Section 1 - Purpose
(1) This Procedure specifies the actions required to classify Information that is owned or handled by Macquarie University (the University) and facilitate the application of appropriate security measures in accordance with the Cyber Security Policy.
Scope
(2) This Procedure applies to:
- all Information collected, created, stored, or processed by, or for, the University on computer and network resources; and
- all individuals who handle Information for the University.
Top of PageSection 2 - Policy
(3) Refer to the Cyber Security Policy.
Top of PageSection 3 - Procedures
Responsibilities and Required Actions
Information Handling
(4) Information must be handled in a responsible and appropriate manner. Before collecting, storing or distributing Information, University staff, students and other authorised individuals must:
- classify the Information against security classification and privacy classification;
- determine the length of time that the Information needs to be retained and how the Information can be securely erased when no longer required;
- minimise the Information (fields and records) that is distributed to only that which is required;
- engage Macquarie IT to review the compliance of third parties who are required to receive the Information; and
- be protected while being transferred in accordance with the Encryption section of the Computer and Network Security Policy.
(5) If Confidential or Highly Sensitive Information is shared with an unauthorised party, exposed in an uncontrolled location, lost, or accidentally received, the following actions must be taken:
- immediately notify the relevant manager or supervisor;
- log the incident with the IT Service Desk through OneHelp;
- do not attempt to investigate, delete or remediate the exposure; and
- preserve all relevant records, including emails and logs.
(6) Where an incident involves personal Information, health Information or sensitive personal Information, the Cyber Security team must notify the University Privacy Officer (privacyofficer@mq.edu.au), who will assess the incident under the Data Breach Policy and coordinate mandatory notification obligations.
(7) For urgent cyber security incidents, the Chief Information Security Officer (cyber@mq.edu.au) must be contacted so that the Cyber Team can manage the incident in accordance with the University's cyber security incident response plan.
Information Classification
(8) The minimum-security standards for protecting University Information on computer systems and networks are established in the Computer and Network Security Policy.
(9) Information takes the highest classification of any element it contains. Combining, aggregating or extracting Information into a new record or dataