimate or indirect access to an entity's people, information, techniques, activities, technology, or resources. All Australian Public Service (APS) employees are trusted to uphold the APS Values and comply with the APS Code of Conduct. They are therefore considered to be 'trusted insiders'. A trusted insider is commonly referred to as an insider.[\/p]"},{"content":"[p]A trusted insider may be acting on behalf of a foreign power, issue motivated group, organised crime groups or violent extremist groups etc. either intentionally or unintentionally to gain access to official, or security classified information.[\/p]"},{"content":"[p]Countering insider threat programs enable entities to identify and manage insider risk in a holistic and coordinated way. An effective insider threat program can protect critical assets, counter unintentional and malicious incidents, prevent loss of data and prevent reputational damage. To be effective, these programs should be both proactive and prevention focussed.[\/p]"},{"content":"[lt]An effective insider threat program is multifaceted, covering:[\/lt][ul][li]security governance and planning[\/li][li]personnel security[\/li][li]security culture and awareness training[\/li][li]access controls[\/li][li]physical and ICT security controls and audit, and[\/li][li]review, reporting and response processes.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0051","index":"0051.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]An insider threat program is implemented by entities that manage Baseline to Positive Vetting security clearance subjects to manage the risk of insider threat in the entity.[\/p]"}]}},{"content":"[p]In addition, entities that manage TS-PA security clearance subjects are required to implement an insider threat program that meets the TOP SECRET-Privileged Access Standard.[\/p]"},{"content":"[p]See Australian Government Personnel Security Adjudicative Standard (on GOVTeams) and TOP SECRET Privileged Access Standard.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"8","title":"Contingency Planning","block":[],"child":[{"type":"chapter","ident":"8.1","title":"Exceptional Circumstances","block":[{"content":"[p]Exceptional circumstances are situations beyond the entity's control that are not routine in nature, not enduring, and are unforeseen, unavoidable or unexpected. The exceptional circumstances provision allows the Accountable Authority, at their discretion, to adapt to arising circumstances that affect the entity's capability to implement or maintain a particular PSPF requirement or standard. Examples of exceptional circumstances include natural disasters, emergency situations. Entities are encouraged to consider alternative mitigation strategies during such periods to provide additional protection.[\/p]"},{"content":"[p]Section 19 of the PGPA Act requires that the Accountable Authority notifies the responsible minister of significant issues that affect, or may affect, the entity. This obligation includes advising the responsible minister, through the annual report on security, of any significant issues with implementing a PSPF requirement or standard or decisions to vary implementation.[\/p]"},{"requirement":{"identifier":"pspf-0052","index":"0052.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p] Where exceptional circumstances prevent or affect an entity's capability to implement a PSPF requirement or standard, the Accountable Authority may vary application, for a limited period of time, consistent with the entity's risk tolerance.[\/p]"}]}},{"requirement":{"identifier":"pspf-0053","index":"0053.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Decisions to vary implementation of a PSPF requirement or standard due to exceptional circumstances are documented in the entity's security plan.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"8.2","title":"Alternative Mitigations","block":[{"content":"[p]An alternative mitigation is a control or standard that differs from the PSPF requirement or standard but achieves the same intent. In the event that an entity is unable to implement a standard, a risk-based approach allows an alternative mitigation to be implemented where it achieves a level of protection that is the same as or exceeds that afforded by the PSPF requirement or standard. In such cases, the entity documents the decision in the entity's security plan, reports 'risk managed' for the corresponding standard and provides the required information as detailed in Protective Security Reporting.[\/p]"},{"requirement":{"identifier":"pspf-0054","index":"0054.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Decisions to implement an alternative mitigation measure that meets or exceeds a PSPF requirement or standard are reviewed and reported annually.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"8.3","title":"Business Continuity Planning","block":[{"content":"[p]Business continuity management is a type of risk management designed to address the threat of disruptions to entity operations and support the prompt response to and recovery from these events.[\/p]"},{"content":"[lt]The entity's business continuity plan documents the:[\/lt][ul][li]set of planned procedures to continue or recover the entity's services to the Government and the public with minimal disruption over a given period, irrespective of the source of the disruption, and[\/li][li]contingency post-event actions that can be implemented to prevent or limit losses and disruption.[\/li][\/ul]"},{"content":"[p]The business continuity plan should also make provision for significant business disruptions to reduce the immediate impact on the entity and provide acceptable lower levels of service, or resumption plans to resume operations within acceptable timeframes.[\/p]"},{"content":"[p]It is essential that the business continuity management plan complements the entity's security plan, other entity policies and procedures and is not prepared in isolation from these arrangements.[\/p]"},{"requirement":{"identifier":"pspf-0055","index":"0055.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]A business continuity plan is developed, implemented and maintained to respond effectively and minimise the impacts of significant business disruptions to the entity's critical services and assets, and other services and assets when warranted by a threat and security risk assessment[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"8.4","title":"Emergency Management and Notifications","block":[{"content":"[p]The Accountable Authority is responsible for the security of their entity's personnel. The preparedness of personnel and their ability to recognise and respond to a potential emergency is of paramount importance.[\/p]"},{"content":"[p]A key element of business continuity is planning for emergencies and the implications these events may have on the security of the entity's personnel, information and facilities.[\/p]"},{"content":"[lt]These arrangements must cover a broad range of emergencies, including:[\/lt][ul][li]bombs and bomb threats[\/li][li]potentially hazardous substances or hoaxes[\/li][li]failure of essential services[\/li][li]fire and explosions[\/li][li]cyber-attacks and serious cyber security incidents (noting National Coordination requirements)[\/li][li]major accidents[\/li][li]natural disasters[\/li][li]disruptive\/dangerous visitors, including active shooter[\/li][li]threatening telephone calls, emails and letters, and[\/li][li]suspicious packages or deliveries.[\/li][\/ul]"},{"content":"[p]Security awareness training, exercises and rehearsal of emergency counter-measures are vital to ensuring that the plans in place are effective and that entity personnel are ready and able to respond.[\/p]"},{"requirement":{"identifier":"pspf-0056","index":"0056.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Plans for managing a broad range of emergencies are integrated within the business continuity plan.[\/p]"}]}},{"requirement":{"identifier":"pspf-0057","index":"0057.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"RISK","applicability":"ALL","content":[{"content":"[p]Personnel who are likely to be impacted are notified if there is a heightened risk of an emergency.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"8.5","title":"Requesting Assistance\/Sharing Information in Emergencies","block":[{"content":"[p]Cyber security emergencies are complex and occur frequently. These events may also take place concurrently or consecutively. Entities experiencing security incidents have reporting obligations, including to share information with other entities that may be effected by the event (see Security Incidents) but may also require assistance to contain or remediate emergencies.[\/p]"},{"content":"[p]The National Emergency Management Agency develops, coordinates and supports effective management of national emergencies. The National Situation Room (NSR) is a 24\/7 crisis management information and government coordination facility provided by the National Emergency Management Agency.[\/p]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"domain","label":"Part Three","name":"INFO","title":"Information","block":[{"content":"[ul][li]Classifications and Caveats[\/li][li]Information Holdings[\/li][li]Information Disposal[\/li][li]Information Sharing[\/li][\/ul]"}],"child":[{"type":"part","ident":"9","title":"Classifications and Caveats","block":[{"content":"[p]Information is a valuable resource and can be collected, used, stored and transmitted in many forms including electronically, physically and audibly.[\/p]"},{"content":"[p]Official information is all information created, sent or received as part of the work of the Australian Government. Official information is a record and provides evidence of what an entity had done and why. All official information requires an appropriate degree of protection as information (and assets holding information) are subject to both intentional and accidental threats.[\/p]"},{"content":"[p]Australian Government entities are required to maintain the confidentiality, integrity and availability of official information, including where the entity is the originator of the information.[\/p]"}],"child":[{"type":"chapter","ident":"9.1","title":"Originator","block":[{"content":"[p]The originator is the entity that initially generated the information, or first received the unmarked information (i.e. an Australian Government or third-party approved security classification has not been applied) from outside the Australian Government, and assessed the value, importance or sensitivity of the information by considering the potential damage that would arise if the information's confidentiality was compromised, and assigned the corresponding protective marking or security classification.[\/p]"},{"requirement":{"identifier":"pspf-0058","index":"0058.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The originator remains responsible for controlling the sanitisation, reclassification or declassification of official and security classified information, and approves any changes to the information's security classification.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"9.2","title":"Security Classifications","block":[{"content":"[p]The Australian Government uses four security classifications: OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET. Security classified information includes OFFICIAL: Sensitive information unless otherwise stated.[\/p]"},{"content":"[p]All other information from business operations and services requires a routine level of protection and is treated as OFFICIAL. Information that does not form part of official duty is treated as UNOFFICIAL.[\/p]"},{"content":"[p]OFFICIAL and UNOFFICIAL are not security classifications and are not mandatory markings.[\/p]"},{"content":"[p]See Email Protective Marking Standard and Recordkeeping Metadata Standard.[\/p]"},{"requirement":{"identifier":"pspf-0059","index":"0059.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p] The value, importance or sensitivity of official information (intended for use as an official record) is assessed by the originator by considering the potential damage to the government, the national interest, organisations or individuals that would arise if the information's confidentiality were compromised.[\/p]"}]}},{"requirement":{"identifier":"pspf-0060","index":"0060.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The security classification is set at the lowest reasonable level.[\/p]"}]}},{"requirement":{"identifier":"pspf-0061","index":"0061.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Security classified information is clearly marked with the applicable security classification, and when relevant, security caveat, by using text-based markings, unless impractical for operational reasons.[\/p]"}]}},{"table":"[table name='Table 3' title='Potential Damage of Compromise of Information's Confidentiality'][head][cell]-[\/cell][cell]TOP SECRET[\/cell][cell]SECRET[\/cell][cell]PROTECTED[\/cell][cell]OFFICIAL:SENSITIVE[\/cell][cell]OFFICIAL[\/cell][cell]UNOFFICIAL[\/cell][\/head][row][cell]Business Impact level[\/cell][cell]5 - Catastrophic business impact[\/cell][cell]4 - Extreme business impact[\/cell][cell]3 - High business impact[\/cell][cell]2 - Low to medium business impact[\/cell][cell]1 - Low business impact[\/cell][cell]No business impact[\/cell][\/row][row][cell]Expected level of damage[\/cell][cell]Exceptionaly grave damage to the national interest, organisations or individuals.[\/cell][cell]Serious damage to the national interest, organisations or individuals.[\/cell][cell]Damage to the national interest, organisations or individuals.[\/cell][cell]Limited damage to an individual, organisation or government generally if compromised.[\/cell][cell]No or insignificant damage. This is the majority of routine information.[\/cell][cell]No damage. This information does not form part of official duty.[\/cell][\/row][\/table]"}],"child":[],"stats":[]},{"type":"chapter","ident":"9.3","title":"Minimum Protections and Handling Requirements","block":[{"content":"[p]The minimum protections and handling requirements establish the key operational controls for accessing, storing or communicating OFFICIAL and security classified information in a physical format and on both government-issued mobile devices and non-government issued mobile devices.[\/p]"},{"content":"[p]Entity facilities is defined as the physical premises or space that the entity occupies to perform its approved functions. Facilities can be a building, floor of a building or designated space. See Section 17.3.1 for advice on working remotely in Australia, including in co-location or hosting arrangements.[\/p]"},{"content":"[p]See Security Containers, Cabinets and Rooms for details of lockable containers.[\/p]"},{"content":"[p]See Information Security Manual for controls for non-mobile desktop equipment and servers.[\/p]"},{"requirement":{"identifier":"pspf-0062","index":"0062.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The minimum protections and handling requirements are applied to protect OFFICIAL and security classified information.[\/p]"}]}}],"child":[{"type":"section","ident":"9.3.1","title":"Protections and Handling Requirements for Physical information","block":[{"content":"[p]Physical information means information that physically exists in hard copy, including printed copies of emails. Entities must apply the following minimum protections and handling requirements for all Australian Government physical information. Additional restrictions may apply for caveated information, refer to the Australian Government Security Caveat Standards for minimum handling requirements and protections for caveated information including codeword information.[\/p]"},{"table":"[table name='Table 4' title='Physical Information - Inside Entity Facilities'][\/table]"},{"table":"[table name='Table 5' title='Physical Information - Working Remotely in Australia (including home-based work)'][\/table]"},{"table":"[table name='Table 6' title='Physical Information - Working Remotely Internationally'][\/table]"},{"table":"[table name='Table 7' title='Physical Information - Travelling in Australia (domestic travel)'][\/table]"},{"table":"[table name='Table 8' title='Physical Information - Travelling Outside of Australia (international travel)'][\/table]"}],"child":[],"stats":[]},{"type":"section","ident":"9.3.2","title":"Protections and Handling Requirements for Government-issued Mobile Devices","block":[{"content":"[p]A government-issued mobile device is a mobile or portable computing communications device that is owned and issued by an Australian Government entity to access the entity's systems and data and is approved by the relevant authority to process, store or communicate entity information of a specified protective marking or security classification. This includes mobile phones, handheld computers, tablets, laptops and personal digital assistants configured, encrypted and managed to Australian Signals Directorate's standards and guidance. If these requirements are met, then a government-issued mobile device is considered in a 'secured state'. Entities must apply the following minimum protections and handling requirements for all Australian Government-issued mobile devices.[\/p]"},{"content":"[p]The Australian Signals Directorate is the relevant authority for TOP SECRET and SECRET government-issued mobile devices and capabilities and may set additional restrictions or conditions for use. The may also approve alternative mitigation arrangements, including outside entity facilities, to support operational or ministerial briefing requirements. The entity is the relevant authority for other government-issued mobile devices.[\/p]"},{"table":"[table name='Table 9' title='Government-Issued Mobile Devices - Inside Entity Facilities'][\/table]"},{"table":"[table name='Table 10' title='Government-Issued Mobile Devices - Working Remotely in Australia (including home-based work)'][\/table]"},{"table":"[table name='Table 11' title='Government-Issued Mobile Devices - Working Remotely Internationally'][\/table]"},{"table":"[table name='Table 12' title='Government-Issued Mobile Devices - Travel in Australia (domestic travel)'][\/table]"},{"table":"[table name='Table 13' title='Government-Issued Mobile Devices - Travel Outside of Australia (international travel)'][\/table]"},{"table":"[table name='Table 14' title='Government-Issued Mobile Devices - Provided at International Destination'][\/table]"}],"child":[],"stats":[]},{"type":"section","ident":"9.3.3","title":"Protections and Handing Requirements for Non-Government Mobile Devices","block":[{"content":"[lt]There are two types of non-government mobile devices and entities must apply the following minimum protections and handling requirements for both types of non-government mobile devices.[\/lt][ul][li]Authorised non-government device - mobile or portable computing communications devices (including mobile phones, handheld computers, tablets, laptops and digital assistants) owned or issued by a non-government source (for example commercial organisation, non-government organisation, industry issued or privately-owned) that is managed, configured and encrypted in accordance with ASD standards and guidance, and the residual risk is accepted by the Commonwealth entity system risk owner to access, process, store or communicate OFFICIAL, OFFICIAL: Sensitive and PROTECTED Australian Government information. Non-government devices must not access, process, store or communicate SECRET or TOP SECRET information. If these requirements are fully met, then a non-government mobile device is considered in a 'secured state'. If these requirements are not fully met, refer to 'unsecured state' requirements.[\/li][li]All other mobile devices - devices that are not owned, issued or authorised by the entity. These devices must not be authorised to access, process, store or communicate government OFFICIAL: Sensitive or above information, and must not enter Zones 4-5 or where SECRET or TOP SECRET information or devices are present. If use of these devices is required in a Zone 3, then use is subject to risk assessment and approval by the CSO or CISO. All other mobile devices also includes radio frequency and infrared devices such as private mobile phones, devices, wireless keyboards, Bluetooth devices, smart watches, cameras and any other infrared device that is capable of recording or transmitting audio or data. See the Information Security Manual for additional controls.[\/li][li]All other mobile devices includes radio frequency and infrared medical devices that connect to entity networks or the internet and may expose the entity to an increased cyber threat. Therefore, a risk assessment is required before allowing medical devices that rely on Wi-Fi, Bluetooth or are capable of recording or transmitting audio or data, into Zones 4 and 5 areas.[\/li][\/ul]"},{"table":"[table name='Table 15' title='Non-Government Mobile Devices - Inside Entity Facilities'][\/table]"},{"table":"[table name='Table 16' title='Non-Government Mobile Devices - Working Remotely in Australia (including home-based work)'][\/table]"},{"table":"[table name='Table 17' title='Non-Government Mobile Devices - Working Remotely Internationally'][\/table]"},{"table":"[table name='Table 18' title='Non-Government Mobile Devices - Travel in Australia (domestic travel)'][\/table]"},{"table":"[table name='Table 19' title='Non-Government Mobile Devices - Travel Outside of Australia (international travel)'][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"9.4","title":"Information Management Markers","block":[{"content":"[p]Information management markers are an optional way for entities to identify information that is subject to non-security related restrictions on access and use. They are a subset of the controlled list of terms for the 'Rights Type' property in the National Archives of Australia's . Information management markers are not protective markers or security classifications.[\/p]"},{"content":"[p]See Recordkeeping Metadata Standard for requirements and PSPF Guidelines for description of optional information management markers.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"9.5","title":"Security Caveats and Accountable Material","block":[],"child":[{"type":"section","ident":"9.5.1","title":"Security Caveats","block":[{"content":"[p]Security Caveats are a warning that the information has special protections in addition to those indicated by the security classification. Security Caveats are not classifications and must appear with a security classification of PROTECTED or higher.[\/p]"},{"content":"[lt]There are four categories of security caveats:[\/lt][ul][li]Codewords (sensitive compartment information that requires a compartmental briefing)[\/li][li]Foreign Government Markings[\/li][li]Special Handling Instructions, and[\/li][li]Releasability Caveats.[\/li][\/ul]"},{"content":"[p]Each security caveat is governed by a 'controlling authority', responsible for managing and administering the security caveat. See the Australian Government Security Caveat Guidelines for details.[\/p]"},{"requirement":{"identifier":"pspf-0063","index":"0063.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The Australian Government Security Caveat Standard and special handling requirements imposed by the controlling authority are applied to protect security caveated information.[\/p]"}]}},{"requirement":{"identifier":"pspf-0064","index":"0064.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Security caveats are clearly marked as text and only appear in conjunction with a security classification of PROTECTED or higher.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"9.5.2","title":"Accountable Material","block":[{"content":"[p]Accountable material is information that requires the strictest control over its access and movement.[\/p]"},{"content":"[lt]Accountable material includes:[\/lt][ul][li]TOP SECRET information[\/li][li]all codeword information, see Australian Government Security Caveat Standard for details[\/li][li]select special handing instruction caveats, see Australian Government Security Caveat Standard for details, and[\/li][li]any classified information designated as accountable material by the originator.[\/li][\/ul]"},{"content":"[p]See Information Asset Registers for information on auditable records for accountable material.[\/p]"},{"requirement":{"identifier":"pspf-0065","index":"0065.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Accountable material has page and reference numbering.[\/p]"}]}},{"requirement":{"identifier":"pspf-0066","index":"0066.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Accountable material is handled in accordance with any special handling requirements imposed by the originator and security caveat owner detailed in the Australian Government Security Caveat Standard.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"","title":"Email Protective Marking Standard","block":[{"content":"[p]The Australian Government Email Protective Marking Standard details the standardised format for protective markings, security classifications and, where relevant information management markers, on emails exchanged in and between Australian Government entities, and with other authorised parties. This includes authorised non-government entities and foreign partners where a formal agreement or arrangement has been established.[\/p]"},{"content":"[p]This standard supports processes and technology systems, such as an entity's email gateway, to control the flow of information into and out of the entity. For message recipients it also identifies what handling protections are needed to safeguard the information.[\/p]"},{"requirement":{"identifier":"pspf-0067","index":"0067.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The Australian Government Email Protective Marking Standard is applied to protect OFFICIAL and security classified information exchanged by email in and between Australian Government entities, including other authorised parties.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"9.7","title":"Recordkeeping Metadata Standard","block":[{"content":"[p]Metadata is a term that means 'data about data'. Text-based protective markings on technology systems are supplemented by the use of metadata to describe, among other things, key security characteristics of information. For electronic records management systems, the National Archives of Australia produces the to provide standardised metadata terms and definitions for consistency across government. The minimum metadata set is a practical application of the standard that identifies the metadata properties essential for entity management and use of official information.[\/p]"},{"requirement":{"identifier":"pspf-0068","index":"0068.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The Australian Government Recordkeeping Metadata Standard's 'Security Classification' property (and where relevant, the 'Security Caveat' property) is applied to protectively mark information on technology systems that store, process or communicate security classified information.[\/p]"}]}},{"requirement":{"identifier":"pspf-0069","index":"0069.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Apply the Australian Government Recordkeeping Metadata Standard's 'Rights' property where the entity wishes to categorise information content by the type of restrictions on access.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"9.8","title":"Security Classified Discussions","block":[{"content":"[p]Security classified discussions includes any audible dissemination of information, including briefings, irregular discussions and meetings either in person or using a mobile device, phone or video conference platform. ASIO Technical Note 1\/15 Physical Security of Zones defines 'irregular discussions' as those that are unpredictable, non-ongoing or unannounced.[\/p]"},{"requirement":{"identifier":"pspf-0070","index":"0070.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Security classified discussions and dissemination of security classified information are only held in approved locations.[\/p]"}]}}],"child":[{"type":"section","ident":"9.8.1","title":"Approved Locations for Security Classified Discussions","block":[{"content":"[p]Table 20 details the approved locations for security classified discussions. This identifies when entities must 'exercise judgement', use discretion and to judge the suitability of the location and environment. Entities must also consider who else might be able to hear the security classified information.[\/p]"},{"content":"[p]The risk of deliberate or accidental overhearing can be minimised by controlling the environment where the discussion is taking place. This may be achieved by treating the room, area or entire facility acoustically, combined with other physical and procedural security measures. See Technical Surveillance Countermeasures and Table 47: Physical Security Measures and Controls - Technical surveillance counter-measures (TSCM) for mandatory elements.[\/p]"},{"content":"[p]To provide protection for security classified discussions, it is necessary for the sound created within the room to be unintelligible to a person or device located outside that room. Appropriate and effective sound insulation is critical to achieving the required level of security for security classified discussions as it is extremely difficult for an entity to ensure that only low-volume voice levels are used for security classified discussions or that background noise will always exist in the receiving area. See ASIO Technical Note 1\/15 - Physical Security of Zones, Section 16: Audio Security and ASIO Technical Note 5\/12 Physical Security Zones (TOP SECRET) areas.[\/p]"},{"table":"[table name='Table 20' title='Approved Locations for Security Classified Discussions\/Audible Dissemination of Information'][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"9.9","title":"Historical Classifications","block":[{"content":"[p]There are historical security classifications and other protective markings (e.g. UNCLASSIFIED, X-IN-CONFIDENCE, RESTRICTED, PROTECTED, CONFIDENTIAL and HIGHLY PROTECTED) that no longer reflect Australian Government policy. The historical security classifications and historical handling protections remain unless the originator reclassifies or declassifies the information and applies a current security classification.[\/p]"},{"content":"[p]See PSPF Guidelines for protections and handling requirements for historical classifications and markings.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"10","title":"Information Holdings","block":[{"content":"[p]Information is a valuable asset. Information is an all-encompassing term for describing data, information and records in any format. All information entities create, use or receive as part of its business is subject to the Archives Act 1983, no matter what its format or location. All government personnel (including contractors) are responsible for creating and capturing information into systems that manage and support its use over time.[\/p]"},{"content":"[p]See the National Archives of Australia's Information Management Standard for guidance.[\/p]"},{"requirement":{"identifier":"pspf-0071","index":"0071.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p] Entity implements operational controls for its information holdings that are proportional to their value, importance and sensitivity.[\/p]"}]}}],"child":[{"type":"chapter","ident":"10.1","title":"Aggregated Information Holdings","block":[{"content":"[p]Aggregated information is a compilation of information that may be assessed as requiring a higher security classification or additional security controls where the aggregated holding is significantly more valuable than its individual components. This is because the collated information reveals new or more sensitive information or intelligence than would be apparent from the individual source components, and would cause greater damage than individual components. When viewed separately, the components of the information holding retain their individual classifications. The entity that aggregates the information becomes the 'originator' and is therefore responsible for assessing the classification of the aggregated information.[\/p]"},{"content":"[p]Integrated information is information that is combined from different sources into a single, unified view. While the value of integrated data can be high, it is also generally de-identified, cleansed and transformed to the extent that it provides limited information outside of the insights for which it was created to provide. Considering this, integrated data is of a single value and should only be classified according to the value, importance and sensitivity of the fully integrated data set. The entity that integrates the data becomes the 'originator' and must therefore assess the classification of the integrated data.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"10.2","title":"Information Asset Registers","block":[{"content":"[p]Monitoring and auditing the dissemination of information plays an important role in information protection. For highly classified or caveated information (such as TOP SECRET information and accountable material), it is critical to maintain an auditable register (such as a Classified Document Register or electronic document management repository) of all incoming and outgoing information and material, transfers or copying, along with regular spot check audits.[\/p]"},{"content":"[p]See Security Caveats and Accountable Material.[\/p]"},{"requirement":{"identifier":"pspf-0072","index":"0072.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]An auditable register is maintained for TOP SECRET information and accountable material.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"11","title":"Information Disposal","block":[{"content":"[p]All official information the Australian Government creates, sends and receives is considered a Commonwealth record. Not all official information is kept forever and disposing of it does not always mean it is destroyed.[\/p]"},{"content":"[p]Under the Archives Act 1983, disposal of Australian Government business information means either its destruction, the transfer of its custody or ownership, or damage or alteration. Destruction is the complete and irreversible process of erasing the business information so it cannot be reconstituted or reconstructed.[\/p]"},{"content":"[p]Business information is managed for as long as it has value; some information will have long-term historical and social value. The National Archives of Australia's Information Management Standard for Australian Government Principle 6 states that business information is accountably destroyed or transferred Records authorities set out the minimum periods for which business information should be retained. The Information Management Standard for the Australian Government states that entities must not destroy relevant business information until the disposal freeze or retention notice is no longer in place.[\/p]"},{"content":"[lt]Destruction of Australian Government business information can occur if it is:[\/lt][ul][li]approved by the National Archives through a records authority[\/li][li]required by legislation, or[\/li][li]covered under a normal administrative practice (NAP).[\/li][\/ul]"},{"content":"[p]The careless disposal of security classified information is a serious source of leakage or compromise of information, and can undermine public confidence in the Australian Government.[\/p]"},{"requirement":{"identifier":"pspf-0073","index":"0073.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]OFFICIAL and security classified information is disposed of securely in accordance with the Minimum Protections and Handling Requirements, Information Security Manual, the Records Authorities, a Normal Administrative Practice and the Archives Act 1983.[\/p]"}]}},{"requirement":{"identifier":"pspf-0074","index":"0074.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Security classified information is appropriately destroyed in accordance with the Minimum Protections and Handling Requirements when it has passed the minimum retention requirements or reaches authorised destruction dates.[\/p]"}]}}],"child":[],"stats":[]},{"type":"part","ident":"12","title":"Information Sharing","block":[{"content":"[p]Australian Government security classified and caveated information requires protection if it is to be shared with other government entities, non-government stakeholders and international partners.[\/p]"},{"content":"[p]Entities must consider the information they share and disclose and ensure it is appropriately controlled, when sharing security classified information, or disclosing information outside of government.[\/p]"},{"requirement":{"identifier":"pspf-0075","index":"0075.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Access to security classified information or resources is only provided to people outside the entity with the appropriate security clearance (where required) and a need-to-know, and is transferred in accordance with the Minimum Protections and Handling Requirements.[\/p]"}]}}],"child":[{"type":"chapter","ident":"12.1","title":"Domestic Information Sharing","block":[],"child":[{"type":"section","ident":"12.1.1","title":"Sharing with Other Government Entities","block":[{"content":"[p]All non-corporate Commonwealth entities are required to adhere to the PSPF. Entities may share information with other non-corporate Commonwealth entities provided the recipient holds the appropriate security clearance (where required), the need-to-know principle is applied, and the information is provided by means authorised in the PSPF.[\/p]"},{"content":"[p]The PSPF represents better practice for other Commonwealth entities (i.e. corporate Commonwealth entities and Commonwealth Companies), but is not mandatory. Entities may share information with other Commonwealth entities provided the information is transferred in accordance with the PSPF, the need-to-know principle is applied, the recipient holds the appropriate security clearance, and agrees to adhere to the Minimum Protections and Handling Requirements.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"12.1.2","title":"Sharing with Australian State and Territory Agencies","block":[{"content":"[p]A Memorandum of Understanding (MOU) between the Commonwealth, States and Territories is in place for the protection of security classified information and to support national cooperation between jurisdictions. Under the MOU, state and territory government agencies that hold or access Australian Government security classified information are required to apply the relevant protective security measures contained in the PSPF to that information.[\/p]"},{"requirement":{"identifier":"pspf-0076","index":"0076.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]The Memorandum of Understanding between the Commonwealth, States and Territories is applied when sharing information with state and territory government agencies.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"12.1.3","title":"Sharing with Non-Government Stakeholders","block":[{"content":"[p]Risks arise when sharing information outside of government as the PSPF Minimum protections and handling requirements apply only to non-corporate Commonwealth entities. These arrangements therefore need an agreement, contract or deed in place to provide assurance that the non-government stakeholder understands the obligations to protect government information.[\/p]"},{"content":"[p]OFFICIAL information (i.e. non-classified information) may be shared with non-government stakeholders without an agreement or arrangement for its protection.[\/p]"},{"requirement":{"identifier":"pspf-0077","index":"0077.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]An agreement or arrangement, such as a contract or deed, that establishes handling requirements and protections, is in place before security classified information or resources are disclosed or shared with a person or organisation outside of government.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"12.2","title":"International Information Sharing","block":[{"content":"[lt]Australia has international treaty-level agreements, or less-than-treaty-status arrangements, that provide for equivalent international protection of Australian Government OFFICIAL and security classified information or resources:[\/lt][ul][\/ul]"},{"content":"[p]Australian Government security classified information and resources must not be shared with a foreign entity unless explicit legislative provisions, international agreements or arrangements for protection of classified information and resources are in place.[\/p]"},{"content":"[lt]There are generally two types of international agreements:[\/lt][ul][li]Whole of government international agreement - referred to as General Security Agreements (GSA).[\/li][li]Entity-to-entity specific international agreements - these vary in format and substance.[\/li][\/ul]"},{"content":"[p]Australian Government security classified information or resources must not be shared with a foreign entity that is subject to extensive data collection powers or exposure to extrajudicial directions from a foreign government that conflict with Australian law.[\/p]"},{"requirement":{"identifier":"pspf-0078","index":"0078.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Provisions are met concerning the security of people, information and resources contained in international agreements and arrangements to which Australia is a party.[\/p]"}]}},{"requirement":{"identifier":"pspf-0079","index":"0079.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Australian Government security classified information or resources shared with a foreign entity is protected by an explicit legislative provision, international agreement or international arrangement.[\/p]"}]}},{"requirement":{"identifier":"pspf-0080","index":"0080.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Australian Government security classified information or resources bearing the Australian Eyes Only (AUSTEO) caveat is never shared with a person who is not an Australian citizen, even when an international agreement or international arrangement is in place[\/p]"}]}},{"requirement":{"identifier":"pspf-0081","index":"0081.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Australian Government security classified information or resources bearing the Australian Government Access Only (AGAO) caveat is not shared with a person who is not an Australia citizen, even when an international agreement or international arrangement is in place, unless they are working for, or seconded to, an entity that is a member of National Intelligence Community, the Department of Defence or the Australian Submarine Agency.[\/p]"}]}},{"requirement":{"identifier":"pspf-0082","index":"0082.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Where an international agreement or international arrangement is in place, security classified foreign entity information or resources are safeguarded in accordance with the provisions set out in the agreement or arrangement.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"12.2.1","title":"Sharing with Non-Government International Stakeholders","block":[{"content":"[p]Sharing of Australian Government security classified information and resources with a foreign entity (including non-government individuals, companies or organisations) is prohibited unless explicit legislative provisions, international agreements or arrangements for protection of classified information and resources are in place.[\/p]"},{"content":"[p]These arrangements ensure that the appropriate mutual arrangements for the protection of information and resources have been considered and agreed.[\/p]"},{"content":"[p]Risk-based approaches to ad hoc or one-off sharing of Australian Government security classified information and resources can be made through arrangements such as a letter of assurance or using temporary access provisions at Access to Resources.[\/p]"},{"content":"[lt]If agreed by the Accountable Authority, these ad hoc arrangements must be:[\/lt][ul][li]documented, including the date the accountable authority approved the arrangements[\/li][li]for a limited\/specific period of time only, i.e. not ongoing or enduring[\/li][li]for a specific purpose, project or activity, and[\/li][li]inclusive of protections for use and storage of security classified and caveated information in accordance with the Minimum Protections and Handling Requirements and the Australian Government Security Caveat Standards.[\/li][\/ul]"},{"content":"[p]Australian Government security classified information or resources must not be shared with foreign non-government stakeholders that are subject to extensive data collection powers or exposure to extrajudicial directions from a foreign government that conflict with Australian law.[\/p]"},{"requirement":{"identifier":"pspf-0083","index":"0083.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"INFO","applicability":"ALL","content":[{"content":"[p]Australian Government security classified information or resources shared with a foreign non-government stakeholder is protected by an explicit legislative provision, international agreement or international arrangement.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]}],"stats":[]},{"type":"domain","label":"Part Four","name":"TECH","title":"Technology","block":[{"content":"[ul][li]Technology Lifecycle Management[\/li][li]Cyber Security Strategies[\/li][li]Cyber Security Programs[\/li][\/ul]"}],"child":[{"type":"part","ident":"13","title":"Technology Lifecycle Management","block":[{"content":"[p]Technology lifecycle management is the approach to managing the entity's information technology and operational technology systems (technology systems) across designing, developing, planning, procurement, deployment and maintenance through to retirement of the systems.[\/p]"}],"child":[{"type":"chapter","ident":"13.1","title":"Information Security Manual","block":[{"content":"[p]The Australian Signals Directorate's Information Security Manual outlines the controls to protect the entity's technology systems and data from cyber threats, using a risk management framework. Broadly the Information Security Manual's risk management framework has six steps: define the system, select controls, implement controls, assess controls, authorise the system and monitor the system.[\/p]"},{"requirement":{"identifier":"pspf-0084","index":"0084.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The Australian Signals Directorate's Information Security Manual cyber security principles are applied during all stages of the lifecycle of each system.[\/p]"}]}},{"requirement":{"identifier":"pspf-0085","index":"0085.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The Australian Signals Directorate's Information Security Manual controls and cyber security guidelines are applied on a risk-based approach.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"13.2","title":"Network Documentation","block":[{"content":"[p]Network documentation is developed to accurately depict the current state of the entity's networks and includes high-level network diagrams showing all connections into networks; logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances; and device settings for all critical servers, high-value servers, network devices and network security appliances.[\/p]"},{"content":"[p]Network documentation can assist in troubleshooting network problems as well as responding to and recovering from cyber security incidents. Finally, as network documentation could be used by malicious actors to assist in compromising networks, it is important that it is appropriately protected.[\/p]"},{"content":"[p]Entities may want to use vulnerability, network or attack surface scanning tools and explore how they could be leveraged for mitigating security risks posed by inadequate information technology and operational technology asset inventories or shadow IT. See and .[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"13.3","title":"Technology System Authorisation","block":[{"content":"[p]The effective implementation of the Information Security Manual's cyber security principles, controls and guidelines are key to safeguarding entity technology and systems from cyber threats and managing the associated security risks.[\/p]"},{"content":"[p]All technology systems require authorisation to operate or be used in the entity. The authorisation process ensures that an appropriate level of security is being applied to the technology system and that residual security risks have been accepted by the relevant authority. This approach also provides confidence that the technology system meets security objectives, and addresses known security vulnerabilities. An impartial (and in some cases independent) security assessment can be a valuable tool in authorisation decisions.[\/p]"},{"content":"[p]Obligations for protecting Australian Government information and data that is processed, stored or communicated via an outsourced managed service provider or cloud service provider are no different than using an internal entity service. The same authorisation to operate framework for managing security risks during the lifecycle of the technology system still applies.[\/p]"},{"table":"[table name='Table 21' title='Authorising Officer and Security Assessor for Technology System Authorisation'][head][cell]Technology System[\/cell][cell]Security Assessor[\/cell][cell]Authorising Officer[\/cell][\/head][row][cell]TOP SECRET systems (including sensitive compartmented information systems, outsourced information technology and cloud services)[\/cell][cell]Australian Signals Directorate assessor (or their delegate)[\/cell][cell]Director-General Australian Signals Directorate (or their delegate)[\/cell][\/row][row][cell]SECRET system[\/cell][cell]Entity assessor or IRAP assessor[\/cell][cell]Accountable Authority or Chief Information Security Officer (or their delegate) of entity system owner[\/cell][\/row][row][cell]SECRET outsourced information technology and cloud services[\/cell][cell]IRAP assessor[\/cell][cell]Accountable Authority or Chief Information Security Officer (or their delegate) of entity system owner[\/cell][\/row][row][cell]PROTECTED, OFFICIAL: Sensitive and OFFICIAL systems[\/cell][cell]Entity assessor or IRAP assessor[\/cell][cell]Accountable Authority or Chief Information Security Officer (or their delegate) of entity system owner[\/cell][\/row][row][cell]PROTECTED, OFFICIAL: Sensitive and OFFICIAL outsourced information technology and cloud services[\/cell][cell]IRAP assessor[\/cell][cell]Accountable Authority or Chief Information Security Officer (or their delegate) of entity system owner[\/cell][\/row][row][cell]Multinational and multi-entity systems[\/cell][cell]Determined by agreement between the parties involved[\/cell][cell]Determined by a formal agreement between the parties involved[\/cell][\/row][row][cell]Gateways[\/cell][cell]IRAP assessor[\/cell][cell]Accountable Authority or Chief Information Security Officer (or their delegate) of entity system owner[\/cell][\/row][\/table]"},{"requirement":{"identifier":"pspf-0086","index":"0086.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The Authorising Officer authorises each technology system to operate based on the acceptance of the residual security risks associated with its operation before that system processes, stores or communicates government information or data.[\/p]"}]}},{"requirement":{"identifier":"pspf-0087","index":"0087.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Decisions to authorise (or reauthorise) a new technology system or make changes to an existing technology system are based on the Information Security Manual's risk-based approach to cyber security.[\/p]"}]}},{"requirement":{"identifier":"pspf-0088","index":"0088.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The technology system is authorised to the highest security classification of the information and data it will process, store or communication.[\/p]"}]}},{"requirement":{"identifier":"pspf-0089","index":"0089.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]A register of the entity's authorised technology systems is developed, implemented and maintained and includes the name and position of the Authorising Officer, system owner, date of authorisation, and any decisions to accept residual security risks.[\/p]"}]}}],"child":[{"type":"section","ident":"13.3.1","title":"Technology System Reauthorisation","block":[{"content":"[p]During the lifecycle of a technology system, it may require a reassessment to continue operation or eventually be decommissioned (i.e. disposal at the end of its life).[\/p]"},{"content":"[ul][li]changes of application in the Information Security Manual's controls or security policies relating to the technology system[\/li][li]detection of new or emerging cyber threats to the technology system or its operating environment[\/li][li]the discovery that security controls for the technology system are not as effective as planned[\/li][li]a major cyber security incident involving the technology system, or[\/li][li]major functionality or architectural changes to the technology system.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0090","index":"0090.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Each technology system's suitability to be authorised to operate is reassessed when it undergoes significant functionality or architectural change, or where the system's security environment has changed considerably.[\/p]"}]}}],"child":[{"type":"topic","ident":"13.3.1.1","title":"Continued Authorisation","block":[{"content":"[p]Authorisation to operate is generally ongoing once the system is operational. However, the system owner monitors to ensure that the risks of operating the system do not exceed the entity's risk tolerances. Where a risk level has been exceeded, the system owner must take appropriate steps to identify the level of mitigation required and whether the Authorising Officer needs to accept the risk or sign off on the proposed mitigations. If multiple risks are exceeded simultaneously the system owner must consider if one or more of the triggers from the above section are warranted triggering a full reassessment and reauthorisation.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"section","ident":"13.3.2","title":"System Owners","block":[{"content":"[p]System owners are responsible for ensuring the secure operation of their technology systems. System owners may delegate the day-to-day management and operation of their technology systems to other personnel.[\/p]"},{"content":"[p]See PSPF Guidelines and the Information Security Manual for the authorisation process steps.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"13.4","title":"Applications Management","block":[{"content":"[p]All applications require approval to be installed or used on resources that access Australian Government technology systems or data.[\/p]"}],"child":[{"type":"section","ident":"13.4.1","title":"Social Media Applications","block":[{"content":"[p]Social media applications can pose significant security and privacy risks to the Australian Government due to the potential collection and exploitation of user and device data. Decisions to install social media applications need to be made on an assessment of the risk, in cases where the application is produced by vendors that are subject to extrajudicial directions from a foreign government whose laws conflict with Australian law.[\/p]"},{"content":"[ul][li]Extensive data collection - Social media applications typically collect extensive data as part of their business model. These applications may also collect additional data from individuals' devices, which extends beyond the content of messages, videos and voice recordings. The type of data collected may change over time, including when new versions or features are released. The terms of use and privacy policies relating to what data is collected, as well as how and when it can be used, may also change at short notice or be difficult to understand. Sometimes this data is stored outside of Australia and may be subject to lawful access or covert collection by other countries. In such cases, current Australian legislation and privacy or consumer laws may not apply.[\/li][li]Exploitation of personal information - Personal information posted to social media can be exploited. Even seemingly benign posts, messages, photos or videos can be used to develop detailed profiles of individuals. This information could be used in extortion or social engineering campaigns aimed at eliciting sensitive information, or influencing individuals to compromise organisations' activities or technology systems.[\/li][\/ul]"},{"content":"[p]In addition, social media content may not come from reputable or trustworthy sources and may contain disinformation.[\/p]"},{"content":"[p]See Procurement, Outsourcing and Contract Management.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"13.5","title":"Legacy Information Technology Management","block":[],"child":[{"type":"section","ident":"13.5.1","title":"Category A","block":[{"content":"[ul][li]Considered an end-of-life product, or[\/li][li]Out of support, and extended support from the manufacturer, vendor or developer.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"section","ident":"13.5.2","title":"Category B","block":[{"content":"[ul][li]Impractical to update or support within the entity, or[\/li][li]No longer cost-effective, or[\/li][li]Considered to be above the current acceptable risk threshold, or[\/li][li]Offers diminishing business utility, or[\/li][li]Prevents or obstructs fulfilment of the entity's IT strategies.[\/li][\/ul]"},{"content":"[p]Legacy IT presents significant and enduring risks to the cyber security posture of Australian Government. Its presence can increase the risk of a cyber security incident, and make any incident that does occur much more impactful. All IT will eventually become legacy and present these acute cyber security risks. The most effective method to mitigate the risk posed by legacy IT is to replace it before it with IT that is still supported. Where legacy IT cannot immediately be replaced, the entity must apply the Australian Signals Directorate's guidance on managing the risks posted by legacy IT. This guidance provides a list of temporary mitigations that entities must consider implementing in addition to any additional mitigations that are relevant to the entity's IT environment. These mitigations are suitable for temporary as the only long-term solution is replacement of legacy IT. See Managing the Risks of Legacy ICT: Practitioner Guidance | Cyber.gov.au[\/p]"},{"requirement":{"identifier":"pspf-0093","index":"0093.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The Australian Signals Directorate's are applied to manage legacy information technology that cannot yet be replaced.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"13.6","title":"Technology Asset Storage","block":[{"content":"[p]A technology asset is defined as any hardware, software or information system, platform, mobile application or 'as-a-service' offering, which stores, processes, transmits or communicates official or security classified information or data belonging to, or utilised by, the Australian Government.[\/p]"},{"content":"[p]A technology asset storage facility is a designated space or floor of an entity's building used to house the entity's technology systems, information technology and operational technology equipment and their components.[\/p]"},{"content":"[lt]These facilities include:[\/lt][ul][li]server and gateway rooms[\/li][li]datacentres[\/li][li]storage areas for equipment that hold, store, process or communicate official information, and[\/li][li]communication and patch rooms.[\/li][\/ul]"},{"content":"[p]See Construct or Lease Entity Facilities.[\/p]"},{"requirement":{"identifier":"pspf-0094","index":"0094.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Technology assets and their components, classified as SECRET or below are stored in the appropriate Security Zone based on their aggregated security classification or business impact level.[\/p]"}]}},{"requirement":{"identifier":"pspf-0095","index":"0095.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Technology assets and their components classified as TOP SECRET are stored in suitable SCEC-endorsed racks or compartments within an accredited Security Zone Five area meeting ASIO Technical Note 5\/12 - Compartments within Zone Five areas requirements.[\/p]"}]}},{"requirement":{"identifier":"pspf-0096","index":"0096.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Outsourced facilities that house technology assets and their components with a catastrophic business impact level are certified by ASIO-T4 physical security and accredited by ASD before they are used operationally.[\/p]"}]}}],"child":[{"type":"section","ident":"13.6.1","title":"Technology Asset Housed in Security Zone","block":[],"child":[],"stats":[]},{"type":"section","ident":"13.6.2","title":"Technology Asset Housed in Layered Security Zones","block":[{"content":"[p]The physical security of containers required to house technology assets and their components may be lowered when the facility is a separate Security Zone (secondary Security Zone) within an existing Security Zone (primary Security Zone) that is suitable for the aggregation of the information held.[\/p]"},{"table":"[table name='Table 23' title='Layered Storage Container Requirements for Technology Assets (other than mobile devices)'][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"13.7","title":"Technology Assets Disposal","block":[{"content":"[p]Entities may need to dispose of physical technology assets due to, advances in technology, the end of the usable life of the physical technology asset, downsizing or changes in business requirements.[\/p]"},{"content":"[p]Entities must dispose of physical technology assets securely. Prior to decommissioning and disposal of physical technology assets such as security containers, cabinets, vaults, strongrooms and secure rooms, the combination locks (electronic and mechanical) need to be reset to factory settings and the asset is visually inspected to remove all contents from the asset.[\/p]"},{"content":"[p]Secure disposal of technology assets may be achieved through either sanitisation or destruction in accordance with the Information Security Manual. Entities may also set their own destruction requirements in addition to those detailed in the Information Security Manual.[\/p]"},{"requirement":{"identifier":"pspf-0097","index":"0097.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Technology assets are disposed of securely in accordance with the Information Security Manual.[\/p]"}]}}],"child":[{"type":"section","ident":"13.7.1","title":"Destruction equipment","block":[{"content":"[p]Destruction equipment is used for security classified information and IT media) so that resultant waste particles cannot be reconstructed to enable the recovery of information.[\/p]"},{"content":"[p]See the Minimum Protections and Handling Requirements for information on the destruction equipment required for each security classification.[\/p]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"14","title":"Cyber Security Strategies","block":[],"child":[{"type":"chapter","ident":"14.1","title":"Cyber Security Strategy","block":[{"content":"[p]Cyber threats faced by the Australian Government include both external and internal malicious actors that steal data, destroy data or attempt to prevent technology systems from functioning. The most common cyber threat facing entities is external malicious actors who attempt to steal data. Often these malicious actors attempt to access technology systems and data through malicious emails and websites. It is critical that entities safeguard the data held on technology systems that can receive emails or browse internet content.[\/p]"},{"content":"[p]A cyber security strategy articulates the entity's plans and priorities for a cyber security uplift to manage cyber security risks. Achieving and maintaining effective cyber security mitigations requires investment, sufficient capability and clear objectives.[\/p]"},{"requirement":{"identifier":"pspf-0098","index":"0098.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]A cyber security strategy and uplift plan is developed, implemented and maintained to manage the entity's cyber security risks in accordance with the Information Security Manual.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"14.2","title":"Essential Eight Strategies","block":[{"content":"[p]The Australian Signals Directorate has developed prioritised mitigation strategies, in the form of Strategies to Mitigate Cyber Security Incidents, to help protect against various cyber threats. The most effective of these mitigation strategies are the Essential Eight.[\/p]"},{"content":"[p]The Essential Eight is designed to protect internet-connected information technology networks. While the principles behind the Essential Eight may be applied to enterprise mobility and operational technology networks, it was not designed for such purposes and alternative mitigation strategies may be more appropriate to defend against unique cyber threats to these environments.[\/p]"},{"content":"[p]Entities are required to implement the Essential Eight strategies to Maturity Level Two under ASD's Essential Eight Maturity Model and consider which of the remaining 29 Strategies to Mitigate Cyber Security Incidents are required to address the entity's threats.[\/p]"}],"child":[{"type":"section","ident":"14.2.1","title":"Patch Applications","block":[{"content":"[p]A patch is a piece of software designed to fix problems or update an application or operating system. This includes fixing security vulnerabilities or other deficiencies as well as improving the usability or performance of an application or operating system.[\/p]"},{"content":"[p]Temporary workarounds or alternative mitigations are required for applications that are no longer supported by vendors to prevent exposing the government to high risk.[\/p]"},{"requirement":{"identifier":"pspf-0099","index":"0099.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Patch applications mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.2","title":"Patch Operating Systems","block":[{"content":"[p]Applying patches to operating systems is critical to ensuring the security of technology systems.[\/p]"},{"content":"[p]Temporary workarounds or alternative mitigations are required for operating systems that are no longer supported by vendors to prevent exposing the government to high risk.[\/p]"},{"requirement":{"identifier":"pspf-0100","index":"0100.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Patch operating systems mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.3","title":"Multi-Factor Authentication","block":[{"content":"[p]Multi-factor authentication is used to authenticate users to the entity's online services and technology systems that process, store or communicate OFFICIAL and security classified data. Multi-factor authentication uses two or more different authentication factors. This mitigation is one of the most effective controls an entity can implement to prevent an adversary from gaining access to an online service or technology system and accessing OFFICIAL or security classified data. When implemented correctly, multi-factor authentication can make it significantly more difficult for an adversary to steal legitimate credentials to facilitate further malicious activities on an online service or technology system.[\/p]"},{"requirement":{"identifier":"pspf-0101","index":"0101.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Multi-factor authentication mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.4","title":"Restrict Administrative Privileges","block":[{"content":"[p]User accounts with administrative privileges are an attractive target for malicious actors because they have a high level of access to an entity's technology systems and data. Restricting administrative privileges makes it difficult for malicious actors to spread or hide their existence.[\/p]"},{"content":"[p]Privileged accounts that cannot access emails or open attachments, cannot browse the internet, or obtain files via internet services (such as instant messaging or social media) minimise opportunities for these accounts to be compromised.[\/p]"},{"requirement":{"identifier":"pspf-0102","index":"0102.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Restrict administrative privileges mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.5","title":"Application Control","block":[{"content":"[p]Malicious code (malware) often aims to exploit vulnerabilities in existing applications and does not need to be installed on workstations or servers to be successful. If appropriately configured, application control helps to prevent undesired execution of software regardless of whether the software was downloaded from a website, clicked on as an email attachment or introduced via CD\/DVD\/USB removable storage media.[\/p]"},{"requirement":{"identifier":"pspf-0103","index":"0103.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Application control mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.6","title":"Restrict Microsoft Office Macro Settings","block":[{"content":"[p]Microsoft Office files can contain embedded code (known as a macro). A macro can contain a series of commands that can be coded or recorded, and replayed at a later time to automate repetitive tasks. An adversary can also create macros to perform a variety of malicious activities, such as assisting to compromise workstations in order to exfiltrate or deny access to OFFICIAL or security classified data.[\/p]"},{"requirement":{"identifier":"pspf-0104","index":"0104.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Restrict Microsoft Office macros mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.7","title":"User Application Hardening","block":[{"content":"[p]This mitigation strategy significantly helps to reduce the attack surface of users' workstations. It also helps to mitigate malicious actors using malicious content in an attempt to evade application control by either exploiting an application's legitimate functionality, or exploiting a vulnerability for which a vendor patch is unavailable.[\/p]"},{"requirement":{"identifier":"pspf-0105","index":"0105.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]User application hardening mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.8","title":"Regular Backups","block":[{"content":"[p]Regular backups ensure that entities are able to recover their technology systems and data in the event of a disruptive or destructive cyber security incident. The backups include all important data, software and configuration settings for software, network devices and other IT equipment.[\/p]"},{"requirement":{"identifier":"pspf-0106","index":"0106.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Regular back-ups mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"14.2.9","title":"Remaining Strategies","block":[{"content":"[p]While the remaining mitigation strategies from the Strategies to Mitigate Cyber Security Incidents are not mandatory, entities must consider each of these strategies and implement those that are needed to protect the entity.[\/p]"},{"content":"[lt]The suggested implementation order for the remaining strategies is:[\/lt][ul][li]targeted cyber intrusions and other external malicious actors who steal data[\/li][li]ransomware denying access to data for monetary gain, and external malicious actors who destroy data and prevent computers\/networks from functioning[\/li][li]malicious insiders who steal data such as customer details or intellectual property, and[\/li][li]malicious insiders who destroy data and prevent computers\/networks from functioning.[\/li][\/ul]"},{"content":"[p]When implementing a mitigation strategy, first implement it for high risk users and computers such as those with access to important (security classified or high-availability) data, and then implement it for all other users and computers.[\/p]"},{"requirement":{"identifier":"pspf-0107","index":"0107.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The remaining mitigation strategies from the Strategies to Mitigate Cyber Security Incidents are considered and, where required, implemented to achieve an acceptable level of residual risk for their entity.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"14.3","title":"Alternate Cyber Security Standards","block":[{"content":"[p]There are a number of other Australian and International Standards that aim to protect against cyber security related risks, including ISO\/IEC 27001 Information Technology - Security Techniques - Information Security Management Systems. While alternative standards are useful as a resource, they are not specifically targeted for the Australian Government and are not suitable for use as an alternative authorisation to operate pathway.[\/p]"},{"content":"[p]Entities that elect to rely on these alternate standards are required to detail why it was necessary to deviate from ASD's Information Security Manual and Strategies to Mitigate Cyber Security Incidents in their annual report on security to their minister and the Department of Home Affairs.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"15","title":"Cyber Security Programs","block":[],"child":[{"type":"chapter","ident":"15.1","title":"Whole of Government Cyber Security Services","block":[{"content":"[p]Protective Domain Name System (PDNS) services, or other security mechanisms that use reputation or content categorisation, must be used to block connections to and from known malicious endpoints.[\/p]"},{"content":"[p]A PDNS service can be an effective way of blocking connection made by an entity's technology system, or a malicious actor on an entity's technology system, to known malicious domains - either as part of an initial compromise or subsequent command and control activities. Domain Name System (DNS) event logs captured by a PDNS service can also be useful for investigating an exploitation attempt or successful compromise of a technology system.[\/p]"},{"content":"[p]The Australian Signals Directorate offers Commonwealth entities a PDNS service, known as AUPDNS, free of charge. Commercial offerings are also available.[\/p]"},{"requirement":{"identifier":"pspf-0108","index":"0108.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]A Protective Domain Name System service or other security mechanisms is used to prevent connections to and from known malicious endpoints.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"15.2","title":"Secure Cloud Strategy","block":[{"content":"[p]The Department of Home Affairs' Secure Cloud Strategy and ASD's suite of cloud security publications provides guidance on adopting cloud computing. At its core, cloud computing involves outsourcing a part, or all, of an entity's IT capability to a cloud service provider. This outsourcing brings a reduction in control and oversight of the technology stack, as the service provider dictates both the technology and operational procedures available to the cloud consumers using its cloud services.[\/p]"},{"requirement":{"identifier":"pspf-0109","index":"0109.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Cloud Service Providers that have completed an IRAP assessment against the current version of ASD's Information Security Manual within the previous 24 months are used.[\/p]"}]}},{"requirement":{"identifier":"pspf-0110","index":"0110.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Entities consider IRAP assessment recommendations and findings and implement on a risk-based approach.[\/p]"}]}}],"child":[{"type":"section","ident":"15.2.1","title":"Australian Government Hosting Certification Framework","block":[{"content":"[p]The Department of Home Affairs' Australian Government Hosting Certification Framework provides policy guidance on securely hosting government data using cloud services or data centres and associated infrastructure. The Hosting Certification Framework reduces risks associated with access to information and data, supply chain of processed, stored or communicated information and data, and ownership and control of services providers.[\/p]"},{"content":"[p]While use of outsourced date centre services or cloud computing can significantly enhance an entity's cyber security, they also presents other risks that need to be considered and managed. Entities electing to use cloud computing services or data centres services are required to use Hosting Certification Framework certified suppliers for security classified government information and data, a whole of government system or system rated at the classification levels of OFFICIAL: Sensitive and PROTECTED. Entities may use the services of an uncertified provider for non-sensitive government information (OFFICIAL) and commercial information and data.[\/p]"},{"content":"[p]Entities seeking to use SECRET or TOP SECRET cloud services must only use community or private clouds in accordance with Information Security Manual.[\/p]"},{"requirement":{"identifier":"pspf-0111","index":"0111.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]OFFICIAL: Sensitive and PROTECTED government information and data is securely hosted using a Cloud Service Provider and Data Centre Provider that has been certified against the Australian Government Hosting Certification Framework.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"15.2.2","title":"Data Centres","block":[{"content":"[p]The Department of Home Affairs assesses outsourced data centre providers and cloud service providers against the Hosting Certification Framework, and maintains a list of certified service providers.[\/p]"},{"content":"[p]When buying data centre space and services, non-corporate Commonwealth entities are required to use the Digital Transformation Agency's (DTA) Data Centre Facilities Supplies Panel. DTA's 'BuyICT Portal' leverages the Data Centre Facilities Supplies Panel for buying certified data centre space and services.[\/p]"},{"content":"[p]See Procurement, Outsourcing and Contract Management.[\/p]"},{"requirement":{"identifier":"pspf-0112","index":"0112.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]The Data Centre Facilities Supplies Panel is used when procuring certified data centre space and services.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"15.2.3","title":"Offshore or Foreign-Owned Cloud Services and Managed Service Providers","block":[{"content":"[p]Foreign ownership of a managed service provider or cloud service provider presents risks to data. An entity's ability to manage and control resources in an outsourced, offshore or supply chain arrangement is impacted by the service provider's locality, ownership and control. These arrangements need to be considered as part the entity's assessment to determine if the service provider is suitable for handling its data.[\/p]"},{"content":"[p]Foreign-owned service providers may be subject to extrajudicial control and interference by a foreign entity. This could include a foreign entity compelling a service provider to disclose its customers' data unbeknownst to its customers.[\/p]"},{"content":"[p]The service provider's administration arrangements and location where support is provided from should also be considered. Depending on the locations, this can impact personnel pre-employment screening practices, as different countries have different laws about the degree of data that employers can request from their employees.[\/p]"},{"content":"[p]Refer to Australian Signals Directorate's Cloud Assessment and Authorisation and ASIO's Protective Security Circular 149\u2014 Physical security certification of outsourced information and communications technology facilities (on GovTEAMS).[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"15.3","title":"Internet Gateway Policy","block":[{"content":"[p]A gateway is a data flow control mechanism-it securely manages data flows between connected technology systems from different security domains. The Department of Home Affairs' Gateway Policy, as part of the Resilient Digital Infrastructure Framework (RDIF) details security protections and capabilities between security domains.[\/p]"},{"content":"[p]Gateways play a vital role in securing a technology system by providing entities with protection at its perimeter. However, they are only one element of a layered defensive strategy. Gateways can be shared between multiple entities, providing the benefits of a common suite of cyber security defences. As such, threats to technology systems (for example, distributed denial of service attacks, botnets, malware, web application attacks and web-based attacks) can be efficiently mitigated through appropriately configured gateways. At the same time, entities may require the flexibility to source additional security services in a manner that best suits their operational needs and risk environment.[\/p]"},{"requirement":{"identifier":"pspf-0113","index":"0113.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Internet-connected technology systems, and the data they process, store or communicate, are protected by a gateway in accordance with the Information Security Manual and the Gateways Policy[\/p]"}]}},{"requirement":{"identifier":"pspf-0114","index":"0114.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p]Gateways that have completed an IRAP assessment against ASD's Information Security Manual within the previous 24 months are used.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"15.4","title":"Vulnerability Disclosure Program","block":[{"content":"[p]A vulnerability disclosure program (VDP) is a collection of processes and procedures designed to identify, verify, resolve and report on vulnerabilities disclosed by both internal and external sources.[\/p]"},{"content":"[p]Implementing a vulnerability disclosure program, based on responsible disclosure, can assist entities, vendors and service providers to improve the security of their products and services as it provides a way for security researchers, customers and members of the public to responsibly notify them of potential vulnerabilities in a coordinated manner. Furthermore, following the verification and resolution of a reported vulnerability, it can assist entities, vendors and service providers in notifying their customers of any vulnerabilities that have been discovered in their products and services and any recommended security patches, updates or mitigations.[\/p]"},{"requirement":{"identifier":"pspf-0115","index":"0115.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"TECH","applicability":"ALL","content":[{"content":"[p] A vulnerability disclosure program and supporting processes and procedures are established to receive, verify, resolve and report on vulnerabilities disclosed by both internal and external sources[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"domain","label":"Part Five","name":"PER","title":"Personnel","block":[{"content":"[ul][li]Pre-Employment Eligibility[\/li][li]Access to Resources[\/li][li]Security Vetting Process[\/li][li]High Office Holders and their Support Staff[\/li][li]Maintenance and Ongoing Assessment[\/li][li]Separation[\/li][\/ul]"}],"child":[{"type":"part","ident":"16","title":"Pre-Employment Eligibility","block":[],"child":[{"type":"chapter","ident":"16.1","title":"Pre-Employment Screening","block":[{"content":"[p]All personnel working in and for Australian Government entities are required to undergo pre-employment screening, regardless of whether the position requires a security clearance or not. Personnel includes security cleared and non-security cleared personnel, contractors and others who will have access to Australian Government resources (that is technology systems, assets and facilities).[\/p]"},{"content":"[p]Pre-employment screening provides a level of assurance that personnel are suitable to access Australian Government resources and is a primary activity used to mitigate an entity's personnel security risks. PSPF pre-employment screening checks may be supplemented by entity-specific screening where required.[\/p]"},{"content":"[p]Pre-employment screening takes place after the conclusion of the merit selection process but prior to an offer of employment or contract. Completing screening prior to engagement is particularly important for positions that have been identified as requiring a security clearance. If an individual is found to be unsuitable as part of the pre-employment and entity-specific screening, entities must not seek a security clearance for the individual. Where checks are not completed prior to engagement, it is recommended that entities make the employment or contract conditional on satisfying the required checks within a reasonable timeframe.[\/p]"},{"content":"[p]Individuals cannot obtain a security clearance unless they are expected to be engaged in a role requiring a security clearance. Therefore, it is not reasonable to expect an individual to hold a security clearance prior to being selected for a designated role. Selection based on existing clearance status is not merit based and may be contrary to an entity's enabling legislation. Entities that are legislatively required to make employment decisions in accordance with the merit principle cannot discriminate against individuals who do not hold a current security clearance where they indicate a willingness and ability to gain a clearance prior to engagement.[\/p]"},{"requirement":{"identifier":"pspf-0116","index":"0116.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The eligibility and suitability of personnel who have access to Australian Government people and resources is ensured.[\/p]"}]}}],"child":[{"type":"section","ident":"16.1.1","title":"Pre-Employment Screening Checks","block":[{"content":"[p]Pre-employment screening checks, including related security clearance vetting and ongoing suitability checks, are conducted in accordance with the Australian Privacy Principles.[\/p]"},{"content":"[p]Authorised Vetting Agencies may conduct pre-employment screening concurrently with security vetting to permit streamlined engagement of personnel. If conducted concurrently, the Authorised Vetting Agency should record the vetting determination against the criteria and identify whether a decision relates to a pre-employment screening threshold or a security clearance threshold.[\/p]"},{"content":"[p]Pre-employment screening checks for personnel transferring within the Australian Government may have already been conducted. The gaining entity should confirm what checks have been undertaken by the losing entity. Additional checks can be done to meet the specific entity employment requirements of the gaining entity or if the check needs to be revalidated.[\/p]"},{"content":"[p]See Locally Engaged Staff for advice on pre-employment screening arrangements.[\/p]"}],"child":[{"type":"topic","ident":"16.1.1.1","title":"Identity Checks","block":[{"content":"[p]An identity check helps to establish confidence in a person's identity and provides entities with a level of assurance about the prospective employee.[\/p]"},{"content":"[p]The National Identity Proofing Guidelines provide a more robust approach to identity proofing than the traditional '100 point check', and aligns with international best-practice standards.[\/p]"},{"content":"[lt]The National Identity Proofing Guidelines have four levels of assurance. Level of Assurance 3 (high) is the minimum for pre-employment screening identity checks, and includes:[\/lt][ul][li]the uniqueness of the identity in the intended context[\/li][li]the claimed identity is legitimate[\/li][li]the operation of the identity in the community over time[\/li][li]the linkage between the identity and the person claiming the identity, and[\/li][li]the identity is not known to be used fraudulently.[\/li][\/ul]"},{"content":"[p]Verification of a person's claimed identity where no prior government records exist, may be verified with a reputable organisation, trusted referee or bodies known to them. For example, Aboriginal and Torres Strait Islander organisations may not hold, or be able to verify, the identity of clients where no prior government record exists. A trusted referee is a person or organisation that holds a position of trust in the community and does not have a conflict of interest, such as an Aboriginal elder or reputable organisation that the person is a customer, employee or contractor of, and is known and listed by the enrolling agency to perform the function of a referee. The Statutory Declarations Act 1959 provides a list of people who hold a position of trust in the community. Similar lists are also generally included in state and territory legislation. Trusted referees may also include guardians or other people nominated to act on a person's behalf whose identities have been verified.[\/p]"},{"requirement":{"identifier":"pspf-0117","index":"0117.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The pre-employment screening identity check is conducted for all personnel, to verify identity to at least Level 3 (High) of Assurance of the National Identity Proofing Guidelines.[\/p]"}]}},{"content":"[p]The Identity Verification Services Act 2023 (Cth) provides a legislative basis for the operation of the identity verification services. A key element of the identity check is verifying whether the biographic information on the identity document matches the original record through an identity verification solution that checks source documents.[\/p]"},{"content":"[p]The Document Verification Service's (DVS) identity matching service can verify 14 different types of identity documents, including birth certificates, driver licences and Medicare cards. For information on how to access the DVS see the Identity Matching Services website. Other source identity verification solutions may be used if they meet the same standard as the DVS.[\/p]"},{"content":"[p]The entity may omit the identity check in circumstances where obtaining a security clearance prior to engagement is a condition of employment and pre-employment screening is unlikely to be predictive of security clearance suitability.[\/p]"},{"requirement":{"identifier":"pspf-0118","index":"0118.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Biographic information in identity documents is verified to ensure the information matches the original record.[\/p]"}]}}],"child":[],"stats":[]},{"type":"topic","ident":"16.1.1.2","title":"Eligibility Check","block":[{"content":"[p]An eligibility check confirms whether a person is eligible to work in Australia. This requires confirmation that a person holds Australian Citizenship, or if the person is not an Australian citizen, confirming that they have a valid work visa. For information see the Migration Act 1958.[\/p]"},{"content":"[p]Further eligibility conditions, including requirements relating to Australian citizenship, are covered in the Public Service Act 1999 and in the enabling legislation of many entities.[\/p]"},{"content":"[p]Australian citizenship is obtained either automatically or by application. Section 17 of the Australian Citizenship Act 1948 provides that Australians over the age of 18 who took action to acquire the nationality or citizenship of a foreign country between 26 January 1949 and 3 April 2002, automatically ceased to be an Australian citizen. Australians impacted by this change can apply to resume their Australian citizenship. On 4 April 2002, section 17 of the 1948 Act was repealed. This enabled Australian citizens to acquire dual citizenship without losing their Australian citizenship. A dual citizen is a person who holds citizenship of two or more countries.[\/p]"},{"content":"[p]Information on how to confirm Australian citizenship, apply to resume citizenship and verify visas is available on the Department of Home Affairs website.[\/p]"},{"requirement":{"identifier":"pspf-0119","index":"0119.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The pre-employment screening eligibility check is conducted for all personnel, to confirm their eligibility to work in Australia and for the Australian Government.[\/p]"}]}},{"requirement":{"identifier":"pspf-0120","index":"0120.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The entity obtains assurance of each person's suitability to access Australian Government resources, including their agreement to comply with the government's policies, standards, protocols and guidelines that safeguard resources from harm, during pre-employment screening.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"section","ident":"16.1.2","title":"Personnel Transferring within the Australian Government","block":[{"content":"[p]Pre-employment screening checks for personnel transferring within the Australian Government may have already been conducted. The gaining entity should confirm what checks have been undertaken by the losing entity. Additional checks can be done to meet the specific entity employment requirements of the gaining entity or if the check needs to be revalidated.[\/p]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"17","title":"Access to Resources","block":[{"content":"[p]The need-to-know principle applies to all security classified information and resources. It reflects the need for personnel to access this information only where there is an operational requirement to do so. The practice helps personnel understand their responsibility to protect information, including the correct methods for storage, handling and dissemination.[\/p]"}],"child":[{"type":"chapter","ident":"17.1","title":"Temporary Access to Resources","block":[{"content":"[p]Temporary access to classified information may be required in some limited circumstances. Temporary access may be provided up to and including PROTECTED level information without a security clearance, after the risks of doing so have been assessed and for limited time periods. Temporary access to SECRET information requires an existing Baseline security clearance and TOP SECRET information requires an existing Negative Vetting 1 security clearance.[\/p]"},{"content":"[lt]There are two types of temporary access to security classified information:[\/lt][ul][li]Short-term temporary access - where the person does not hold a clearance at the appropriate level (but has a valid need-to-know and requires immediate access to relevant information, system or resources) and the risks can be managed. This may include, but is not limited to:[ul][li]new starters[\/li][li]people on short-term projects[\/li][li]people who are reasonably expected to have only incidental or accidental contact with security classified information (e.g. security guards, cleaners, external IT personnel, researchers and visitors such as children who do not have an ability to comprehend the classified information, that is children aged under 10 years of age)[\/li][\/ul][\/li][li]Provisional temporary access - where the person has commenced a clearance process by providing the relevant details for assessment by an Authorised Vetting Agency, and immediate access is urgently required. Provisional temporary access can be maintained until a security clearance is granted or denied.[\/li][\/ul]"},{"content":"[p]Short-term access can be changed to provisional once the Authorised Vetting Agency has confirmed that the completed security clearance pack has been received and advises the entity that no initial concerns have been identified.[\/p]"},{"content":"[p]See Australian Government Personnel Security Adjudicative Standard for further guidance.[\/p]"},{"requirement":{"identifier":"pspf-0121","index":"0121.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Prior to granting temporary access to security classified information or resources, pre-employment checks are completed, and an existing Negative Vetting 1 security clearance is confirmed prior to granting temporary access to TOP SECRET information data or resources.[\/p]"}]}}],"child":[{"type":"section","ident":"17.1.1","title":"Temporary Access Risk Assessment","block":[{"content":"[p]Temporary access may only be granted after a security risk assessment has been completed and if security risks arising from the proposed action are identified, they are assessed as manageable.[\/p]"},{"content":"[lt]When conducting a risk assessment for temporary access, the entity must consider:[\/lt][ul][li]the need for temporary access, including if the role can be performed by a person who already holds the necessary clearance.[\/li][li]confirmation from the Authorised Vetting Agency that the person has no identified concerns, or a clearance that has been cancelled or denied.[\/li][li]potential conflicts of interest.[\/li][li]the period of access under consideration, noting the time limitations imposed on short-term access.[\/li][li]proposed risk management measures, including any conditions placed on the clearance holder subject to the waiver or temporary access.[\/li][li]the quantum and classification level of matters that could be accessed, and the potential business impact if these matters were compromised.[\/li][li]how access to classified information will be supervised, including how access to caveat or compartmented classified information will be prevented, and[\/li][li]other risk mitigating factors such as pre-engagement screening, entity specific character checks, and knowledge of personal history, previous security clearance issues of concern, and security breaches.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0122","index":"0122.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]A risk assessment determines whether a person is granted temporary access to security classified information or resources.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"17.1.2","title":"Supervise Temporary Access","block":[{"content":"[lt]Entities must supervise all temporary access. Examples include:[\/lt][ul][li]escorting visitors in premises where classified information is being stored or used[\/li][li]oversight of the work completed by personnel with temporary access, and[\/li][li]monitoring or audit logging of incidences of contact with security classified information (e.g. contract conditions that require service providers to report when any of their contractors have had contact with security classified information or activities).[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0123","index":"0123.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Temporary access to security classified information, resources and activities is supervised.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"17.1.3","title":"Limit Duration of Temporary Access","block":[{"content":"[lt]Entities must limit the duration of access to security classified information as follows:[\/lt][ul][li]Short-term access - an individual can be granted access for a total combined maximum of 3-months in a 12-month period for all entities (e.g. Entity A: 2 months, and Entity B: one month), and[\/li][li]Provisional access - an individual can be granted access until a security clearance is granted or denied.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0124","index":"0124.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Short-term temporary access to security classified information, resources and activities is limited to the period in which an application for a security clearance is being processed for the particular person, or up to a total combined maximum of three months in a 12-month period for all entities.[\/p]"}]}},{"content":"[p]Short-term access can be changed to provisional once the Authorised Vetting Agency has confirmed that the completed security clearance pack has been received and advises the entity that no initial concerns have been identified.[\/p]"},{"requirement":{"identifier":"pspf-0125","index":"0125.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Authorised Vetting Agency confirms that the completed security clearance pack has been received and that no initial concerns have been identified for the clearance subject, before short-term temporary access is changed to provisional temporary access.[\/p]"}]}},{"content":"[p]In exceptional circumstances, short-term or provisional access to caveated classified information may be granted by the originator and caveat owner (controlling authority) based on the assessed risk and granted on a case-by case basis.[\/p]"},{"requirement":{"identifier":"pspf-0126","index":"0126.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Temporary access to classified caveated information, resources or activities is not granted, other than in exceptional circumstances, and only with the approval of the caveat controlling authority[\/p]"}]}},{"requirement":{"identifier":"pspf-0127","index":"0127.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Prior to granting temporary access, the entity obtains an undertaking from the person to protect the security classified information, resources and activities they will access.[\/p]"}]}},{"requirement":{"identifier":"pspf-0128","index":"0128.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Prior to granting temporary access, the entity obtains agreement from any other entity (or third party) whose security classified information, resources and activities will be accessed by the person during the temporary access period.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"17.2","title":"Ongoing Access to Resources","block":[{"content":"[p]Ongoing access to government information or resources must be appropriately controlled, especially when accessing security classified information outside the entity's facilities or providing access to non-government personnel.[\/p]"},{"content":"[p]Some Australian office holders are not required to hold a security clearance. See Clearance Exemptions for Australian High Office Holders.[\/p]"},{"requirement":{"identifier":"pspf-0129","index":"0129.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Access to official information is facilitated for entity personnel and other relevant stakeholders.[\/p]"}]}},{"requirement":{"identifier":"pspf-0130","index":"0130.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Appropriate access to official information is enabled, including controlling access (including remote access) to supporting technology systems, networks, infrastructure, devices and applications.[\/p]"}]}},{"requirement":{"identifier":"pspf-0131","index":"0131.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Access to security classified information or resources is only given to entity personnel with a need-to-know that information.[\/p]"}]}},{"requirement":{"identifier":"pspf-0132","index":"0132.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Personnel requiring ongoing access to security classified information or resources are security cleared to the appropriate level.[\/p]"}]}},{"requirement":{"identifier":"pspf-0133","index":"0133.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Personnel requiring access to caveated information meet any clearance and suitability requirements imposed by the originator and caveat controlling authority.[\/p]"}]}},{"requirement":{"identifier":"pspf-0134","index":"0134.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p] A unique user identification, authentication and authorisation practice is implemented on each occasion where system access is granted, to manage access to systems holding security classified information.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"17.3","title":"Remote Access to Resources","block":[{"content":"[p]A service-wide, principles-based approach to working flexibility in the Australian Public Service (APS) was endorsed by the Secretaries Board in March 2023. A common clause on flexible working arrangements has been included in all APS enterprise agreements.[\/p]"}],"child":[{"type":"section","ident":"17.3.1","title":"Working Remotely in Australia","block":[{"content":"[p]Working remotely for the purposes of the PSPF, is defined as all work outside of the entity's facilities in Australia using either portable mobile devices or remote access to the entity's services, information and technology systems. Working remotely includes home-based work, working in another government entity's facilities in Australia, and field work undertaken on behalf of the entity by contractors, but does not include any work undertaken by contractors in their own facilities.[\/p]"}],"child":[{"type":"topic","ident":"17.3.1.1","title":"Working from Home","block":[{"content":"[p]Flexible work is a core part of the way the APS does business, including access to working from home arrangements where it is agreed to do so. Under the Fair Work Act 2009 and the common clause on flexible working arrangements, which has been largely replicated in APS enterprise agreements, requests to work from home can only be denied on reasonable business grounds. The common clause provides examples of reasonable business grounds, including where it would not be possible to accommodate the working arrangements without significant changes to security requirements. In making decisions about working from home arrangements, the delegate must comply with the Fair Work Act 2009 and the relevant entity's enterprise agreement. This supports the Accountable Authority to ensure operational requirements are met and the entity's services continue to be delivered.[\/p]"},{"content":"[p]Remote working arrangements to support home-based work must adhere to the Minimum Protections and Handling Requirements mandated for Working Remotely in Australia (including home-based work).[\/p]"}],"child":[],"stats":[]},{"type":"topic","ident":"17.3.1.2","title":"Working in Another Government Entity's Facilities in Australia (Hosted or Co-location Arrangements)","block":[{"content":"[p]The Accountable Authority is responsible for safeguarding the entity's people and resources from harm or compromise. In order to fulfil these requirements, the Accountable Authority needs to maintain control over where the entity's people and resources are located, and the security decisions relating to these locations.[\/p]"},{"content":"[p]When making property decisions in line with the Commonwealth Property Management Framework (such as the effective and efficient use of office space through co-locating staff within another entity's property, locating another entity's staff in their property or wholly assigning a lease to or from another entity) the accountable authority needs to assess the security risks associated with these arrangements, and consider the environment in which the other entity operates, its security culture and practice and the type of information that will be used in the facilities. Co-location or hosted arrangements must adhere to the Minimum Protections and Handling Requirements. The Accountable Authority, with support from the CSO, remains responsible even where personnel or resources are located or hosted in another Government entity's facilities.[\/p]"},{"requirement":{"identifier":"pspf-0135","index":"0135.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]A security risk assessment of the proposed location and work environment informs decisions by the Chief Security Officer to allow personnel to work in another government entity's facilities in Australia.[\/p]"}]}},{"requirement":{"identifier":"pspf-0136","index":"0136.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]An agreement is in place to manage the security risks associated with personnel working in another government entity's facilities in Australia.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"section","ident":"17.3.2","title":"Working Remotely Outside of Australia (International)","block":[{"content":"[p]Working remotely outside of Australia includes working at entity facilities located internationally, Australian Government international missions and international posts, including those managed by the Department of Foreign Affairs and Trade (DFAT), and remote home-based work outside of an Australian Government entity facility, mission or post.[\/p]"}],"child":[{"type":"topic","ident":"17.3.2.1","title":"Working Inside an Australian Government International Entity Facility, Mission or Post","block":[{"content":"[p]In accordance with the Prime Minister's Directive on Guidelines for Management of the Australian Government Presence Overseas (February 2007), the Department of Foreign Affairs and Trade (DFAT) is responsible for all aspects of security policy affecting Australian missions and staff attached to DFAT-managed missions. International entity facilities managed entities other than DFAT are the responsibility of the entity managing the facility.[\/p]"},{"content":"[p]All Australian Government international missions and international posts, including those managed by DFAT are required to meet the PSPF requirements, unless a specific legislative provision allows for alternative arrangements. See International Entity Facilities (including Missions and Posts).[\/p]"}],"child":[],"stats":[]},{"type":"topic","ident":"17.3.2.2","title":"Working Outside of an Australian Government International Entity Facility, Mission or Post","block":[{"content":"[p]Security considerations are key when making decisions about the geographic location of personnel, particular in working overseas.[\/p]"},{"content":"[p]Not all locations are suitable for international remote work arrangements, particularly countries that have extensive collection of user data or are subject to extrajudicial directions from a foreign government that conflict with Australian law. Contact ASIO for country-specific threat assessment advice from the National Intelligence Community.[\/p]"},{"content":"[p]Decisions to approve extended working remotely at international location arrangements must not expose government information, data or systems to compromise or unacceptable risk. Entities that choose to allow their personnel to work remotely at international locations for extended periods (i.e. not for short-term travel) must assess and record the risk in each instance and ensure the remote facilities meet the minimum protections and handling requirements for the classification of information.[\/p]"},{"content":"[p]The Minimum Protections and Handling Requirements for Australian Government security classified information and resources do not change when personnel are working overseas. The same PSPF requirements must be met. In fact, international remote working arrangements are likely to increase the security risks and may lead to unexpected exposure to insider threat and compromise of information's confidentiality.[\/p]"},{"content":"[p]Each request requires a risk assessment to determine whether the country and the proposed work environment (including the workspace, IT equipment, access, storage facilities and connectivity) are sufficient to meet the requirements of the PSPF and ISM. It would be challenging to work with information and mobile devices at the PROTECTED level and above, in workspaces outside of an Australian Government international facility, post, chancery, embassy or consulate.[\/p]"},{"content":"[p]Contact the DFAT for advice, as it is responsible for security arrangements at international posts, including providing security awareness training for Australian Government personnel deployed or posted overseas.[\/p]"},{"requirement":{"identifier":"pspf-0137","index":"0137.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Approval for remote access to TOP SECRET information, data or systems in international locations outside of facilities meeting PSPF requirements, is only granted if approved by the Australian Signals Directorate.[\/p]"}]}},{"requirement":{"identifier":"pspf-0138","index":"0138.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]A security risk assessment of the proposed location and work environment informs decisions to allow personnel to work remotely in international locations.[\/p]"}]}},{"requirement":{"identifier":"pspf-0139","index":"0139.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p] Personnel are not granted approval to work remotely in locations where Australian Government information, or resources are exposed to extrajudicial directions from a foreign government that conflict with Australian law, unless operationally required, and the residual risks are managed and approved by the Chief Security Officer.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"18","title":"Security Clearances","block":[{"content":"[p]Security vetting is conducted to determine whether an individual is eligible and suitable to hold a security clearance in order to access security classified government information, resources and activities. To be eligible for an Australian Government security clearance, an individual must be an Australian citizen, have a checkable background and possess and demonstrate integrity and trustworthiness commensurate with the security classified information, resources and activities they will be expected to protect.[\/p]"},{"content":"[p]The security vetting process details the standardised vetting practices to be undertaken when employing personnel and contractors. These practices provide a high-quality and consistent approach to managing personnel eligibility and suitability risk across government. Security vetting applies to Australian Government Baseline, Negative Vetting 1, Negative Vetting 2 and Positive Vetting security clearances.[\/p]"},{"content":"[lt]The security vetting process establishes confidence that an individual possesses a sound and stable character, and they are not unduly vulnerable to key national security threats such as:[\/lt][ul][li]espionage - a form of theft,[\/li][li]sabotage - violence or damage (physical or other) aimed at destroying, degrading, corrupting or delaying access to information or capabilities[\/li][li]foreign interference - including influence and corruption operations, and[\/li][li]political violence.[\/li][\/ul]"},{"content":"[p]These activities could overlap with each other and with non-national security threats. Non-national security threats that may also be protected by these security measures include theft, fraud, criminal damage or criminal violence.[\/p]"},{"content":"[p]Individuals who require ongoing access to Australian Government security classified information, technology systems and resources must hold a security clearance, commensurate with the security classification, unless the entity specifies a higher security clearance is necessary for operational requirements. The security clearance level required is not based on the person's rank, seniority or status.[\/p]"}],"child":[{"type":"chapter","ident":"18.1","title":"Security Clearances","block":[{"content":"[p]A security clearance is a statement of assurance that a person is both eligible and, so far as can be determined at the time that the clearance is issued, suitable to hold a position of trust that gives them access to security classified Australian Government information, resources and activities.[\/p]"},{"content":"[p]It is a point in time judgement that must be accompanied by ongoing security management of those holding clearances to ensure that they remain suitable.[\/p]"},{"content":"[p]Individuals who require ongoing access to Australian Government security classified information, resources and activities must hold a security clearance, commensurate with their security classification. The security clearance level required is not based on the person's rank, seniority or status, but on the necessary access required to perform their identified position (see Identifying and Recording Positions that Require a Security Clearance).[\/p]"}],"child":[{"type":"section","ident":"","title":"Security Clearance Levels","block":[{"content":"[p]The Australian Government has four security clearance levels, noting Positive Vetting security clearances are being phased out and replaced with TS-PA security clearances. Clearances are linked to and reflective of the security classification system. This system applies a security classification to information, resources and activities that require security protection.[\/p]"},{"content":"[p]Table 24 details the Australian Government security clearance levels required to access security classified information, resources and activities.[\/p]"},{"table":"[table name='Table 24' title='Australian Government Security Clearances Levels'][\/table]"}],"child":[],"stats":[]},{"type":"section","ident":"18.1.2","title":"Security Clearance Status","block":[{"table":"[table name='Table 25' title='Australian Government Security Clearances Status'][head][cell]Security Clearance Status[\/cell][cell]Definition[\/cell][\/head][row][cell]Active[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Inactive[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Expired[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Ceased[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t[\/cell][\/row][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"18.2","title":"Authorised Vetting Agencies","block":[{"content":"[p]Security vetting may only be performed by Authorised Vetting Agencies authorised to assess, process and grant security clearances for Australian Government entities.[\/p]"},{"content":"[p]The Australian Government Security Vetting Agency (AGSVA) conducts security vetting for Australian Government entities, unless the entity has been authorised to conduct security vetting for its own personnel. Authorised Vetting Agencies must conduct security vetting in a manner consistent with the PSPF and the Personnel Security Adjudicative Standard.[\/p]"},{"content":"[p]The term 'vetting analyst' denotes a person within an Authorised Vetting Agency who conducts vetting assessments. The term 'security clearance delegate' denotes a person formally authorised to make decisions on the outcome of a vetting process (i.e. to grant, deny, grant-conditional, revoke or cancel a security clearance).[\/p]"},{"requirement":{"identifier":"pspf-0140","index":"0140.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Australian Government Security Vetting Agency (AGSVA) or the TOP SECRET-Privileged Access Vetting Authority is used to conduct security vetting, or where authorised, the entity conducts security vetting in a manner consistent with the Personnel Security Vetting Process and Australian Government Personnel Security Adjudicative Standard.[\/p]"}]}},{"content":"[p]See Authorised Vetting Agencies and TOP SECRET-Privileged Access Authority.[\/p]"}],"child":[{"type":"section","ident":"18.2.1","title":"Competencies of Vetting Personnel","block":[{"content":"[p]Authorised Vetting Agencies are required to ensure vetting personnel (i.e. vetting analysts and security clearance delegates) maintain the required skills and competencies for their role. PSPF Guidelines for a list of recommended competencies and skills. These competencies and skills can be attained through formal qualifications, such as the Certificate IV or Diploma in Government Security (Personnel Vetting), or equivalent qualifications. Where Authorised Vetting Agencies determine that a formal qualification is required for vetting personnel in the agency, they should be obtained from a registered training organisation. A list of registered training organisations is available at www.training.gov.au.[\/p]"},{"requirement":{"identifier":"pspf-0141","index":"0141.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]All vetting personnel attain and maintain the required skills and competencies for their role.[\/p]"}]}},{"content":"[p]The TS-PA Standard establishes the minimum qualifications and specific competencies for practitioners for TS-PA security clearances.[\/p]"},{"content":"[p]See PSPF Guidelines for recommended competencies and skills.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"18.3","title":"Recognition of Existing Security Clearances","block":[{"content":"[p]Where an individual holds, or has previously held, a security clearance issued by an Authorised Vetting Agency at the level required for the identified position (or higher), an entity may assume sponsorship of that security clearance.[\/p]"},{"content":"[p]Prior to seeking a new security clearance, the sponsoring entities must identify whether the clearance subject already holds, or has previously held, a security clearance, and advise the Authorised Vetting Agency accordingly. The Authorised Vetting Agency will confirm the clearance details with the granting agency, obtain the clearance subject's personal security file and record the new sponsorship of the security clearance on the file.[\/p]"},{"content":"[lt]A security clearance held by the clearance subject cannot be recognised if:[\/lt][ul][li]the clearance has expired due to the period since the clearance being granted (or last revalidated) exceeding periods as defined in Table 26[\/li][li]the Authorised Vetting Agency has concerns that the incoming clearance subject is no longer eligible or suitable to access Australian Government security classified resources at that clearance level[\/li][li]the clearance was granted on the basis of an eligibility (citizenship or checkable background) waiver[\/li][li]the clearance was granted subject to clearance conditions, or[\/li][li]the clearance has ceased.[\/li][\/ul]"},{"table":"[table name='Table 26' title='Security Clearance Expiration Periods'][head][cell]Security Clearance[\/cell][cell]Expiration Period[\/cell][\/head][row][cell]Baseline[\/cell][cell]15 years[\/cell][\/row][row][cell]Negative Vetting 1 (NV1)[\/cell][cell]10 years[\/cell][\/row][row][cell]Negative Vetting 2 (NV2)[\/cell][cell]7 years[\/cell][\/row][row][cell]Positive Vetting (PV)[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]TOP SECRET-Privileged Access (TS-PA)[\/cell][cell]See the TS-PA Standard for details. This Standard is available to TOP SECRET Privileged Access practitioners via the TOP SECRET-Privileged Access Quality Assurance Office.[\/cell][\/row][\/table]"},{"content":"[p]If a clearance is subject to an eligibility waiver or clearance conditions, the Authorised Vetting Agency will advise the gaining sponsoring entity.[\/p]"},{"requirement":{"identifier":"pspf-0142","index":"0142.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The gaining sponsoring entity establishes new clearance conditions before assuming sponsorship of an existing security clearance that is subject to clearance conditions.[\/p]"}]}},{"requirement":{"identifier":"pspf-0143","index":"0143.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The gaining sponsoring entity undertakes the exceptional business requirement and risk assessment provisions prior to requesting transfer of sponsorship of an existing security clearance that is subject to an eligibility waiver.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"18.4","title":"Sponsoring Security Clearances","block":[{"content":"[p]Security clearances must be sponsored by an Australian Government entity or an organisation otherwise authorised by the Australian Government.[\/p]"},{"content":"[p]State and territory governments may request that AGSVA conduct security clearances for their personnel up to and including Negative Vetting 2, in accordance with the 2007 Memorandum of Understanding for the Protection of National Security Information. States and territories require an Australian Government entity to sponsor all Positive Vetting security clearances for their personnel.[\/p]"},{"requirement":{"identifier":"pspf-0144","index":"0144.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Authorised Vetting Agency only issues a security clearance where the clearance is sponsored by an Australian Government entity or otherwise authorised by the Australian Government.[\/p]"}]}}],"child":[{"type":"section","ident":"18.4.1","title":"Identifying and Recording Positions that Require a Security Clearance","block":[{"content":"[p]Sponsoring entities are required to identify and document the positions that require a security clearance to have ongoing access to Australian Government classified information, resources and activities. Recruitment for positions identified as requiring a security clearance must specify eligibility to obtain a security in the conditions of employment.[\/p]"},{"content":"[p]Given the interrelationships and complementarity of security classification, security information, resources and activities that require protection must be appropriately classified.[\/p]"},{"content":"[p]Entities may use security clearances where they need additional assurance of the suitability and integrity of personnel. This could be for access to security classified information, or to provide greater assurance for designated positions.[\/p]"},{"requirement":{"identifier":"pspf-0145","index":"0145.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Positions that require a security clearance are identified and the level of clearance required is documented.[\/p]"}]}},{"requirement":{"identifier":"pspf-0146","index":"0146.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Each person working in an identified position has a valid security clearance issued by the relevant Authorised Vetting Agency.[\/p]"}]}},{"content":"[p]See Clearance Exemptions for Australian High Office Holders.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"18.5","title":"Eligibility for a Security Clearance","block":[{"content":"[p]To be eligible for an Australian Government security clearance, an individual must be an Australian citizen and have a checkable background. Australian citizenship is determined by the sponsoring entity before requesting a security clearance.[\/p]"},{"content":"[p]General checkable background is determined by the Authorised Vetting Agency as part of the vetting assessment. ASIO may also deem a background as 'security uncheckable' as part of the Security Clearance Suitability Assessment (SCSA) process.[\/p]"},{"content":"[p]Pre-employment screening is the first 'vetting' activity, used to establish a person's eligibility to be employed by or for the Australian Government. It provides limited assurance on personnel security risks. Sponsoring entities are required to confirm that the mandatory pre-employment screen checks are completed before they seek a security clearance from their Authorised Vetting Agency.[\/p]"},{"requirement":{"identifier":"pspf-0147","index":"0147.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Australian citizenship is confirmed and pre-employment screening is completed before the entity seeks a security clearance for a person in a position identified as requiring a security clearance.[\/p]"}]}},{"content":"[p]See Pre-Employment Eligibility and Pre-Employment Screening.[\/p]"}],"child":[{"type":"section","ident":"18.5.1","title":"Checkable and Uncheckable Backgrounds","block":[{"content":"[lt]A 'checkable background' is established when an Authorised Vetting Agency:[\/lt][ul][li]has completed the minimum checks required for the checkable period,[\/li][li]is satisfied that the checks provide an appropriate level of assurance in order to assess the clearance subject's life or background, and[\/li][li]has validated the information provided by the clearance subject with respect to their identity and background from independent and reliable sources.[\/li][\/ul]"},{"content":"[p]An 'uncheckable background' is where the Authorised Vetting Agency is unable to validate the information provided by a clearance subject with respect to their background from independent and reliable sources or authorities.[\/p]"},{"content":"[lt]There are generally two forms of uncheckable background:[\/lt][ul][li]Uncheckable identity - clearance subject is born and substantially raised in a country where the Authorised Vetting Agency cannot reliably check the clearance subject's identity.[\/li][li]Uncheckable period -clearance subject's identity can be confidently established, but the Authorised Vetting Agency is unable to check the clearance subject's activities and associations as they have spent a significant period of time in a high-security risk country where reliable checking is not possible.[\/li][\/ul]"},{"content":"[p]The implications and significance of an uncheckable background will depend on a number of factors, including the security risk associated with the country in which the uncheckable time was spent, the reason the background is uncheckable, or the nature of the clearance subject. If an uncheckable background prevents the Authorised Vetting Agency from positively identifying the clearance subject, this may prevent them from identifying and responding to attempts by a foreign intelligence service, or other threat source, to insert their people into a position of access to Australian Government information, resources or activities. An uncheckable background may also conceal a clearance subject's activities, associations, or beliefs that might be of concern or otherwise relevant to their suitability to hold a security clearance.[\/p]"},{"content":"[p]The degree of confidence the Authorised Vetting Agency has in checks with international countries will vary depending on the relationship Australia has with the government of that country and the level of security risk associated with that country. For example, high confidence in authorities from low-security risk countries that have similar values and government arrangements, and low to no confidence in authorities from high-security risk countries that have authoritarian and undemocratic values that are hostile to Australia. Periods spent in the latter are usually uncheckable.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"18.5.2","title":"Checkable Background Gaps","block":[{"content":"[p]Gaps in a clearance subject's checkable background information due to a period overseas reduces confidence in assessments of suitability but does not necessarily point to a concern to be resolved.[\/p]"},{"content":"[p]Gaps in a subject's checkable background in low-security risk countries may be satisfactorily resolved by using documentary evidence from another reliable source, such as an employer or academic institution, or by information provided by a reliable referee who had first-hand knowledge of the subject and their activities in that location.[\/p]"},{"content":"[p]Gaps relating to a period in a high-security risk country, particularly countries which host or pose a security threat to Australia, is of greater concern and may be indicative of specific security issues requiring resolution. Where the Authorised Vetting Agency determines that despite any gaps, the clearance subject's background is 'checkable' and all vetting issues are dealt with exhaustively, any potential concerns arising from the gaps may be considered as part of ASIO's SCSA.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"18.6","title":"Eligibility Waivers","block":[{"content":"[p]An eligibility waiver is a determination by the Accountable Authority that the advantage to the entity of allowing access to security classified information, resources or activities by a person that does not meet either the required citizenship or checkable background requirements, outweighs the risk involved.[\/p]"},{"content":"[p]The Accountable Authority (or Chief Security Officer if delegated) may waive the citizenship or checkable background requirements, if there is an exceptional business requirement and after conducting a risk assessment, taking into account the ASIO threat assessments relating to the clearance subject's current or former country (or countries) of residence, and where the residual risks of waiving these requirements are assessed and have been accepted.[\/p]"},{"content":"[lt]The Accountable Authority's decision to approve an exceptional business requirement is informed by whether the role:[\/lt][ul][li]is critical to meeting the Sponsoring Entity's outcomes[\/li][li]can be performed by a person who meets the eligibility requirements (i.e. is there another person capable of performing the role who is an Australian citizen and\/or has a checkable background), or[\/li][li]can be redesigned, so that the access to security classified resources is restricted to a person who already holds, or is eligible to hold, the appropriate security clearance.[\/li][\/ul]"},{"content":"[p]The risk assessment for a citizenship or checkable background waiver is based on a specific position and entity. As such, security clearances granted on the basis of a citizenship or checkable background waiver cannot be transferred to a new position or entity unless the exceptional business requirement and risk assessment provisions are undertaken and accepted for the new position or entity.[\/p]"},{"content":"[p]The granting of a waiver does not lead to the presumption that a security clearance will be granted. Where an eligibility waiver has been issued, the Authorised Vetting Agency can still deny a security clearance if there are significant concerns about the clearance subject's eligibility or suitability to hold the clearance that cannot be mitigated. This includes concerns relating to the eligibility condition that was waived.[\/p]"},{"content":"[p]Where the Accountable Authority has waived the citizenship or checkable background requirements for any security clearances sponsored by the entity, the number of personnel in the entity with active waivers and the type of waivers are reportable in the annual report on security.[\/p]"},{"content":"[p]There are two types of eligibility waivers - citizenship and checkable background.[\/p]"}],"child":[{"type":"section","ident":"18.6.1","title":"Citizenship Eligibility Waiver","block":[{"content":"[p]This type of waiver may be used when a clearance subject is not an Australian Citizen but has a valid visa with work rights.[\/p]"},{"requirement":{"identifier":"pspf-0148","index":"0148.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity establishes an exceptional business need and conducts a risk assessment before a citizenship eligibility waiver is considered for a non-Australian citizen who has a valid visa and work rights to work in an identified position.[\/p]"}]}},{"requirement":{"identifier":"pspf-0149","index":"0149.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Accountable Authority (or the Chief Security Officer if delegated) approves a citizenship eligibility waiver only after accepting the residual risk of waiving the citizenship requirement for that person, and maintains a record of all citizenship eligibility waivers approved.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"18.6.2","title":"Checkable Background Eligibility Waiver","block":[{"content":"[p]This type of waiver may be used when the Authorised Vetting Agency assesses that a clearance subject has an uncheckable background as they cannot complete the minimum checks and inquiries for the required period, or the checks and inquiries made do not provide an adequate basis to assess the clearance subject's life or background.[\/p]"},{"content":"[p]In these circumstances, and if no checkable background eligibility waiver is in place from the sponsoring entity, the Authorised Vetting Agency will deny the request for a clearance.[\/p]"},{"requirement":{"identifier":"pspf-0150","index":"0150.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity establishes an exceptional business need and conducts a risk assessment (including seeking advice from the Authorised Vetting Agency), before a checkable background eligibility waiver is considered for a clearance subject assessed as having an uncheckable background.[\/p]"}]}},{"requirement":{"identifier":"pspf-0151","index":"0151.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p] The Sponsoring Entity's Accountable Authority (or the Chief Security Officer if delegated) approves checkable background eligibility waivers only after accepting the residual risk of waiving the checkable background requirement for each person, and maintains a record of all checkable background eligibility waivers approved.[\/p]"}]}},{"requirement":{"identifier":"pspf-0152","index":"0152.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p] The Authorised Vetting Agency provides the Sponsoring Entity with information to inform a risk assessment if a clearance subject has an uncheckable background and only issues a clearance if the Accountable Authority waives the checkable background requirement and provides the Authorised Vetting Agency with a copy of the waiver.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"18.6.3","title":"Eligibility Waivers Risk Assessment","block":[{"content":"[p]Entities granting eligibility waivers must only do so after conducting an assessment of the security risks arising from the proposed action. Risk assessments to inform eligibility waivers are role-specific and not portable or transferrable. Gaining sponsoring entities cannot rely on the assessment of the losing sponsoring entity, rather they must conduct their own assessment of the security risks of an eligibility waiver and where approved, reissue a waiver.[\/p]"},{"content":"[lt]When conducting a risk assessment for eligibility waivers, the Sponsoring Entity must consider:[\/lt][ul][li]potential conflicts of interest[\/li][li]advice from the Authorised Vetting Agency and ASIO, including any known concerns about the clearance subject[\/li][li]the period of access under consideration, and[\/li][li]proposed risk management measures, including any conditions placed on the clearance holder subject to the waiver or temporary access.[\/li][\/ul]"},{"content":"[lt]For uncheckable background eligibility waivers, also consider:[\/lt][ul][li]details of any concerns associated with the subject's uncheckable background and assessment of the impact of this uncheckable period against the whole-of-person assessment, and[\/li][li]any threat assessments from ASIO on the clearance subject's country(ies) of citizenship or the country(ies) that gave rise to issues of checkability.[\/li][\/ul]"},{"content":"[lt]For citizenship eligibility waivers, also consider:[\/lt][ul][li]details of the clearance subject's visa status and whether they are actively seeking Australian citizenship, or plan to[\/li][li]the sponsoring entity's plan to ensure the clearance subject does not access caveated AUSTEO information, and[\/li][li]any threat assessments from ASIO on the clearance subject's country(ies) of citizenship or the country(ies) that gave rise to issues of checkability.[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"18.7","title":"Clearance Subject Responsibilities","block":[{"content":"[p]Clearance subjects who agree to undertake the security clearance process for the purposes of gaining employment, transfer or promotion to a position, securing a service provision contract, or to complete additional tasks within an existing position must disclose all relevant and required information. They must also co-operate in the collection of personal documentation and corroborating evidence. Clearance subjects must answer questions fully and honestly, and provide accurate information and personal documentation.[\/p]"},{"content":"[p]Sponsoring Entities must deny or withdraw a security clearance if a clearance subject fails or refuses to complete the required forms or to comply with reasonable requests from the Authorised Vetting Agency. This could result in a reduction of or an alteration to, duties or termination of employment. Before an entity denies a security clearance for this reason, they must inform the clearance subject of the likely consequences of not cooperating.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"18.8","title":"Locally Engaged Staff","block":[{"content":"[p]Locally engaged staff employed to support and complement the capacities of APS employees posted as representatives of the Australian Government at international posts (Australian embassies, high commissions and consulates). Locally engaged staff are not APS personnel but provide essential in-country knowledge, networks and continuity at an international post.[\/p]"},{"content":"[p]Locally engaged staff who are not Australian citizens may be granted a diplomatic mission clearance in accordance with the Prime Minister's Directive on Guidelines for the Management of the Australian Government Presence Overseas. These clearances are only recognised for the mission they are granted, are role-specific and not portable or transferrable.[\/p]"},{"content":"[p]The Department of Foreign Affairs and Trade is responsible for the security vetting of their locally engaged staff. The Australian Trade and Investment Commission is a managing entity under this directive and conducts security screening for its locally engaged staff and for those of attached entities.[\/p]"},{"content":"[p]The Accountable Authority (or Chief Security officer if delegated) may grant a waiver for citizenship eligibility to locally engaged staff working for an Australian Government entity in an international facilities not managed by DFAT, where the preferred person is not an Australian citizen and the entity understands and agrees to manage that risk. Such waivers must be subject to a suitable risk assessment.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"19","title":"Personnel Security Vetting Process","block":[{"content":"[p]Security vetting is conducted to ensure personnel are eligible and suitable to access classified government resources. The security vetting process results in a determination of the clearance subject's eligibility and suitability to hold a security clearance.[\/p]"},{"content":"[p]Security vetting of an individual establishes confidence that they possess an appropriate level of integrity, a sound and stable character, and they are not unduly vulnerable to influence or coercion.[\/p]"},{"content":"[lt]The determination is based on:[\/lt][ul][li]an assessment against the Australian Government Personnel Security Adjudicative Standard[\/li][li]minimum personnel security checks, and[\/li][li]a resolution of any doubt in the national interest.[\/li][\/ul]"},{"content":"[p]The personnel security vetting process details the standardised vetting practices to be undertaken when employing personnel and contractors. These processes provide a high-quality and consistent approach to managing personnel eligibility and suitability risk across government.[\/p]"},{"content":"[p]In the security context, integrity is defined as a range of character traits that indicate the individual is able to protect Australian Government security classified information, resources and activities.[\/p]"},{"content":"[lt]These character traits are:[\/lt][ul][li]honesty[\/li][li]trustworthiness[\/li][li]maturity[\/li][li]tolerance[\/li][li]resilience, and[\/li][li]loyalty.[\/li][\/ul]"},{"content":"[p]The security vetting process is summarised in Figure 3. The vetting assessment phase includes all the mandatory minimum personnel security checks, including ASIO's security clearance suitability assessment (SCSA) which applies to all security clearance applications (other than Baseline security clearance applications as ASIO's SCSA is optional but not mandatory for Baseline security clearances).[\/p]"},{"image":"Figure 3"}],"child":[{"type":"chapter","ident":"19.1","title":"Informed Consent","block":[{"content":"[p]The Authorised Vetting Agency is required to seek informed consent from the clearance subject to collect, use and disclose their personal information for the purposes of assessing and managing their eligibility and suitability to hold a security clearance.[\/p]"},{"content":"[p]Personal information received or used during security clearance vetting and ongoing suitability checks must be conducted in accordance with the Australian Privacy Principles (unless these principles do not apply to the entity).[\/p]"},{"content":"[p]Due to the nature of its content, personal information will always be classified at least OFFICIAL: Sensitive and must be protected in accordance with the minimum protections and handling requirements for this classification.[\/p]"},{"content":"[p]Sharing relevant information, even when it is sensitive personal information, will not breach an individual's privacy provided that informed consent is received and the information is used for the purpose for which consent is provided. To be able to meet the PSPF obligations to share information of concern, Authorised Vetting Agencies are required to obtain informed consent from all clearance subjects to share information with other entities. This includes but is not limited to the sponsoring Entity and other Authorised Vetting Agencies. Consent is recommended to be obtained at key information collection points, such as application for a security clearance, and that consent is updated at reasonable intervals.[\/p]"},{"content":"[p]It is ideal for entities to also include a privacy statement in their recruitment and pre-recruitment paperwork detailing how personal information will be collected, used and disclosed. This should note that information gathered through the security vetting process may be shared to inform other decisions related to law enforcement or counter intelligence.[\/p]"},{"content":"[p]Entities are exempt from the provisions of the Privacy Act when communicating personal information to ASIO in support of ASIO's functions.[\/p]"},{"requirement":{"identifier":"pspf-0153","index":"0153.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The clearance subject's informed consent is given to collect, use and disclose their personal information for the purposes of assessing and managing their eligibility and suitability to hold a security clearance.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"19.2","title":"Personnel Security Adjudicative Standard","block":[{"content":"[p]The Personnel Security Adjudicative Standard applies to Australian Government Baseline, Negative Vetting 1, Negative Vetting 2, and Positive Vetting security clearances. Positive Vetting security clearances will be progressively replaced by TS-PA security clearances, issued in accordance with the TS-PA Standard.[\/p]"},{"content":"[p]Authorised Vetting Agencies must assess an individual's eligibility and suitability from a whole-of-person perspective to hold a security clearance. This includes consideration of their integrity in accordance with the Personnel Security Adjudicative Standard. For the purposes of security vetting, integrity is defined as the character traits of honesty, trustworthiness, maturity, tolerance, resilience and loyalty.[\/p]"},{"content":"[p]The Personnel Security Adjudicative Standard provide the common risk factor areas against which a clearance subject's eligibility and suitability is assessed. These areas may have a bearing on one or more of a clearance subject's character traits. Authorised Vetting Agencies should use a process of structured professional judgement to achieve an overall decision or decision based on the available information.[\/p]"},{"requirement":{"identifier":"pspf-0154","index":"0154.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by considering their integrity (i.e. the character traits of maturity, trustworthiness, honesty, resilience, tolerance and loyalty) in accordance with the Australian Government Personnel Security Adjudicative Standard.[\/p]"}]}}],"child":[{"type":"section","ident":"19.2.1","title":"TOP-SECRET Privileged Access","block":[{"content":"[p]The TS-PA Standard establishes the requirements that apply to TS-PA clearances. The Standard is a classified document that is only available to qualified practitioners conducting TS-PA vetting, psychological assessments or insider threat management activities in the TOP SECRET-Privileged Access Authority, Quality Assurance Office, or sponsoring entities (referred to as TS-PA practitioners).[\/p]"},{"content":"[p]Only entities with an insider threat program that meets the TS-PA Standard are able to sponsor TS-PA security clearances.[\/p]"},{"content":"[p]All personnel who obtain a TS-PA security clearance will be provided with a copy of the annex to the TS-PA Standard that outlines their obligations for maintaining their security clearance.[\/p]"},{"content":"[p]The TOP SECRET-Privileged Access Vetting Authority is required to assess an individual's suitability to hold TS-PA security clearance by considering their trustworthiness and commitment to Australia, its values, and its democratic system of government in accordance with the TS-PA Standard.[\/p]"},{"requirement":{"identifier":"pspf-0155","index":"0155.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The clearance subject's eligibility and suitability to hold a TOP SECRET-Privileged Access security clearance is assessed in accordance with the TOP SECRET-Privileged Access Standard.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"19.3","title":"Minimum Personnel Security Checks","block":[{"content":"[p]The purpose of minimum personnel security checks is to verify identity and collect relevant information necessary to obtain an accurate picture of the clearance subject's background, lifestyle and character. These checks establish the clearance subject's eligibility and suitability to hold a security clearance.[\/p]"},{"content":"[p]The effectiveness of these minimum personnel security checks relies on complete, consistent and accurate information provided by the clearance subject.[\/p]"},{"requirement":{"identifier":"pspf-0156","index":"0156.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by conducting the minimum personnel security checks for the commensurate security clearance level.[\/p]"}]}},{"table":"[table name='Table 27' title='Minimum Personnel Security Checks'][head][cell]Check[\/cell][cell]Security Clerance Level[\/cell][\/head][head][cell]Baseline Vetting[\/cell][cell]Negative Vetting 1[\/cell][cell]Negative Vetting 2[\/cell][cell]Positive Vetting[\/cell][cell]TOP SECRET-Privileged Access[\/cell][\/head][row][cell]Identity CHeck[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Entities must verify the person's identification documents with the issuing authority by using the Document Verification Service (or other source identity verification solution) for Australian issued primary identification documents.[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Confirmation of Australian citizenship and status of any other citizenships[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Background assessment[\/cell][cell]Required for the checkable period of 5 years[\/cell][cell]Required for the checkable period of 10 years[\/cell][cell]Required for the checkable period of 10 years[\/cell][cell]Required for the checkable period that is greater of 10 years or from the age of 16 TS-PA Standard[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Acknowledgement of relevant legislation (secrecy of information)[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Referee checks[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Digital footprint check[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]National police check\/criminal history check[\/cell][cell]Required, no exclusion[\/cell][cell]Required, no exclusion[\/cell][cell]Required, no exclusion[\/cell][cell]Required, no exclusion[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Financial history assessment[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Financial statement[\/cell][cell]Not required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required with supporting documents[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Financial probity assessment[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Comprehensive financial assessment[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]ASIO security clearance suitability assessment[\/cell][cell]Not required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Security interview[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Psychological assessment[\/cell][cell]Not required, however optional where deemed necessary by the Authorised Vetting Agency.[\/cell][cell]Required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Overseas travel check[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]Not required[\/cell][cell]TS-PA Standard[\/cell][\/row][row][cell]Statutory declaration (only when vetting is conducted by a state or territory agency)[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Required[\/cell][cell]Not required[\/cell][cell]TS-PA Standard[\/cell][\/row][\/table]"},{"content":"[p]See PSPF Guidelines for detailed information on each of these mandatory minimum checks.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"19.4","title":"National Interest","block":[{"content":"[p]The national interest is Australia's sovereignty, security, prosperity, independence of decision-making and the freedom and social cohesion of its people.[\/p]"},{"content":"[p]All people working in and on behalf of Australian Government must have a primary and overriding commitment to the democratic process and a respect for the processes by which the elected government functions. If a clearance subject expresses political or personal views incompatible with Australia's constitutional, democratic system of government, doubts arise about whether they are loyal to the Australian Government. Conflict of views or conscientious objections could arise in some cases. However, the issue is whether a clearance subject recognises their responsibilities to their employing entity, the elected government and the public interest. When a clearance subject acts in ways that indicate a preference for a foreign country over Australia, then they may be prone to act in ways that are harmful to the national interest of Australia.[\/p]"},{"content":"[lt]The determination of whether an individual is suitable to hold a security clearance, consistent with the national interest, is based on careful consideration of the whole person in the context of the following risk factor areas:[\/lt][ul][li]external loyalties, influences and associations[\/li][li]personal relationships and conduct[\/li][li]financial considerations[\/li][li]alcohol and drug usage[\/li][li]criminal history and conduct[\/li][li]security attitudes and violations, and[\/li][li]mental health disorders.[\/li][\/ul]"},{"content":"[p]These factor areas may have a bearing on one or more of a clearance subject's character traits.[\/p]"},{"content":"[p]Each clearance subject is assessed on their own merits, and the final determination of their suitability rests with the Authorised Vetting Agency delegate. Any doubt concerning the clearance subject's suitability must be resolved in favour of the national interest See PSPF Guidelines for further information on national interest risk factors.[\/p]"},{"requirement":{"identifier":"pspf-0157","index":"0157.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by resolving any doubt in the national interest.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"19.5","title":"Security Vetting Outcomes","block":[{"content":"[p]A vetting analyst conducts the assessment and provides a security clearance delegate with a recommended outcome.[\/p]"},{"content":"[lt]The outcome of a security vetting process is a decision of the clearance subject's eligibility and suitability to hold a security clearance based on an assessment:[\/lt][ul][li]against the Personnel Security Adjudicative Guidelines (for Baseline, Negative Vetting 1, Negative Vetting 2 and Positive Vetting)[\/li][li]against the TOP SECRET-Privileged Access Standard (for TS-PA)[\/li][li]taking into account all relevant, reliable and independently verified information obtained through the minimum personnel security checks, and any additional checks required[\/li][li]taking into account ASIO's security clearance suitability assessment (for Baseline, Negative Vetting 1, Negative Vetting 2 and Positive Vetting), and[\/li][li]resolving any doubt in the national interest.[\/li][\/ul]"},{"content":"[lt]In determining the security clearance outcome based on the recommendation from the vetting analyst, the delegate:[\/lt][ul][li]satisfies themselves that all issues raised in the clearance process have been addressed, and[\/li][li]provides the clearance subject with the opportunity to respond to any adverse information, if appropriate.[\/li][\/ul]"},{"content":"[p]Authorised Vetting Agencies are asked to use consistent language to describe the outcomes of security vetting processes in personal security files.[\/p]"},{"table":"[table name='Table 28' title='Determinative Security Vetting Outcomes'][\/table]"},{"content":"[p]Administrative outcomes of the security vetting process apply where no vetting assessment or security clearance decision has been made.[\/p]"},{"table":"[table name='Table 29' title='Administrative Security Vetting Outcomes'][\/table]"}],"child":[{"type":"section","ident":"19.5.1","title":"Conditional Security Clearances","block":[{"content":"[p]Security clearance conditions enable the sponsoring entity to manage ongoing risks affecting the clearance subject's eligibility and suitability to hold a security clearance. This may include access restrictions or other risk mitigations measures.[\/p]"},{"content":"[p]Conditions may be placed on a clearance at the instigation of the Sponsoring Entity, or the Authorised Vetting Agency, or on the recommendation of ASIO's security clearance suitability assessment.[\/p]"},{"content":"[p]Monitoring a clearance subject's compliance with security clearance conditions is Requirement 165. Non-compliance with conditions may trigger a review for cause.[\/p]"},{"requirement":{"identifier":"pspf-0158","index":"0158.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[lt]Concerns that are identified during the vetting or security clearance suitability assessment process, that are not sufficient to deny a security clearance and where the related risks can be managed through conditions attached to the security clearance, the Authorised Vetting Agency must:[\/lt][ul][li]identify the clearance conditions[\/li][li]provide the sponsoring entity with information about the concerns to inform a risk assessment[\/li][li]only issue a conditional security clearance if the Accountable Authority and the clearance subject accept the clearance conditions. The Accountable Authority may delegate this decision to the Chief Security Officer, however the Chief Security Officer is required to notify the Accountable Authority of the clearance conditions.[\/li][\/ul]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"19.6","title":"Sharing Information of Concern","block":[{"content":"[p]Authorised Vetting Agencies are required to provide relevant information of concern obtained during the security vetting process to the sponsoring entity. Information of concern includes information of security concern (such as issues that raise concern over the protection of security classified information, resources or activities from compromise, espionage, sabotage, foreign interference etc.) and information of non-security concern (such as integrity or allegiance to Australia or the Australian Government's interest). This is particularly important if identified concerns may lead to an adverse recommendation, or where vetting uncovers information likely to impact on the clearance subject's suitability to hold the role. For example, current drug use in an entity with a zero drug-use policy.[\/p]"},{"content":"[p]In these circumstances the Authorised Vetting Agency (where a security clearance decision is still pending, including circumstances where a response has been invited from the clearance subject in relation to the identified risks) shares only relevant information with the sponsoring entity to enable temporary measures until a final outcome is made.[\/p]"},{"content":"[p]Not all information of concern obtained during the security vetting process will disqualify the security clearance applicant from obtaining a security clearance or require conditions to be imposed on the security clearance. However, where this type of information is identified, the Authorised Vetting Agency should consider the merits of sharing this information with the sponsoring entity, noting the decision to share this type of information is at their discretion. For example, the clearance subject has falsified their qualifications, however during the vetting process the Authorised Vetting Agency determines that this is manageable from a security clearance perspective but considers this renders the applicant ineligible for the particular role for which they have been recruited. By sharing this information with the sponsoring entity, the Authorised Vetting Agency supports the sponsoring entity with making sound risk-based decisions on whether to proceed with the clearance.[\/p]"},{"content":"[p]When advising the sponsoring entity of the security clearance outcome, the Authorised Vetting Agency should include information relating to any vulnerabilities or risk factors and risk mitigation measures that were applied by the vetting agency. The sponsoring entity can then understand and manage any risks relating to the clearance holder's ongoing access to Australian Government resources.[\/p]"},{"requirement":{"identifier":"pspf-0159","index":"0159.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency provides the sponsoring entity with any other relevant information of concern that is identified during the vetting process when advising them of the outcome of the security vetting process, to inform the sponsoring entity's risk assessment.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"19.7","title":"Procedural Fairness","block":[{"content":"[p]Procedural fairness applies to Baseline, Negative Vetting 1, Negative Vetting 2 and Positive Vetting security clearance processes. The TS-PA Standard provides guidance on procedural fairness for TS-PA security clearance processes.[\/p]"},{"content":"[p]Procedural fairness is concerned with the procedures used by a decision maker, rather than the actual outcome reached - it is a matter of administrative law. It requires a fair and proper procedure be used when making a decision. A decision maker who follows a fair procedure is more likely to reach a fair and correct decision.[\/p]"},{"content":"[p]Authorised Vetting Agencies must apply procedural fairness to security clearance decisions that are adverse to a clearance subject, without compromising the national interest or betraying the confidentiality of the source of any adverse information. When the principles of procedural fairness are applied in a security clearance process, it protects the rights of the individual and reduces the possibility of a new clearance process being ordered on review or appeal.[\/p]"},{"content":"[p]If the vetting analyst intends to recommend against the approval of a clearance at the level sought, or to recommend that the clearance be approved with clearance conditions, it is recommended that the clearance subject be provided an opportunity to respond before the final recommendation is made. It is recommended that any information used to make a decision be substantiated, particularly when the information is from a referee who may be biased or have a conflict of interest.[\/p]"},{"content":"[lt]The essential elements of providing procedural fairness are:[\/lt][ul][li]the hearing rule, which requires a person be provided with a clear understanding of the matters at issue (the allegations or charges against them) and an opportunity to be heard and express their views to a decision maker[\/li][li]the bias rule, which requires a decision maker to be impartial.[\/li][li]a sound (reliable and sufficient) evidentiary base for decisions, and[\/li][li]diligent inquiry into and, where possible, resolution of any matters in dispute.[\/li][\/ul]"},{"content":"[p]The term procedural fairness is preferred when referring to administrative decision-making because the term 'natural justice' is associated with procedures used by courts of law. However, the terms have similar meaning and are commonly used interchangeably. For consistency, the term 'procedural fairness' is used in this standard.[\/p]"},{"requirement":{"identifier":"pspf-0160","index":"0160.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency applies the rules of procedural fairness to security clearance decisions that are adverse to a clearance subject, including decisions to deny a security clearance (including grant lower level) or grant a conditional security clearance, without compromising the national interest.[\/p]"}]}},{"content":"[p]Note: Separate arrangements ensure procedural fairness and national security are preserved where denial of a clearance is based on an ASIO security clearance suitability assessment.[\/p]"}],"child":[{"type":"section","ident":"19.7.1","title":"Procedural Fairness and Security Clearance Decisions","block":[{"content":"[p]To comply with administrative law principles, Authorised Vetting Agencies must apply the rules of procedural fairness to security clearance decisions that are adverse to a clearance subject, including decisions to deny or revoke a security clearance.[\/p]"},{"content":"[p]As part of the security clearance decision-making process and in accordance with the hearing rule, where an adverse decision is proposed, it is recommended that Authorised Vetting Agencies tell the clearance subject the case to be met (to the fullest extent possible consistent with national security) and give them an opportunity to reply before the delegate makes a decision.[\/p]"},{"content":"[lt]It is also recommended that Authorised Vetting Agencies ensure that the clearance subject:[\/lt][ul][li]is told the case to be met before preparing their reply, including being provided with a description of the proposed decision, the criteria for making that decision and the information on which any such decision would be based. It is recommended that negative information an Authorised Vetting Agency has about the clearance subject be disclosed to the extent possible consistent with national security. It is sufficient that a summary of the information being considered be provided to the clearance subject - original documents and the identity of confidential sources do not have to be provided[\/li][li]is provided with a reasonable opportunity to consider their position and prepare a response, and[\/li][li]have their reply considered by the delegate before the decision is made.[\/li][\/ul]"},{"content":"[lt]The bias rule requires that a delegate making a security clearance decision:[\/lt][ul][li]does not have an interest (either direct or indirect) in the matter being decided[\/li][li]does not bring, or appear to bring, a biased or prejudiced mind to making the decision.[\/li][\/ul]"},{"content":"[p]A delegate must be impartial. Authorised Vetting Agencies must maintain processes to ensure application of the bias rule to comply with administrative law principles.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"19.7.2","title":"Procedural Fairness and Delegate","block":[{"content":"[lt]In making a security clearance decision that complies with administrative law principles, a delegate must comply with the rules of procedural fairness and ensure that:[\/lt][ul][li]a clearance subject has been provided with an opportunity to be heard to make submissions if this has not already occurred and it is not prejudicial to security to do so[\/li][li]they act fairly and impartially, including by ensuring there is no reasonable perception of bias on the part of the delegate, and[\/li][li]any information used to make a decision can be substantiated, particularly when the information is from a referee who may be biased or have a conflict of interest.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"section","ident":"19.7.3","title":"Procedural Fairness and Negative Delegate Decisions","block":[{"content":"[p]If a clearance subject is negatively affected by a delegate's decision they can expect that the vetting analyst and delegate will follow the rules of procedural fairness before reaching a conclusion.[\/p]"},{"content":"[lt]In particular, a clearance subject is entitled to:[\/lt][ul][li]being told the case to be met (e.g. that an agency is considering denying, ceasing a clearance, or imposing conditions on the clearance), including being provided with a description of the proposed decision, the criteria for making that decision and the information on which the decision would be based, except where to do so would be inconsistent with national security[\/li][li]an opportunity to reply to the case to be met by a written reply or submission or, in certain circumstances, through a face-to-face or phone interview.[\/li][\/ul]"},{"content":"[lt]In responding to concerns, a clearance subject may:[\/lt][ul][li]deny the allegations[\/li][li]provide evidence they believe disproves the allegations[\/li][li]explain the allegations or present an innocent explanation, or[\/li][li]provide details of any special circumstances they believe need to be taken into account.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"section","ident":"19.7.4","title":"Procedural Fairness and Vetting Analysts","block":[{"content":"[p]A vetting analyst must take into account the requirements of procedural fairness during the clearance process, including when undertaking a security clearance assessment and preparing a recommendation for a delegate.[\/p]"},{"content":"[lt]To comply with administrative law principles when making a recommendation to a delegate, a vetting analyst must:[\/lt][ul][li]consider all submissions made by a clearance subject[\/li][li]take into account only relevant information[\/li][li]ensure that any recommendation made is based on a sound (reliable and sufficient) evidentiary base[\/li][li]act fairly and impartially[\/li][li]conduct the clearance process without unnecessary delay[\/li][li]ensure that a full record of the clearance process has been made.[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"19.8","title":"Review of Decisions","block":[{"content":"[p]The denial or granting of a security clearance, with or without clearance conditions, is an administrative decision and is reviewable. The avenues for review vary depending on the applicable Authorised Vetting Agency, Sponsoring Entity and the status of the clearance subject.[\/p]"},{"table":"[table name='Table 30' title='Administrative Review Process by Sponsoring Entity'][\/table]"},{"content":"[p]A secondary review by the Merit Protection Commissioner cannot reverse a decision made by the delegate, under regulation 5.28 of the Public Service Regulations 1999. Instead, under the regulations the Commissioner must make a recommendation to the relevant Authorised Vetting Agency. Under regulation 5.32, the vetting agency may confirm the action, vary it or set the action aside and substitute a new action in response to the recommendation. The agency must advise the Merit Protection Commissioner of its decision. If the Merit Protection Commissioner is not satisfied with the vetting agency's response, subsection 33(6) of the Public Service Act 1999 allows for the matter to be reported to the agency's minister, the Prime Minister and the Parliament.[\/p]"},{"content":"[p]Security clearance decisions made by ASIO may be internally reviewable and reviewable by the Administrative Review Tribunal or an independent reviewer appointed by the Attorney-General. Information about review rights is provided to eligible clearance subjects.[\/p]"},{"content":"[p]The clearance subject may appeal in the Administrative Review Tribunal against certain prejudicial ASIO security clearance suitability assessments. The Administrative Review Tribunal has replaced the Administrative Appeals Tribunal. The subject must be advised in writing (usually within 14 days of furnishing of the assessment. The review process is conducted through the Security Division of the Administrative Review Tribunal. For information about how to apply for a review of a decision in the Security Division, see Administrative Review Tribunal (art.gov.au).[\/p]"},{"content":"[p]Authorised Vetting Agencies should ensure the clearance subject has been given a chance to respond to any other suitability concerns. Any responses by the clearance subject will be included on the clearance subject's personal security file.[\/p]"},{"content":"[lt]The clearance subject may also make a formal complaint to:[\/lt][ul][li]the Privacy Commissioner, if they feel there was a breach of the Privacy Act 1988 in the way information was handled[\/li][li]the Human Rights Commissioner, if they feel they have been unfairly discriminated against. Under section 20 of the Human Rights Commission Act 1986, the Commissioner will investigate a complaint or provide written notice explaining why the complaint will not be investigated. If the complaint refers to an action by an intelligence agency, the Commissioner will refer the complaint to the Inspector-General of Intelligence and Security.[\/li][\/ul]"},{"content":"[p]The clearance subject may also seek judicial review of a vetting decision in the Federal Court of Australia or High Court of Australia under section 39B of the Judiciary Act 1903 or section 75(v) of the Constitution.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"20","title":"High Office Holders and their Support Staff","block":[],"child":[{"type":"chapter","ident":"20.1","title":"Clearance Exemptions for Australian High Office Holders","block":[{"content":"[p]Some Australian high office holders are not required to hold a security clearance to access security classified information while exercising the duties of the office. Staff of these office holders are not exempt from security clearance requirements.[\/p]"},{"content":"[lt]Australian office holders who do not need a security clearance are:[\/lt][ul][li]members and senators of the Commonwealth (including Ministers, shadow ministers and backbenchers) and state parliaments and territory legislative assemblies members[\/li][li]judges of federal courts and the Supreme Courts of the states and territories[\/li][li]royal commissioners[\/li][li]the Governor-General, state governors, the Northern Territory administrator[\/li][li]members of the Executive Council, and[\/li][li]appointed office holders with enabling legislation that gives the same privileges as the office holders already identified e.g. members of the Administrative Review Tribunal.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"chapter","ident":"20.2","title":"PSPF Obligations for Australian High Office Holders","block":[{"content":"[p]An Australian high officer holder's exemption from the requirements of the PSPF is limited to the requirement for a security clearance.[\/p]"},{"content":"[p]Departments of State responsible for managing protective security for Australian office holders are to ensure that classified information, devices and resources in their possession are appropriately safeguarded at all times in accordance with the PSPF.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"20.3","title":"","block":[{"content":"[p]Parliamentarians employ staff under the Members of Parliament (Staff) Act 1984 (MOP(S) Act). Staff are referred to as MOP(S) Act employees. This Act covers electorate employees, personal employees (Ministerial) and personal employees (non-Ministerial for example staff members of shadow ministers and backbenchers).[\/p]"},{"content":"[p]The power to employ, and the terms and conditions of employment, may be affected by arrangements and determinations made by the Prime Minister. Further, successive responsible Ministers have made determinations and authorisations under the authority provided by the MOP(S) Act to assist in the administration of entitlements of employees.[\/p]"},{"content":"[p]Once such determination, the Special Minister of State Determination 2023\/12, requires that electorate or personal staff (ministerial staff) employed under Part III of the MOP(S) Act by Ministers obtain and maintain a Negative Vetting 2 security clearance.[\/p]"},{"content":"[p]The Australian Government Security Vetting Agency is the Authorised Vetting Agency responsible for the security clearances of ministerial staff.[\/p]"},{"content":"[p]The responsibilities for sponsorship and management of the security clearances of ministerial staff are shared between the Department of Finance, the Department of State in the relevant portfolio (or another entity in the portfolio as their delegate) and the relevant Minister (or Chief of Staff as their delegated authorised officer).[\/p]"},{"content":"[p]The key responsibilities are detailed below.[\/p]"},{"table":"[table name='Table 31' title='Key Stakeholder Responsibilities for Ministerial Staff Security Clearances'][head][cell]Department of Finance[\/cell][cell]Department of State (or delegate)[\/cell][cell]Minister\/Chief of Staff[\/cell][\/head][row][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][\/table]"}],"child":[{"type":"section","ident":"20.3.1","title":"Variation of Special Minister of State's Determination for a Minister's electorate officer","block":[{"content":"[p]The Special Minister of State Determination 2023\/12 requires that staff of Ministers employed under Part III of the MOP(S) Act obtain and maintain a Negative Vetting 2 security clearance. Under the Determination, in exceptional circumstances, a Minister's Chief of Staff may request a variation of the security clearance requirement from the Secretary of the Department of Home Affairs.[\/p]"},{"content":"[p]The Secretary, Department of Home Affairs will consider a request to vary the requirement for a Negative Vetting 2 security clearance following endorsement by the relevant Department of State. Please complete the variation request form in PSPF Guidelines and send to PSPF@homeaffairs.gov.au[\/p]"},{"table":"[table name='Table 32' title='Possible Variations for Electorate Officers Employed by a National Security Committee Minister'][head][cell]Staff[\/cell][cell]Information Access[\/cell][cell]Security Clearance Variation[\/cell][\/head][row][cell]Electorate officers employed by a National Security Committee[\/cell][cell]TOP SECRET or SECRET[\/cell][cell]No variation. Negative Vetting 2 security clearance required[\/cell][\/row][row][cell]Minister[\/cell][cell]PROTECTED, OFFICIAL: Sensitive or OFFICIAL[\/cell][cell]Variation to Baseline security clearance may be sought.[\/cell][\/row][row][cell]Electorate officers employed by a non-National Security Committee[\/cell][cell]TOP SECRET[\/cell][cell]No variation. Negative Vetting 2 security clearance required.[\/cell][\/row][row][cell]Minister[\/cell][cell]SECRET[\/cell][cell]Variation to Negative Vetting 1 security clearance may be sought.[\/cell][\/row][row][cell]PROTECTED, OFFICIAL: Sensitive or OFFICIAL[\/cell][cell]Variation to Baseline security clearance may be sought.[\/cell][\/row][\/table]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"21","title":"Maintenance and Ongoing Assessment","block":[{"content":"[p]Effectively assessing and managing ongoing suitability ensures that entity personnel, including contractors, continue to meet eligibility and suitability requirements established at the point of engagement.[\/p]"},{"content":"[p]Entitles must maintain confidence in their personnel's ongoing suitability to access Australian Government resources, and manage the risk of malicious or unwitting insiders. It is critical that entities are aware of changes in their personnel's circumstances and workforce behaviours. This awareness is facilitated by effective information sharing and a positive security culture, recognising that security is everyone's responsibility.[\/p]"},{"content":"[p]Entities that sponsor Australian Government security clearances (Sponsoring Entity) and Authorised Vetting Agencies play a critical role in assuring ongoing suitability of personnel occupying positions that require access to security classified resources or additional levels of assurance.[\/p]"}],"child":[{"type":"chapter","ident":"21.1","title":"Security Clearance Maintenance","block":[{"content":"[p]A security clearance is based on a point in time assessment and the reliability of that assessment begins to decay from that point in time. Ongoing security management of clearance holders is essential to ensuring suitability from that point on. Effectively assessing and managing ongoing suitability ensures that entity personnel, including contractors, continue to meet eligibility and suitability requirements established at the point of engagement.[\/p]"},{"content":"[p]Entitles must maintain confidence in their personnel's ongoing suitability to access Australian Government resources, and manage the risk of malicious or unwitting insiders. It is critical that entities are aware of changes in their personnel's circumstances and workforce behaviours. This awareness is facilitated by effective information sharing and a positive security culture, recognising that security is everyone's responsibility.[\/p]"},{"content":"[p]Entities that sponsor Australian Government security clearances (Sponsoring Entity) and Authorised Vetting Agencies play a critical role in assuring ongoing suitability of personnel occupying positions that require access to security classified resources or additional levels of assurance.[\/p]"},{"content":"[p]Departments of State also have responsibilities for the assessment and management of the ongoing suitability of the ministerial staff of their portfolio ministers employed under Part III of the Members of Parliament (Staff) Act 1984. This includes the monitoring and management of the clearance holder.[\/p]"},{"content":"[p]Ensuring the ongoing eligibility and suitability of security cleared personnel to hold an Australian Government security clearance is the joint responsibility of Authorised Vetting Agencies, the Sponsoring Entity and the individual clearance holder. For details on the responsibilities for the ongoing assessment of ministerial staff employed under Part III of the Members of Parliament (Staff) Act 1984, see section 20.3.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"21.2","title":"Authorised Vetting Agencies Maintenance Responsibilities","block":[{"content":"[p]Authorised Vetting Agencies are responsible for assessing how information relates to an individual's eligibility and suitability to hold a clearance.[\/p]"}],"child":[{"type":"section","ident":"21.2.1","title":"Share Information of Concern","block":[{"content":"[p]Authorised Vetting Agencies are required to share relevant information about security clearance holder's ongoing eligibility and suitability for employment or to hold an Australian Government security clearance. Authorised Vetting Agencies must share all information relating, or appearing to relate, to the ongoing suitability of personnel so the entity receiving the information can determine whether it is relevant.[\/p]"},{"content":"[p]This includes in relation to transfers of personnel, including temporary and permanent transfers within entities and to other entities. Note that information sharing may be limited by legislation, including the Australian Privacy Principles and an entity-enabling legislation. Sharing relevant information, even when it is sensitive personal information, does not breach an individual's privacy provided that informed consent is received and the information is used for the purpose for which consent was given.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"21.2.2","title":"Assess and Respond to Information of Concern","block":[{"content":"[p]Authorised Vetting Agencies must assess and respond to information of concern about security clearance holders, which includes reports from sponsoring entities.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"21.2.3","title":"Review Conditional Security Clearances","block":[{"content":"[p]The Authorised Vetting Agency must review the conditions for conditionally security clearances annually. This ensures the conditions remain appropriate and continue to mitigate the identified concerns. As part of this review it may be necessary for the Authorised Vetting Agency to confirm with the sponsoring entity and clearance subject that the agreed conditions are still able to be met. Where concerns relevant to the clearance conditions have changed, the Authorised Vetting Agency will need to reassess the clearance holder's suitability to hold a security clearance.[\/p]"},{"requirement":{"identifier":"pspf-0161","index":"0161.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency reviews the conditions of conditional security clearances annually.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"21.2.4","title":"Review for Cause","block":[{"content":"[p]Authorised Vetting Agencies must review a clearance holder's eligibility and suitability to hold a security clearance where concerns are identified. This process is known as a review for cause.[\/p]"},{"content":"[lt]Concerns may arise from:[\/lt][ul][li]advice from the clearance subject of a change in circumstances[\/li][li]concern raised by the clearance subject's sponsoring entity[\/li][li]a security incident involving the clearance subject[\/li][li]non-compliance with clearance conditions, or[\/li][li]other information or advice of concern received by the Authorised Vetting Agency about the clearance subject.[\/li][\/ul]"},{"content":"[p]A review for cause may entail an investigation into specific concerns in the context of the whole person, or may prompt bringing forward a full revalidation of the security clearance.[\/p]"},{"content":"[lt]In conducting a review for cause, Authorised Vetting Agencies are encouraged to:[\/lt][ul][li]assess if a review for cause is warranted[\/li][li]check with the sponsoring entity whether an ongoing investigation is underway that might be compromised by the review for cause and negotiate how to proceed[\/li][li]advise the clearance subject prior to starting any reviews for cause and provide the reasons for the review, and[\/li][li]undertake the checks required to resolve the concerns that led to the initiation of the review for cause, for example:[ul][li]targeted checks to resolve an issue[\/li][li]a full revalidation if the concerns are wide ranging[\/li][\/ul][\/li][li]advise both the clearance subject and the sponsoring entity of the review for cause outcome.[\/li][\/ul]"},{"content":"[p]ASIO may also undertake a review for cause of a security clearance suitability assessment on the basis of information of concern provided by the sponsoring entity, Authority Vetting Agency, other sources or as a result of its own security investigations.[\/p]"},{"requirement":{"identifier":"pspf-0162","index":"0162.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency reviews the clearance holder's eligibility and suitability to hold a security clearance, where concerns are identified (review for cause).[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"21.2.5","title":"Implement TS-PA Standard","block":[{"content":"[p]Authorised TOP SECRET-Privileged Access (TS-PA) Vetting Agencies are to implement specific requirements in the TS-PA Standard to assess and manage the ongoing suitability of TS-PA security clearance holders. This includes, but is not limited to, assessing information provided by sponsoring entities and other sources (including changes of circumstances), and conducting annual clearance reviews of all TS-PA security clearances, reviews for cause, and revalidation of TS-PA security clearances.[\/p]"},{"requirement":{"identifier":"pspf-0163","index":"0163.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised TOP SECRET-Privileged Access Vetting Agency implements the TOP SECRET-Privileged Access Standard in relation to the ongoing assessment and management of personnel with TOP SECRET-Privileged Access security clearances.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"21.3","title":"Sponsoring Entities Maintenance Responsibilities","block":[{"content":"[p]Sponsoring Entities are responsible for assessing how information relates to an entity's security risks, as well as a person's suitability for employment by the entity. This is particularly relevant where there are entity-specific employment requirements, such as a zero-tolerance drug and alcohol policy. Sponsoring entities must also share relevant information of concern and assess whether information is relevant to share.[\/p]"},{"content":"[p]The potential for insiders (employees, contractors and others with access to Australian Government resources) to betray the trust placed in them presents an enduring security risk. Insiders who compromise security may be unwitting or malicious. Possible motives are complex and can be driven by a mix of personal vulnerabilities, life events and situational factors.[\/p]"},{"content":"[p]While pre-employment screening and security clearance vetting provide an assessment of a person's suitability at a point in time, ongoing awareness of changes in personnel's circumstances and workplace behaviours is essential to manage the risk of insider threat.[\/p]"},{"content":"[p]Entities are responsible for ensuring their personnel remain suitable to access Australian Government information, resources and activities for the entire period of their engagement. However, ensuring the ongoing eligibility and suitability of security cleared personnel to hold an Australian Government security clearance is the joint responsibility of authorised vetting agencies, the sponsoring entity and the individual clearance holder.[\/p]"},{"content":"[p]Effective assessment of personnel's ongoing suitability relies on entities encouraging and facilitating reporting of concerns, as well as collating and assessing information on personnel from a range of sources, including their management and colleagues.[\/p]"},{"content":"[lt]The way entities assess and manage ongoing suitability will depend on:[\/lt][ul][li]the type of personnel (employees and contractors, security clearance holders or uncleared personnel) within the entity[\/li][li]their access to classified and unclassified Australian Government information, resources and activities[\/li][li]the entity's tolerance for security risks[\/li][li]any risks that may be specific to the position, and[\/li][li]the individual's personal risk profile.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0164","index":"0164.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Sponsoring Entity actively assesses, monitors and manages the ongoing suitability of personnel.[\/p]"}]}},{"requirement":{"identifier":"pspf-0165","index":"0165.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Sponsoring Entity monitors and manages compliance with any conditional security clearance requirements and reports any non-compliance to the Authorised Vetting Agency.[\/p]"}]}},{"requirement":{"identifier":"pspf-0166","index":"0166.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Sponsoring Entity monitors and manages compliance with security clearance maintenance obligations for the clearance holders they sponsor.[\/p]"}]}}],"child":[{"type":"section","ident":"21.3.1","title":"Procedures for Assessing Managing Ongoing Suitability","block":[{"content":"[p]The procedures for assessing and managing ongoing suitability of personnel are listed below. Entities should include periodic employment suitability checks, as well as mechanisms to support reporting of concerns.[\/p]"},{"table":"[table name='Table 33' title='Procedures for Assessing and Managing Ongoing Suitability'][head][cell]Procedure[\/cell][cell]Uncleared Personnel[\/cell][cell]Security Cleared Personnel[\/cell][\/head][row][cell]Building personnel security into performance management[\/cell][cell]Mandatory[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Periodic employment suitability check[\/cell][cell]Mandatory[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Annual security check[\/cell][cell]Recommended[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Contact reporting obligations[\/cell][cell]Recommended[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Security incident reporting and follow-up[\/cell][cell]Recommended[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Collecting and assessing information on changes in personal circumstances[\/cell][cell]Recommended[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Annual reviews of eligibility waivers[\/cell][cell]Not applicable[\/cell][cell]Mandatory for holders of a clearance subject to an eligibility waiver[\/cell][\/row][row][cell]Monitoring compliance with clearance conditions[\/cell][cell]Not applicable[\/cell][cell]Mandatory[\/cell][\/row][row][cell]Positive Vetting maintenance obligations in accordance with the SMSMP-PVG[\/cell][cell]Not applicable[\/cell][cell]Mandatory for Positive Vetting holders[\/cell][\/row][row][cell]TOP SECRET-Privileged Access clearance management in accordance with the TOP SECRET-Privileged Access Standard[\/cell][cell]Not applicable[\/cell][cell]Mandatory for TS-PA holders[\/cell][\/row][\/table]"}],"child":[],"stats":[]},{"type":"section","ident":"21.3.2","title":"Share Information of Concern","block":[{"content":"[p]Sponsoring Entities are required to share relevant information about security clearance holder's ongoing eligibility and suitability for employment or to hold an Australian Government security clearance. This includes in relation to transfers of personnel, including temporary and permanent transfers within entities and to other entities. Note that information sharing may be limited by legislation, including the Australian Privacy Principles and an entity-enabling legislation.[\/p]"},{"content":"[p]Sharing relevant information, even when it is sensitive personal information, does not breach an individual's privacy provided that informed consent is received and the information is used for the purpose for which consent was given. It is therefore critical that entities obtain informed consent from all personnel (existing and potential) to share sensitive personal information with other entities and the Authorised Vetting Agency for the purposes of assessing their ongoing eligibility and suitability. This consent is best obtained at key information collection points, such as pre-employment screening and application for a security clearance, and updated at reasonable intervals, such as when conducting periodic employment checks and revalidation of a security clearance.[\/p]"},{"requirement":{"identifier":"pspf-0167","index":"0167.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity shares relevant information of concern, where appropriate.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"21.3.3","title":"Annual Security Checks","block":[{"content":"[p]Sponsoring entities must conduct an annual security check with all security cleared personnel. An annual security check provides an opportunity to discuss any identified behavioural concerns, improve awareness and understanding of security obligations, and reinforces a positive security culture.[\/p]"},{"content":"[lt]An annual security check addresses the person's:[\/lt][ul][li]compliance with general security clearance obligations, as well as any conditions associated with a conditional security clearance. General security clearance obligations for clearance holders include compliance with entity security procedures, in particular:[ul][li]reporting:[ul][li]changes in circumstances[\/li][li]security incidents[\/li][li]suspicious, ongoing, unusual or persistent contact with foreign and Australian nationals who are seeking information that they do not need to know, as well as suspicious, ongoing, unusual or persistent incidents (e.g. such as social media contact)[\/li][\/ul][\/li][li]completing security awareness training[\/li][\/ul][\/li][li]workplace behaviours to identify behaviours of concern.[\/li][\/ul]"},{"content":"[p]Line managers are well placed to conduct an annual security check as they are likely to have the best knowledge of their personnel's behaviour. Where appropriate, checks may be conducted in consultation with a security practitioner or an appropriate representative from the entity's human resources area. This may be particularly relevant where clearance conditions exist.[\/p]"},{"content":"[p]Entities may include the annual security check as part of their annual performance management process or as a stand-alone requirement. The annual security check does not replace an entity's responsibility to monitor and evaluate ongoing suitability through performance management, including code-of-conduct investigations.[\/p]"},{"content":"[p]If the sponsoring entities' annual security check identifies any concerns about a security clearance holder, they must share those concerns with the relevant Authorised Vetting Agency in addition to reporting any changes in circumstances, security incidents, and suspicious, ongoing, unusual or persistent contact reports as they occur.[\/p]"},{"content":"[p]Personnel holding a Positive Vetting security clearance are subject to additional requirements for annual security appraisals, which are set out in the SMSMP-PVG.[\/p]"},{"content":"[p]For personnel holding a TS-PA security clearance, the sponsoring entity is required to provide the relevant Authorised Vetting Agency with information from the annual security check and any information obtained as part of the insider threat program to inform the annual clearance review as set out in the TS-PA Standard.[\/p]"},{"requirement":{"identifier":"pspf-0168","index":"0168.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity conducts an annual security check with all security cleared personnel.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"21.3.4","title":"Review Eligibility Waivers","block":[{"content":"[p]Sponsoring entities must review security clearance eligibility waivers at least annually and before revalidation of a security clearance.[\/p]"},{"content":"[p]An eligibility waiver is role-specific, non-transferable, finite and subject to review. In other words, the waiver applies only while the clearance holder remains in the position for which the clearance was granted. The waiver does not follow the clearance holder to any other position without review. An eligibility waiver is not open ended and is subject to regular review to confirm that there is a continuing requirement for the waiver.[\/p]"},{"content":"[p]It is important that personnel with clearances subject to a waiver (as well as their line manager and in the case of ministerial staff their Chief of Staff or Minister, and potentially, co-workers) are informed of the limitations and conditions of the security clearance.[\/p]"},{"requirement":{"identifier":"pspf-0169","index":"0169.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity reviews eligibility waivers at least annually, before revalidation of a security clearance, and prior to any proposed position transfer.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"21.3.5","title":"Implement TS-PA Standard","block":[{"content":"[p]Sponsoring agencies are to implement specific requirements in the TS-PA Standard to assess and manage the ongoing suitability of TS-PA security clearance holders. This includes, but is not limited to, conducting annual security checks, facilitating contact reporting, collecting and assessing information of concern (including changes of circumstances), monitoring compliance with conditional security clearances and reviewing eligibility waivers at least annually.[\/p]"},{"content":"[p]The TS-PA Standard requires all entities that manage TS-PA security clearance subjects to implement an insider threat program. Insider threat programs enable organisations to identify and manage insider risk in a holistic and coordinated way. An effective insider threat program can protect critical resources, counter unintentional and malicious incidents, prevent loss of data and prevent reputational damage. To be effective, these programs should be both proactive and prevention focussed.[\/p]"},{"requirement":{"identifier":"pspf-0170","index":"0170.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p] The Sponsoring Entity monitors, assesses and manages personnel with TOP SECRET-Privileged access security clearances in accordance with the TOP SECRET-Privileged Access Standard.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"21.4","title":"Clearance Holder Maintenance Obligations","block":[{"content":"[p]Holders of an Australian Government security clearance must meet obligations in order to retain the clearance. These obligations are established by the Authorised Vetting Agency at the time the clearance is granted.[\/p]"},{"content":"[lt]The obligations include:[\/lt][ul][li]maintain a standard of behaviour that the public would reasonably expect of someone who holds a position of public trust and that meets the requirements of holding a security clearance[\/li][li]avoid the intake of excessive amounts of alcohol[\/li][li]not take illegal recreational or non-prescribed prescription drugs[\/li][li]notify the Authorised Vetting Agency of any reportable changes in personal circumstances[\/li][li]keep up-to-date with security clearance holder requirements[\/li][li]cooperate with security clearance assurance activities and undertake required security awareness training[\/li][li]protect classified information, resources and activities, including adherence to the need-to-know principle[\/li][li]report any suspicious or unusual occurrences in or around the workplace to your entity's security unit immediately[\/li][li]report all adverse changes in personality or suspicious behaviour displayed by work colleagues to entity's security unit or Authorised Vetting Agency[\/li][li]report suspicious, unusual or persistent contacts and incidents (contact reporting) with entity's security unit[\/li][li]act with honesty and integrity[\/li][li]act in accordance with applicable laws, regulations, determinations and comply with any lawful and reasonable direction given by a person who has the authority to give it[\/li][li]perform duties with care, diligence and with adherence to relevant security requirements[\/li][li]use official information, equipment and facilities in a proper and secure manner[\/li][li]disclose correct personal information when it is required for official purposes[\/li][li]disclose and avoid real or apparent conflicts of interest, financial or otherwise, and[\/li][li]not take advantage of a position or authority to seek or obtain a benefit or to avoid a liability or penalty[\/li][\/ul]"}],"child":[{"type":"section","ident":"21.4.1","title":"Reportable Changes in Circumstances","block":[{"content":"[p]Clearance holders must report any changes in circumstances that may affect their suitability to hold a security clearance. The Authorised Vetting Agency or Sponsoring Entity will provide the clearance holder with a list of reportable changes in circumstances at the time the clearance is granted.[\/p]"},{"content":"[lt]Reportable changes in circumstances include:[\/lt][ul][li]change of name or identity, including gender[\/li][li]change in citizenship or nationality, including dual-citizenship[\/li][li]change in significant relationships, including entering into, or ceasing, a marriage, domestic partnership or significant personal relationship[\/li][li]involvement or association with any group, society or organisation that may be a security concern[\/li][li]involvement with any individual that may be a security concern[\/li][li]suspicious, unusual, persistent, regular or ongoing contact with foreign nationals[\/li][li]relatives residing in a foreign country[\/li][li]changes of address or share-housing arrangements[\/li][li]residence in a foreign country[\/li][li]change in financial circumstances, including entering into a mortgage, incurring a significant debt, significant change to household income, receiving a lump sum payment or other financial windfall[\/li][li]change of employer[\/li][li]external business interests, including business activities with overseas individuals and entities[\/li][li]change in health or medical circumstances[\/li][li]change in criminal history, police involvement and association with criminal activity[\/li][li]disciplinary procedures[\/li][li]illicit or illegal drug use or alcohol problems[\/li][li]changes in religious beliefs[\/li][li]security incidents[\/li][li]international travel, and[\/li][li]identity document replacement following a cyber-hack, including driver's licence, passport and Medicare card.[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"21.5","title":"Security Clearance Revalidation","block":[{"content":"[p]Revalidation assesses a clearance holder's ongoing eligibility and suitability to hold a security clearance by repeating many of the checks undertaken to determine their initial suitability, and again considering the required character traits.[\/p]"},{"content":"[p]The revalidation covers the period since the initial clearance or last revalidation was completed, unless there are significant security concerns that raise doubts about the previous assessment, or indication of an enduring pattern of behaviour.[\/p]"},{"content":"[p]The Authorised Vetting Agency is responsible for commencing the revalidation process and should allow sufficient time to complete the revalidation before the due date so that the security clearance does not lapse. Where cases are complex or new security concerns are identified during the revalidation process, this may require additional time.[\/p]"},{"content":"[p]The Authorised Vetting Agency is required to share information of security concern about security clearance holders with the Sponsoring Entity so they can decide whether to suspend or limit the clearance holder's access to Australian Government classified information, systems or resources until the concerns are resolved.[\/p]"},{"requirement":{"identifier":"pspf-0171","index":"0171.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency reassesses a clearance holder's eligibility and suitability to hold a security clearance by revalidating minimum personnel security checks for a security clearance[\/p]"}]}},{"requirement":{"identifier":"pspf-0172","index":"0172.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency reassesses a clearance holder's eligibility and suitability to hold a Baseline, Negative vetting 1, Negative Vetting 2 or Positive Vetting security clearance, by considering their integrity in accordance with the Australian Government Personnel Security Adjudicative Standard.[\/p]"}]}},{"requirement":{"identifier":"pspf-0173","index":"0173.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The TOP SECRET-Privileged Access Vetting Authority reassesses a clearance holder's eligibility and suitability to hold a TOP SECRET-Privileged Access security clearance, by, assessing their trustworthiness in accordance with the TOP SECRET-Privileged Access Standard.[\/p]"}]}},{"requirement":{"identifier":"pspf-0174","index":"0174.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency reassess a clearance holder's eligibility and suitability to hold a security clearance by resolving any doubt in the national interest.[\/p]"}]}},{"table":"[table name='Table 34' title='Minimum Personnel Security Checks for Revalidation of Security Clearances'][head][cell]-[\/cell][cell]Security Clearance Level[\/cell][\/head][head][cell]Check[\/cell][cell]Baseline Vetting[\/cell][cell]Negative Vetting 1[\/cell][cell]Negative Vetting 2[\/cell][cell]Positive Vetting[\/cell][cell]TOP SECRET Privileged Access[\/cell][\/head][\/table]"}],"child":[{"type":"section","ident":"21.5.1","title":"Revalidation Timeframes","block":[{"content":"[p]The Authorised Vetting Agency is responsible for commencing the revalidation process and should allow sufficient time to complete the revalidation before the due date so that the security clearance does not lapse. Where cases are complex or new concerns are identified during the revalidation process, this may require additional time.[\/p]"},{"requirement":{"identifier":"pspf-0175","index":"0175.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency commences the security clearance revalidation process in sufficient time to complete the revalidation before the due date so that the security clearance does not lapse.[\/p]"}]}},{"requirement":{"identifier":"pspf-0176","index":"0176.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p] The Authorised Vetting Agency shares information of concern about security clearance holders with the Sponsoring Entity so they can decide whether to suspend or limit the clearance holder's access to Australian Government classified information, resources or activities until the concerns are resolved.[\/p]"}]}},{"content":"[p]See Table 34 for revalidation timeframes.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"21.6","title":"Information Sharing on Security Clearances","block":[{"content":"[p]Sponsoring Entities and Authorised Vetting Agencies are required to share relevant information about security clearance holder's ongoing eligibility and suitability for employment or to hold an Australian Government security clearance. This includes in relation to transfers of personnel, including temporary and permanent transfers within entities and to other entities. Note that information sharing may be limited by legislation, including the Australian Privacy Principles and an entity-enabling legislation.[\/p]"},{"content":"[p]Sharing relevant information, even when it is sensitive personal information, does not breach an individual's privacy provided that informed consent is received and the information is used for the purpose for which consent was given. It is therefore critical that entities obtain informed consent from all personnel (existing and potential) to share sensitive personal information with other entities and the Authorised Vetting Agency for the purposes of assessing their ongoing eligibility and suitability. This consent is best obtained at key information collection points , such as pre-employment screening and application for a security clearance, and updated at reasonable intervals, such as when conducting periodic employment checks and revalidation of a security clearance.[\/p]"},{"requirement":{"identifier":"pspf-0177","index":"0177.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Sponsoring Entity shares relevant information of security concern, where appropriate with the Authorised Vetting Agency.[\/p]"}]}},{"requirement":{"identifier":"pspf-0178","index":"0178.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency shares information of security concern about security clearance holders with the Sponsoring Entity.[\/p]"}]}},{"requirement":{"identifier":"pspf-0179","index":"0179.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency assesses and responds to information of security concern about security clearance holders, including reports from Sponsoring Entities.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"21.7","title":"International Travel","block":[{"content":"[p]Holding a security clearance is a privilege that comes with some restrictions. Negative Vetting 2, Positive Vetting and TOP SECRET-Privileged Access security clearances have specific obligations in relation to international travel. Security clearance holders briefed into compartments for codeword material, will be advised of other obligations, including those related to international travel.[\/p]"},{"content":"[p]All personnel who obtain a TS-PA security clearance are provided with a copy of the annex to the TS-PA Standard that outlines their obligations for maintaining their security clearance. These obligations include approval of all international travel. Additional information on these obligations is available from the insider threat team in each Sponsoring Entity.[\/p]"},{"requirement":{"identifier":"pspf-0180","index":"0180.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Negative Vetting 2 and higher clearance holders receive appropriate departmental travel briefings when undertaking international personal and work travel.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"22","title":"Separation","block":[{"content":"[p]Separation processes to protect Australian Government people, information and resources when personnel permanently or temporarily leave their employment with an entity are vital. Effectively managing personnel security includes ensuring departing personnel fulfil their obligations to safeguard Australian Government resources; this limits the potential for the integrity, availability and confidentiality of those resources to be compromised.[\/p]"},{"content":"[lt]Separating personnel include:[\/lt][ul][li]security cleared personnel, non-security cleared personnel, contractors and third parties[\/li][li]personnel voluntarily leaving an entity[\/li][li]personnel whose employment has been terminated for misconduct or other adverse reasons[\/li][li]personnel transferring temporarily or permanently to another Australian Government entity (including machinery of government changes)[\/li][li]personnel taking extended leave for 6 months or longer, and[\/li][li]personnel on leave without pay for 6 months or longer.[\/li][\/ul]"},{"content":"[p]See Security Clearance Status.[\/p]"}],"child":[{"type":"chapter","ident":"22.1","title":"Debriefing Procedures","block":[{"content":"[p]Separating personnel are to be advised of their continuing obligations under the Commonwealth Criminal Code and other relevant legislation, and to acknowledge these obligations prior to separation from the entity. This acknowledgement helps safeguard Australian Government resources and limit the potential for the integrity, availability and confidentiality of security classified information to be compromised.[\/p]"},{"content":"[p]Separating personnel who have access to security classified information and caveated information where additional compartment briefing requirements apply, are required to be debriefed to ensure they understand their continuing obligations. See the Australian Government Security Caveat Standard (on GovTEAMS) for further information on compartment briefing.[\/p]"},{"requirement":{"identifier":"pspf-0181","index":"0181.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Chief Security Officer, Chief Information Security Officer (or other relevant security practitioner) is advised prior to separation or transfer of any proposed cessation of employment resulting from misconduct or other adverse reasons.[\/p]"}]}},{"requirement":{"identifier":"pspf-0182","index":"0182.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Separating personnel are informed of any ongoing security obligations under the Commonwealth Criminal Code and other relevant legislation and those holding a security clearance or access security classified information are debriefed prior to separation from the entity.[\/p]"}]}},{"requirement":{"identifier":"pspf-0183","index":"0183.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Separating personnel transferring to another Australian Government entity, the entity, when requested, provides the receiving entity with relevant security information, including the outcome of pre-employment screening checks and any periodic employment suitability checks.[\/p]"}]}},{"requirement":{"identifier":"pspf-0184","index":"0184.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Separating personnel transferring to another Australian Government entity, the entity reports any security concerns (as defined in the in the Australian Security Intelligence Organisation Act 1979) to the Australian Security Intelligence Organisation.[\/p]"}]}},{"requirement":{"identifier":"pspf-0185","index":"0185.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]A risk assessment is completed to identify any security implications in situations where it is not possible to undertake the required separation procedures.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"22.2","title":"Withdrawal of Access","block":[{"content":"[p]Separating personnel, including those on extended leave or transferring from the entity, are required to have their access to access to Australian Government resources withdrawn, removed or suspended as soon as there is no longer a legitimate business requirement for the access. This may also include where personnel performing malicious activities are detected.[\/p]"},{"content":"[p]It is important to ensure that all access is withdrawn, removed or suspended including access to physical facilities, technology systems access, non-standard system access (e.g. administration privileges, remote access, SECRET or TOP SECRET network access), and any other special access arrangements.[\/p]"},{"requirement":{"identifier":"pspf-0186","index":"0186.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]Separating personnel have their access to Australian Government resources withdrawn upon separation or transfer from the entity, including information, technology systems, and resources.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"22.3","title":"Post-Separation Security Clearance Actions","block":[{"content":"[p]Security clearance actions only apply to personnel that hold a security clearance and take place after separation or transfer.[\/p]"},{"requirement":{"identifier":"pspf-0187","index":"0187.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"ALL","content":[{"content":"[p]The Sponsoring Entity advises the relevant Authorised Vetting Agency of the separation of a clearance holder, including any relevant circumstances (e.g. termination for cause) and any details, if known, of another entity or contracted service provider the clearance holder is transferring to, along with any identified risks or security concerns associated with the separation.[\/p]"}]}},{"content":"[lt]Examples of identified risks or security concerns include:[\/lt][ul][li]the individual's employment or contract is terminated for cause[\/li][li]the individual was subject to a code of conduct investigation, whether completed or not[\/li][li]the individual departed without a security debrief, and[\/li][li]any outstanding security issues, including any risks or issues identified through a risk assessment completed where separation procedures are not possible.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0188","index":"0188.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PER","applicability":"AVA","content":[{"content":"[p]The Authorised Vetting Agency manages and records changes in the security clearance status of separating personnel, including a change of Sponsoring Entity, and transfer personal security files where a clearance subject transfers to an entity covered by a different Authorised Vetting Agency, to the extent that their enabling legislation allows.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"domain","label":"Part Six","name":"PHYS","title":"Physical","block":[{"content":"[ul][li]Physical Security Lifecycle[\/li][li]Security Zones[\/li][li]Physical Security Measures and Controls[\/li][li]Event Security[\/li][\/ul]"}],"child":[{"type":"part","ident":"23","title":"Physical Security Lifecycle","block":[{"content":"[p]Protective security must be integrated during all stages of the physical security lifecycle - planning, selection, designing, approving, operating, modifying, reviewing and retiring entity facilities.[\/p]"},{"content":"[p]A consistent and structured approach to ensure protective security building construction, security zoning and physical security control measures of entity facilities. This ensures the protection of Australian Government people, information and physical resources secured by those facilities.[\/p]"},{"requirement":{"identifier":"pspf-0189","index":"0189.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Protective security is integrated in the process of planning, selecting, designing and modifying entity facilities for the protection of people, information and resources.[\/p]"}]}}],"child":[{"type":"chapter","ident":"23.1","title":"Plan Entity Facilities","block":[{"content":"[p]Site securing planning includes assessing the suitability of the physical security environment of a proposed site for entity facilities and whether a facility can be constructed or modified to incorporate security measures that provide appropriate risk mitigation strategies. While security measures prevent or reduce the likelihood of events, the site and design also needs to accommodate normal business.[\/p]"},{"content":"[p]An entity facility is the designated space, building or floor of a building that is designed and constructed in accordance with the PSPF and ASIO Technical Notes.[\/p]"}],"child":[{"type":"section","ident":"23.1.1","title":"Facility Security Plan","block":[{"content":"[lt]A facility security plan is required for all sites (including new facilities under construction or existing facilities undergoing major refurbishment) to assess the security risks associated with the facilities':[\/lt][ul][li]location and nature of the site[\/li][li]ownership or tenancy of the site (sole or shared, including multiple entities sharing the same space)[\/li][li]collateral exposure, such as the presence nearby of other 'attractive targets'[\/li][li]access to the site for authorised personnel and the public (if necessary) and preventing access as required[\/li][li]security classification of information and resources, including technology assets and related equipment, to be stored, handled or processed in each part of the site, this includes considering the need to hold security classified and other security classified discussions and meetings[\/li][li]other resources that will be on the site, and[\/li][li]protective security measures required for:[ul][li]the site as a whole[\/li][li]particular areas within the site (e.g. a floor or part of a floor that will hold information of a higher classification than the rest of the site)[\/li][li]storage, handling and processing of security classified information[\/li][li]security classified and other security classified discussions and meetings[\/li][li]business hours and out-of-hours, as they are likely to be different, for example increased risks from public and client contact during business hours, and external threats such as break and enters or insider threat may be more prevalent out-of-hours.[\/li][\/ul][\/li][\/ul]"},{"requirement":{"identifier":"pspf-0190","index":"0190.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]A facility security plan is developed for new facilities, facilities under construction or major refurbishments of existing facilities.[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"23.1.2","title":"Facility Site Selection","block":[{"content":"[p]Site selection is important part of planning and needs to factor the suitability of the physical security environment of a proposed site for entity facilities and whether a facility can be constructed or modified to incorporate security measures that provide appropriate risk mitigation strategies. While security measures prevent or reduce the likelihood of events, the site and design also needs to accommodate normal business.[\/p]"},{"content":"[p]Security-in-depth is a multi-layered system in which security measures combine to make it difficult for an intruder or authorised personnel to gain unauthorised access.[\/p]"},{"table":"[table name='Table 35' title='Site Selection Factors for Australian Government Facilities'][head][cell]Factor[\/cell][cell]Description[\/cell][\/head][row][cell]Neighbourhood[\/cell][cell]Local threat environment from neighbourhood-related issues such as local criminal activity, risks from neighbouring entities and businesses, suitability of neighbours, oversight of entity operations.[\/cell][\/row][row][cell]Standoff perimeter[\/cell][cell]Standoff perimeter distances where there is an identified threat from pedestrians and vehicle-based improvised explosive devices (IED). However, it may not be possible in urban areas to achieve an effective standoff distance for some threats. Entities are encouraged to seek additional advice for example blast engineering advice.[\/cell][\/row][row][cell]Site access and parking[\/cell][cell]Need and ability to control access to pedestrians and vehicles to the site including the facility, parking and standoff perimeter.[\/cell][\/row][row][cell]Building access point[\/cell][cell]Ability to secure all building access points including entries and exits, emergency exits, air intakes and outlets and service ducts.[\/cell][\/row][row][cell]Security Zones[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Environmental risks[\/cell][cell]Seek specialist advice about the risk of natural disasters and suitable mitigation strategies and security products.[\/cell][\/row][\/table]"},{"requirement":{"identifier":"pspf-0191","index":"0191.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Decisions on entity facility locations are informed by considering the site selection factors for Australian Government facilities.[\/p]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"23.2","title":"Design and Modify Entity Facilities","block":[{"content":"[p]Protection of people, information and resources is achieved through a combination of physical and procedural security measures that prevent or mitigate threats and attacks. Successive layers of physical security are required when planning for new entity facilities or modifying existing facilities.[\/p]"},{"content":"[p]Protection of people, information and resources is achieved through a combination of physical and procedural security measures that prevent or mitigate threats and attacks.[\/p]"},{"content":"[lt]Facilities should be designed or modified using successive layers of physical security:[\/lt][ul][li]Deter \u2014 measures that cause significant difficulty or require specialist knowledge and tools for adversaries to defeat.[\/li][li]Detect \u2014 measures that identify unauthorised action are being taken or have already occurred.[\/li][li]Delay \u2014 measures to impede an adversary during attempted entry or attack, or slow the progress of a detrimental event to allow a response.[\/li][li]Respond \u2014 measures that resist or mitigate the attack or event when it is detected.[\/li][li]Recover \u2014 measures to restore operations to normal levels following an event.[\/li][\/ul]"},{"content":"[p]Facilities are designed and modified in order to define restricted access areas according to the five Security Zones, with increasing restrictions and access controls as the zones progress from Zone One to Zone Five.[\/p]"},{"requirement":{"identifier":"pspf-0192","index":"0192.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]When designing or modifying facilities, the entity secures and controls access to facilities to meet the highest risk level to entity resources in accordance with Security Zone restricted access definitions.[\/p]"}]}},{"table":"[table name='Table 36' title='Security Zone Restricted Access Definitions'][head][cell]Security Zone[\/cell][cell]Restricted Access Definition[\/cell][\/head][row][cell]Zone One[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Zone Two[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Zone Three[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Zone Four[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][row][cell]Zone Five[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][\/table]"},{"content":"[p]See Minimum Protections and Handling Requirements for details of security classified information and resources that can be used and stored in each Security Zone.[\/p]"},{"content":"[p]See Security Zones.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"23.3","title":"Construct or Lease Entity Facilities","block":[{"content":"[p]All building work in Australia (including new buildings and new building work in existing buildings) must comply with the requirements of the Building Code of Australia (BCA).12 Some older buildings may not comply with the current codes. The BCA classifies buildings according to the purpose for which they are designed, constructed or adapted to be used. The BCA requirements for commercial buildings, including facilities used by entities, provide an increased level of perimeter protection as well as protection for resources and information where the compromise, loss of integrity or unavailability would have a business impact level of medium or below.[\/p]"},{"content":"[lt]Entities may include additional building elements to address specific risks identified in their risk assessment where building hardening may provide some level of mitigation. For example:[\/lt][ul][li]blast mitigation measures[\/li][li]forcible attack resistance[\/li][li]ballistic resistance[\/li][li]siting of road and public access paths, and[\/li][li]lighting (in addition to security lighting).[\/li][\/ul]"},{"content":"[p]See Physical Security Measures for building construction protections for Security Zones. See Security Zone Certification and Accreditation.[\/p]"},{"requirement":{"identifier":"pspf-0193","index":"0193.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[lt]Facilities are constructed in accordance the applicable ASIO Technical Notes to protect against the highest risk level in accordance with the entity security risk assessment in areas:[\/lt][ul][li]accessed by the public and authorised personnel, and[\/li][li]where physical resources and technical assets, other than security classified resources and technology, are stored.[\/li][\/ul]"}]}},{"requirement":{"identifier":"pspf-0194","index":"0194.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Facilities for Security Zones Two to Five that process, store or communicate security classified information and resources are constructed in accordance with the applicable sections of ASIO Technical Note 1\/15 - Physical Security Zones, and ASIO Technical Note 5\/12 - Physical Security Zones (TOP SECRET) areas.[\/p]"}]}}],"child":[],"stats":[]},{"type":"chapter","ident":"23.4","title":"Operate and Maintain Entity Facilities","block":[{"content":"[p]Staying secure requires ongoing activity to keep up to date with evolving security threats and vulnerabilities and to keep your security controls up to date and ensure they remain fit for purpose for your entity's operating environment.[\/p]"},{"requirement":{"identifier":"pspf-0195","index":"0195.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Entity facilities are operated and maintained in accordance with Security Zones and Physical Security Measures and Controls.[\/p]"}]}}],"child":[{"type":"section","ident":"23.4.1","title":"Review or Retire Entity Facilities","block":[{"content":"[p]Undertake regular reviews to ensure your security measures remain fit-for-purpose. Identify changes in your use of facilities, your organisation or the threat environment. Use this information to inform improvements.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"23.5","title":"International Entity Facilities (including Missions and Posts)","block":[{"content":"[p]All Australian Government international entity facilities, including missions, posts, embassies and consulates, including those managed by DFAT, are required to meet the PSPF requirements and be included in the managing entity's annual PSPF report on security.[\/p]"},{"content":"[p]DFAT is responsible for all aspects of security policy affecting Australian missions and staff attached to DFAT managed missions. DFAT also has a broader interest in international security conditions because of the high priority attached by the Australian Government to advising Australians about the risks they might face overseas.[\/p]"},{"content":"[p]The managing entity of each mission\/post is responsible for the implementation the PSPF to ensure appropriate physical, technical, information and personnel security procedures, measures and standards, and for coordinating business continuity and contingency planning at each mission\/post. The managing agency is normally DFAT, though other entities can assume this responsibility where DFAT is not represented.[\/p]"},{"content":"[p]See Minimum Protections and Handling Requirements for use and storage arrangements in each Security Zone for physical information and mobile devices.[\/p]"},{"content":"[p]See Physical Security Measures and Controls and Physical Security Measures and Controls Mandatory Elements in each Security Zone.[\/p]"},{"content":"[p]Secure Areas in International Entity Facilities (including Missions and Posts).[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"part","ident":"24","title":"Security Zones","block":[],"child":[{"type":"chapter","ident":"24.1","title":"Security Zones","block":[{"content":"[p]Security Zones define restricted access areas with increasing restrictions and access controls as the Security Zones progress from Zone One to Zone Five. Security Zones are primarily used to protect the security classified information, resources or activities that will be processed, stored or communicated in that area.[\/p]"},{"content":"[p]Security Zones provide a methodology for scalable physical security risk mitigation that entities apply based on their security risk assessment. Security Zones are constructed to protect against the highest risk level in accordance with the entity's security risk assessment in areas accessed by the public and authorised personnel, and where physical information and resources, other than security classified information and resources, are used, transmitted, stored or discussed.[\/p]"},{"content":"[p]The number and type of Security Zones required by an entity depends on the classification of information accessed, stored, processed or transmitted in the entity.[\/p]"},{"content":"[p]See Construct or Lease Entity Facilities for Security Zone restricted access requirements.[\/p]"},{"table":"[table name='Table 37' title='Security Zones Descriptions and Restricted Access'][head][cell]Security Zone[\/cell][cell]Description[\/cell][cell]Security Clearance for Ongoing Access[\/cell][cell]Restricted Access[\/cell][\/head][\/table]"},{"content":"[p]See Minimum Protections and Handling Requirements for use and storage arrangements in each Security Zone for physical information and mobile devices.[\/p]"},{"content":"[p]See Physical Security Measures and Controls and Physical Security Measures and Controls Mandatory Elements in each Security Zone.[\/p]"}],"child":[{"type":"section","ident":"24.1.1","title":"Secure Areas in International Entity Facilities (including Missions and Posts)","block":[{"content":"[p]The location and threat environment of some Australian Government international entity facilities (including missions and posts) necessitate more stringent protective security arrangements than entity facilities located in Australia. DFAT-managed international entity facilities use different terminology for 'Secure Areas' in place of Security Zones, most of which exceed the protections required for their Security Zone counterparts. These security areas used in some international entity facilities are described in Table 38.[\/p]"},{"table":"[table name='Table 38' title='Secure Area Descriptions and Restricted Access in DFAT-managed International Entity Facilities (including Missions and Posts)'][head][cell]Secure Area[\/cell][cell]Security Clearance for Access[\/cell][cell]Restricted Access[\/cell][\/head][\/table]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"24.2","title":"Security Zone Certification and Accreditation","block":[{"content":"[p]Certification and Accreditation of Security Zones provides a level of confidence that when information is shared, other entities can and will adequately protect it.[\/p]"},{"content":"[p]Entities are required to certify and accredit all areas where security classified information and resources will be used, transmitted, stored or discussed, in accordance with the applicable ASIO Technical Notes and authorities.[\/p]"}],"child":[{"type":"section","ident":"24.2.1","title":"Security Zone Certification Authorities","block":[{"content":"[p]Certification of Security Zones establishes the zone's compliance with the minimum physical security requirements to the satisfaction of the relevant certification authority. See Minimum Protections and Handling Requirements for use and storage arrangements in each Security Zone for physical information and mobile devices.[\/p]"},{"content":"[p]See Physical Security Measures and Controls and Physical Security Measures and Controls Mandatory Elements in each Security Zone.[\/p]"},{"content":"[p]See Secure Areas in International Entity Facilities (including Missions and Posts) for equivalent international secure areas.[\/p]"},{"content":"[p]For Zones One to Five, the CSO (or delegated security practitioner) may certify that the control elements have been implemented and are operating effectively. For Zone Five areas that are used to handle TOP SECRET information or aggregated information where the aggregation of information increases its business impact level to catastrophic, ASIO-T4 is the Certification Authority.[\/p]"},{"table":"[table name='Table 39' title='Certification Authority for Security Zones'][head][cell]-[\/cell][cell]Certification Authority[\/cell][\/head][head][cell]Control Measure[\/cell][cell]Zone One[\/cell][cell]Zone Two[\/cell][cell]Zone Three[\/cell][cell]Zone Four[\/cell][cell]Zone Five[\/cell][\/head][\/table]"},{"content":"[p]See also Technology and System Authorisation.[\/p]"},{"requirement":{"identifier":"pspf-0196","index":"0196.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Security Zones One to Four are certified by the Certification Authority in accordance with the PSPF and applicable ASIO Technical Notes before they are used operationally[\/p]"}]}},{"requirement":{"identifier":"pspf-0197","index":"0197.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Security Zone Five areas that contain TOP SECRET security classified information or aggregated information where the compromise of confidentiality, loss of integrity or unavailability of that information may have a catastrophic business impact level, are certified by ASIO-T4 before they are used operationally[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"24.2.2","title":"Security Zone Accreditation Authorities","block":[{"content":"[p]Security Zone accreditation involves compiling and reviewing all applicable certifications and other deliverables for the zone to determine and accept the residual security risks. Approval is granted for the Security Zone to operate at the desired level for a specified time.[\/p]"},{"table":"[table name='Table 40' title='Accreditation Authority for Security Zones'][head][cell]Security Zone[\/cell][cell]Accreditation Authority[\/cell][\/head][row][cell]Zones One to Five[\/cell][cell]Chief Security Officer (or delegate) when the controls are certified as meeting the applicable requirements for the Security Zone[\/cell][\/row][row][cell]Sensitive Compartmented Information Facility (SCIF) used to secure and access TOP SECRET systems and\/or sensitive compartmented information[\/cell][cell]Australian Signals Directorate[\/cell][\/row][\/table]"},{"requirement":{"identifier":"pspf-0198","index":"0198.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Security Zones One to Five are accredited by the Accreditation Authority before they are used operationally, on the basis that the required security controls are certified and the entity determines and accepts the residual risks.[\/p]"}]}},{"requirement":{"identifier":"pspf-0199","index":"0199.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Sensitive Compartmented Information Facility areas used to secure and access TOP SECRET systems and security classified compartmented information are accredited by the Australian Signals Directorate before they are used operationally[\/p]"}]}}],"child":[],"stats":[]},{"type":"section","ident":"24.2.3","title":"Security Zone Recertification and Reaccreditation","block":[{"content":"[p]Security Zone certification is time-limited. The assessment of compliance is specific to the role of the facility and the resources contained within the facility at the time of certification. This means that facilities may require recertification from time to time.[\/p]"},{"content":"[lt]Security Zone recertification and reaccreditation may be triggered by circumstances including:[\/lt][ul][li]expiry of the certification due to the passage of time[\/li][li]changes in the assessed business impact level associated with the security classified information or resources handled or stored within the zone[\/li][li]significant changes to the architecture of the facility or the physical security controls used[\/li][li]any other conditions stipulated by the Accreditation Authority, such as changes to the threat level or other environmental factors of concern[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]},{"type":"part","ident":"25","title":"Physical Security Measures and Controls","block":[{"content":"[p]There are a range of physical security measures that protect entity resources from being made inoperable or inaccessible, or being accessed, used or removed without proper authorisation. Entities enhance the protection of their physical resources by using successive layers or combinations of procedural and physical security measures.[\/p]"},{"content":"[p]Each Security Zone has individual control elements to achieve the required level of protection.[\/p]"},{"content":"[lt]These zone controls provide a level of assurance against:[\/lt][ul][li]the compromise, loss of integrity or unavailability of sensitive and security classified information, and[\/li][li]the compromise, loss or damage of sensitive and security classified resources.[\/li][\/ul]"},{"content":"[p]These control elements are based on the ASIO Technical Notes for the minimum requirements to protect security classified information and assets. The physical security measures detailed in the applicable ASIO Technical Notes are designed to protect security classified information and resources from covert and surreptitious attack.[\/p]"},{"content":"[p]Entity specific resources may require additional security mitigation treatments based on their risk assessment.[\/p]"},{"requirement":{"identifier":"pspf-0200","index":"0200.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p] Physical security measures are implemented to minimise or remove the risk of information and physical asset resources being made inoperable or inaccessible, or being accessed, used or removed without appropriate authorisation.[\/p]"}]}},{"requirement":{"identifier":"pspf-0201","index":"0201.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Physical security measures are implemented to protect entity resources, commensurate with the assessed business impact level of their compromise, loss or damage.[\/p]"}]}},{"requirement":{"identifier":"pspf-0202","index":"0202.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Physical security measures are implemented to minimise or remove the risk of harm to people.[\/p]"}]}}],"child":[{"type":"chapter","ident":"25.1","title":"Authorised Equipment and Commercial Services","block":[{"content":"[p]The Security Construction and Equipment Committee (SCEC) is responsible for evaluating security equipment for their suitability for use by the Australian Government. The SCEC determines which products will be evaluated and the priority of evaluation. Evaluated security products protect classified information of which the compromise would result in a business impact level of high or above.[\/p]"},{"content":"[p]Evaluated products are assigned a security level (SL) rating numbered 1 to 4. SL4 products offer high level security, while SL1 products offer the lowest acceptable level of security for government use. Approved items are listed in the SCEC Security Equipment Evaluated Product List (available to government personnel on GovTEAMS).[\/p]"},{"content":"[p]Entities may use SCEC-approved security equipment even where it is not mandated. Alternatively, entities can use suitable commercial equipment that complies with identified security related Australian and International Standards for the protection of people and information and physical resources that do not have a confidentiality BIL of medium or above. ASIO-T4 has developed the Security Equipment Guides to assist entities to select security equipment not tested by SCEC.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"25.2","title":"Security Containers, Cabinets and Rooms","block":[{"content":"[p]Suitably assessed security containers and cabinets are used to secure information, portable and valuable assets and money.[\/p]"},{"requirement":{"identifier":"pspf-0203","index":"0203.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]The appropriate container, safe, vault, cabinet, secure room or strong rooms is used to protect entity information and resources based on the applicable Security Zone and business impact level of the compromise, loss or damage to information or physical resources.[\/p]"}]}}],"child":[{"type":"section","ident":"25.2.1","title":"SCEC Approved Security Containers","block":[{"content":"[p]SCEC approved security containers are for storage of security classified information and resources and are not for the storage of valuable, important, attractive, significant or dangerous resources. The designs of these containers provide a high level of tamper evidence of covert attack and significant delay from surreptitious attack, but provide limited protection from a forcible attack.[\/p]"},{"content":"[lt]There are three levels of SCEC-approved containers:[\/lt][ul][li]Class A\u2014protects information that has an extreme or catastrophic business impact level in situations assessed as high risk. These containers can be extremely heavy and may not be suitable in some facilities with limited floor loadings.[\/li][li]Class B\u2014protects information that has an extreme or catastrophic business impact level in situations assessed as low risk. They are also used for information that has a high or extreme business impact level in situations assessed as higher risk. These containers are robust filing cabinets or compactuses fitted with combination locks. Class B containers size and weight needs to be considered when selecting a location. There are broadly two types of Class B containers:[ul][li]heavy constructed models that are suitable for use where there are minimal other physical controls[\/li][li]lighter constructed models that are used in conjunction with other physical security measures.[\/li][\/ul][\/li][li]Class C\u2014protects information up to an extreme business impact level in situations assessed as low risk. They are also used for information that has a medium business impact level in situations assessed as higher risk by the entity. These containers are fitted with a SCEC-approved restricted keyed lock and are of similar construction to the lighter Class B containers.[\/li][\/ul]"}],"child":[],"stats":[]},{"type":"section","ident":"25.2.2","title":"Commercial Safes and Vaults","block":[{"content":"[p]Commercial safes and vaults provide a level of protection against forced entry. A vault is a secure space that is generally built in place and is normally larger than a safe. A safe is normally smaller than a vault and may be moveable. Safes and vaults provide varying degrees of protection depending on the construction and may be used to store valuable physical resources. Table 41 details the commercial safes and vaults to protect physical resources (other than classified resources) in each Security Zone.[\/p]"},{"content":"[p]See Minimum Protections and Handling Requirements for details of security classified information and resources that can be used and stored in each Security Zone.[\/p]"},{"table":"[table name='Table 41' title='Commercial Safes and Vaults to Protect Physical Resources (other than classified resources)'][head][cell]Business impact level[\/cell][cell]1 Low business impact[\/cell][cell]2 Low to medium business impact[\/cell][cell]3 High business impact[\/cell][cell]4 Extreme business impact[\/cell][cell]5 Catastrophic business impact[\/cell][\/head][\/table]"}],"child":[],"stats":[]},{"type":"section","ident":"25.2.3","title":"Secure Rooms and Strongrooms","block":[{"content":"[p]Secure rooms and strongrooms may be used instead of containers to secure large quantities of official information, classified resources and valuable assets, where the compromise, loss or damage would have a business impact level.[\/p]"},{"content":"[p]Secure rooms are designed to protect its contents from covert attack and have some degree of fire protection of the contents if the secure room is constructed properly. Secure rooms are suitable for open storage of large quantities of official information and classified resources, while maintaining the levels of protection provided by a Class A, B or C container.[\/p]"},{"content":"[lt]Advice on construction specifications for secure rooms is detailed in the ASIO Technical notes available for Australian Government security personnel only from the protective security policy community on GovTEAMS:[\/lt][ul][li]Technical Note 7-06 Class A Secure Room.[\/li][li]Technical Note 8-06 Class B Secure Room.[\/li][li]Technical Note 9-06 Class C Secure Room.[\/li][\/ul]"},{"content":"[p]SCEC-approved commercial Class A and B doors and demountable security rooms are listed on the Security Equipment Evaluated Products List.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"25.3","title":"Perimeter Doors, Locks and Hardware for Facilities","block":[{"content":"[p]Locks can deter or delay unauthorised access to information and physical resources. SCEC-approved locks and hardware rated to Security Level 3 are required in Security Zones Three to Five (see the Security Equipment Evaluated Product List available on GovTEAMS).[\/p]"},{"content":"[p]Entities may use suitable commercial locking systems in other areas.[\/p]"},{"requirement":{"identifier":"pspf-0204","index":"0204.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Perimeter doors and hardware in areas that process, store communicate security classified information or resources are constructed and secured in accordance with the physical security measures and controls for perimeter doors and hardware.[\/p]"}]}},{"content":"[p]See Physical Security Measures and Controls Mandatory Elements.[\/p]"},{"content":"[p]See Table 42: Physical Security Measures and Controls - Perimeter Doors and Hardware for mandatory requirements.[\/p]"}],"child":[{"type":"section","ident":"25.3.1","title":"Restricted Keying Systems","block":[{"content":"[p]Restricted keying systems provide a level of assurance to entities that unauthorised duplicate keys have not been made.[\/p]"},{"content":"[lt]To mitigate common keying system compromises, controls include:[\/lt][ul][li]legal controls, for example registered designs and patents[\/li][li]levels of difficulty in obtaining or manufacturing key blanks and the machinery used to cut duplicate keys, or[\/li][li]levels of protection against compromise techniques, such as picking, impressioning and decoding.[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"25.4","title":"Access Control Systems","block":[{"content":"[p]Access control is a measure or group of measures that allows authorised personnel, vehicles and equipment to pass through protective barriers while preventing unauthorised access.[\/p]"},{"requirement":{"identifier":"pspf-0205","index":"0205.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Access by authorised personnel, vehicles and equipment to Security Zones One to Five is controlled in accordance with the physical security measures and controls for access control for authorised personnel.[\/p]"}]}},{"content":"[p]See Table 37: Security Zones Descriptions and Restricted Access Table 43: Physical Security Measures and Controls - Access Control for Authorised Personnel (including contracted and seconded staff) for mandatory requirements.[\/p]"}],"child":[{"type":"section","ident":"25.4.1","title":"Identity Cards","block":[{"content":"[p]Identity cards allow the recognition of authorised personnel in entity facilities.[\/p]"},{"content":"[lt]Identity cards are an essential access control measure and should be:[\/lt][ul][li]uniquely identifiable[\/li][li]worn by all authorised personnel, authorised contractors and visitors[\/li][li]be clearly displayed at all times while in entity facilities (and removed outside entity facilities), and[\/li][li]audited regularly in accordance with the entity's risk assessment.[\/li][\/ul]"},{"content":"[p]Identity card-making equipment and spare, blank or returned cards should be secured within a Security Zone Two or higher zone based on the entity's security risk assessment.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"25.4.2","title":"Authentication Factors and Dual Authentication","block":[{"content":"[lt]There are three categories of authentication factors that can be used to validate identity:[\/lt][ul][li]What you have (for example keys, identity cards, passes).[\/li][li]What you know (for example personal identification numbers).[\/li][li]Who you are (for example visual recognition, biometrics).[\/li][\/ul]"},{"content":"[p]Dual authentication requires the use of factors from two different categories, for example an identity card and a personal identification number.[\/p]"},{"content":"[p]Dual authentication is required for access to Security Zone Five. Entities may use dual authentication in other circumstances where their security risk assessment identifies a need to mitigate the risk of unauthorised access.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"25.4.3","title":"Visitor Access Control","block":[{"content":"[p]A visitor is anyone who is not authorised to have ongoing access to all or part of an entity's facilities. Visitor access control is normally an administrative process; however, this can be supported by use of electronic access control systems.[\/p]"},{"content":"[lt]Visitor registers are used for recording visitor's name, entity or organisation, purpose of visit, date and time of arrival and departure, and visitor pass number. Visitor passes are required to be:[\/lt][ul][li]visible at all times[\/li][li]collected and disabled at the end of the visit, and[\/li][li]audited at the end of the day.[\/li][\/ul]"},{"content":"[lt]Receptionists and guards are recommended to have:[\/lt][ul][li]detailed auditable visitor control and access instructions, and[\/li][li]a secure method of calling for immediate assistance if threatened.[\/li][\/ul]"},{"requirement":{"identifier":"pspf-0206","index":"0206.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Access by visitors to Security Zones One to Five is controlled in accordance with the physical security measures and controls for access control for visitors.[\/p]"}]}},{"content":"[p]See Table 44: Physical Security Measures and Controls - Access Control for Visitors for mandatory elements.[\/p]"}],"child":[{"type":"topic","ident":"25.4.3.1","title":"Foreign Security Assessment Visits","block":[{"content":"[p]Some international agreements or arrangements allow security assessment visits where foreign personnel access secure areas or facilities. The purpose of these visits is to assure foreign governments of the suitability and implementation of security procedures and the protection of areas or facilities where their information or resources are stored and handled.[\/p]"},{"content":"[p]Foreign government personnel visitors must hold a valid level of Australian or foreign government security clearance for access to the foreign government information and resources in the facility. International agreements and arrangements commonly require that the National Security Authority or Competent Security Authority are advised of any security assessment visits. See International Information Sharing.[\/p]"}],"child":[],"stats":[]},{"type":"topic","ident":"25.4.3.2","title":"Event Security","block":[{"content":"[p]Entities must consider the security of all Australian Government events they manage, plan or host, whether organised by the entity or outsourced.[\/p]"},{"content":"[p]The Department of Home Affairs is responsible the coordination of national security arrangements, including developing strategic security risk assessments for events that are declared by the Prime Minister as Special Events.[\/p]"},{"content":"[p]State or territory government agencies should seek advice from the jurisdictional police or the jurisdictional agency responsible for the event on behalf of their government.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"section","ident":"25.4.4","title":"Ongoing Third-party Access to Facilities","block":[{"requirement":{"identifier":"pspf-0207","index":"0207.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[lt]The Accountable Authority or Chief Security Officer approves ongoing (or regular) access to entity facilities for people who are not directly engaged by the entity or covered by the terms of a contract or agreement, on the basis that the person:[\/lt][ul][li]has the required security clearance level for the Security Zone\/s, and[\/li][li]a business need supported by a business case and security risk assessment, which is reassessed at least every two years.[\/li][\/ul]"}]}}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"25.5","title":"Perimeter Access Control","block":[{"content":"[p]Perimeter access controls restrict access to entity facilities and increase the level of deterrence, detection and delay.[\/p]"},{"content":"[lt]Types of perimeter access controls include, but are not limited to:[\/lt][ul][li]fences and walls used to define and secure the perimeter[\/li][li]pedestrian barriers used to restrict pedestrian access through fences or walls by installing entry and exit points, and[\/li][li]vehicle security barriers.[\/li][\/ul]"},{"content":"[p]The level of protection a fence provides depends on its height, construction, materials, access control and any additional features that increase its performance or effectiveness, for example lighting, signage or connection to an external alarm.[\/p]"},{"content":"[p]Entities that face significant threats and those with larger, multi-building facilities may require perimeter access controls to restrict access to their facilities.[\/p]"},{"content":"[p]The Security Equipment Evaluated Product List contains details on perimeter intrusion detection devices. Refer to the ASIO-T4 Security Equipment Guide SEG-003 Perimeter Security Fences, SEG-024 Access Control Portals and Turnstiles, Australian Standard AS 1725.1\u2014Chain-link fabric security fencing and gates, and Australian Standard AS 3016\u2014Electrical installations\u2014Electric security fences.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"25.6","title":"Security Alarm Systems","block":[{"content":"[p]Security alarm systems (SAS) provide detection of unauthorised access to entity facilities. However, an alarm system is only effective if it is used in conjunction with other measures designed to delay and respond to unauthorised access. Where possible security alarm systems should be configured to monitor devices in high risk areas such as irregularly accessed areas, roof spaces, inspection hatches and underfloor cavities.[\/p]"},{"content":"[lt]Alarm systems can be broadly divided into two types:[\/lt][ul][li]Perimeter (or external) Intrusion Detection Systems (PIDS) or alarms - PIDS provide detection of unauthorised breaches of the perimeter and may be of value to entities that have facilities enclosed in a perimeter fence or facilities located on a large land holding.[\/li][li]internal security alarm systems - a combination of SCEC-approved security alarm systems and commercial security alarm systems can be used after consideration of the zone requirements and entity security risk assessment. Security alarm systems may be single sector or sectionalised to give coverage to specific areas of risk. Sectionalised alarm systems allow greater flexibility as highly sensitive areas can remain secured when not in use and other parts of the facility are open.[\/li][\/ul]"},{"content":"[p]Security alarm systems require periodic testing and maintenance from an authorised service provider, preferably every two years (at a minimum) to ensure the alarm system is continually operational.[\/p]"},{"requirement":{"identifier":"pspf-0208","index":"0208.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Unauthorised access to Security Zones One to Five is controlled in accordance with the physical security measures and controls for security alarm systems.[\/p]"}]}},{"content":"[p]See Table 45: Physical Security Measures and Controls - Security Alarm Systems (SAS) for mandatory elements.[\/p]"}],"child":[{"type":"section","ident":"25.6.1","title":"SCEC-Approved Type 1A Security Alarm Systems","block":[{"content":"[p]SCEC-approved Type 1A security alarm systems provide malicious insider threat protection not provided by commercial systems. SCEC-approved Type 1A security alarm systems protect SECRET, TOP SECRET and certain codeword information where the compromise, loss of integrity or unavailability of the aggregate of information would cause extreme or catastrophic damage to Australia's national security.[\/p]"},{"content":"[p]ASIO-T4 provides advice on SCEC Type 1A security alarm systems and may approve, other site-specific arrangements for Zones Four and Five. ASD may approve site-specific arrangements for the security of sensitive compartmented information facilities (SCIF).[\/p]"},{"content":"[p]SCEC Security Zone Consultant Register located in the Protective Security Policy community on GovTEAMS lists SCEC-endorsed Security Zone Consultants by state and territory.[\/p]"}],"child":[],"stats":[]},{"type":"section","ident":"25.6.2","title":"Commercial Security Alarm Systems","block":[{"content":"[p]Commercial security alarm systems are graded on the level of protection they provide.[\/p]"},{"content":"[lt]The AS\/NZS 2201.1 levels of security alarm systems include:[\/lt][ul][li]Class 1 or 2 are only suitable for domestic use.[\/li][li]Class 3 or 4 are suitable for the protection of normal business operations in most entities.[\/li][li]Class 5 is suitable for protection of information and physical resources up to an extreme business impact level.[\/li][\/ul]"},{"content":"[lt]There are a number of commercial security alarm options that may be suitable, including:[\/lt][ul][li]duress alarms (or request-for-assistance devices) allow personnel to call for assistance in response to a threatening incident[\/li][li]individual item alarms (or alarm circuits) provide additional protection to valuable physical resources in premises and on display, and[\/li][li]vehicle alarms to remotely monitor vehicle security where the business impact level of the loss of information or physical resources in the vehicle, or the vehicle itself, is high or above. Remote vehicle alarms may also be linked to remote vehicle tracking and immobiliser systems.[\/li][\/ul]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"25.7","title":"Interoperability of Security Alarm Systems and External Integrated Systems","block":[{"content":"[p]The more interoperability between security alarm systems and external integrated systems (e.g. building management systems, closed circuit television and electronic access controls systems) the greater the security alarm system vulnerabilities to unauthorised access and tampering.[\/p]"},{"content":"[p]Ensure the alarm cannot be disabled by the access control system.[\/p]"},{"content":"[p]Ensure limited one way interoperability in accordance with the Type 1A SAS for Australian Government\u2014Product: Integration specification. The alarm system may disable access control system when activated.[\/p]"},{"content":"[p]See Table 45: Physical Security Measures and Controls - Security Alarm Systems (SAS).[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"25.8","title":"Security Guards","block":[{"content":"[p]Security guards provide deterrence against loss of information and physical resources and can provide a rapid response to security incidents. Stationary guards and guard patrols may be used separately or in conjunction with other security measures. The response time for off-site guards should be less than the delay given by the total of other controls.[\/p]"},{"requirement":{"identifier":"pspf-0209","index":"0209.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Security guard arrangements in Security Zones One to Five are established in accordance with the physical security measures and controls for security guards.[\/p]"}]}},{"content":"[p]See Table 46: Physical Security Measures and Controls - Security Guards for mandatory elements.[\/p]"}],"child":[{"type":"section","ident":"25.8.1","title":"Out-of-Hours Security Guard Services","block":[{"content":"[p]Entities may use security guard services out-of-hours in response to alarms for all Security Zones. Entities may use out-of-hours guard patrols instead of a security alarm system in Zones Two and Three. However, for Zone Three, where out-of-hours guard patrols are used instead of security alarm systems, patrols must be performed at random intervals within every four hours.[\/p]"}],"child":[],"stats":[]}],"stats":[]},{"type":"chapter","ident":"25.9","title":"Technical Surveillance Countermeasures","block":[{"content":"[p]Technical Surveillance Countermeasures (TSCMs) are implemented to protect security classified discussions from technical compromise. This can be achieved through real-time audio interception using electronic transmitting and receiving equipment or by a TSCM inspection that searches for surveillance devices. These countermeasures are also applicable to covert video recordings.[\/p]"},{"content":"[p]A TSCM inspection is a security mitigation that deters, detects and defeats covert electronic devices that may be audio, video and imaging technologies. A TSCM inspection identifies technical security weaknesses and vulnerabilities and provides a high level of assurance that an area is not technically compromised, however it is not a guarantee. Developers of covert technology constantly update and develop new equipment and technologies to avoid detection.[\/p]"},{"content":"[p]Contact ASIO-T4 for advice on TSCM inspections. Requests for TSCM inspections can be made in accordance with the Protective Security Circular No 165 Facilitating TSCM inspections in Australia. See the Information Security Manual for controls to protect technology used for security classified discussions.[\/p]"},{"requirement":{"identifier":"pspf-0210","index":"0210.0","revision":0,"datestring":"Oct-24","datetime":"1729838373","domain":"PHYS","applicability":"ALL","content":[{"content":"[p]Technical surveillance countermeasures for Security Zones One to Five are established in accordance with the physical security measures and controls for technical surveillance countermeasures.[\/p]"}]}},{"content":"[p]See Table 47: Physical Security Measures and Controls - Technical surveillance counter-measures (TSCM) for mandatory elements.[\/p]"}],"child":[],"stats":[]},{"type":"chapter","ident":"25.10","title":"Physical Security Measures and Controls Mandatory Elements","block":[{"table":"[table name='Table 42' title='Physical Security Measures and Controls - Perimeter Doors and Hardware'][\/table]"},{"table":"[table name='Table 43' title='Physical Security Measures and Controls - Access Control for Authorised Personnel (including contracted and seconded staff)'][\/table]"},{"content":"[p]See Security Zones for Security Clearance requirements for ongoing and temporary access.[\/p]"},{"table":"[table name='Table 44' title='Physical Security Measures and Controls - Access Control for Visitors'][\/table]"},{"table":"[table name='Table 45' title='Physical Security Measures and Controls - Security Alarm Systems (SAS)'][\/table]"},{"table":"[table name='Table 46' title='Physical Security Measures and Controls - Security Guards'][head][cell]Measure[\/cell][cell]Zone One[\/cell][cell]Zone Two[\/cell][cell]Zone Three[\/cell][cell]Zone Four[\/cell][cell]Zone Five[\/cell][\/head][row][cell]Security guards and patrols[\/cell][cell]Determined by entity risk assessment.[\/cell][cell]Determined by entity risk assessment. The response time for off-site guards is recommended to be less than the delay given by the total of other controls.[\/cell][cell]As for Zone Two.[\/cell][cell]As for Zone Two.[\/cell][cell]As for Zone Two.[\/cell][\/row][row][cell]Out-of-hours security guard services[\/cell][cell]Security guard services may be used out-of-hours to respond to alarms.[\/cell][cell]Out-of-hours guard patrols may be used instead of a SAS. Security guard services may be used out-of-hours to respond to alarms.[\/cell][cell]Out-of-hours guard patrols may be used instead of a SAS. If no SAS, patrols must be performed at random intervals within every four hours required. Security guard services may be used out-of-hours to respond to alarms.[\/cell][cell]Out-of-hours guard patrols must not be used in place of a SAS. Security guard services may be used out-of-hours to respond to alarms.[\/cell][cell]Out-of-hours guard patrols must not be used in place of a SAS. Security guard services may be used out-of-hours to respond to alarms.[\/cell][\/row][\/table]"},{"table":"[table name='Table 47' title='Physical Security Measures and Controls - Technical surveillance counter-measures (TSCM)'][head][cell]Measure[\/cell][cell]Zone One[\/cell][cell]Zone Two[\/cell][cell]Zone Three[\/cell][cell]Zone Four[\/cell][cell]Zone Five[\/cell][\/head][row][cell]Technical surveillance counter-measures[\/cell][cell]No requirement.[\/cell][cell]No requirement.[\/cell][cell]Determined by entity risk assessment.[\/cell][cell]As for Zone Three.[\/cell][cell]\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t[\/cell][\/row][\/table]"}],"child":[],"stats":[]}],"stats":[]}],"stats":[]}]}}}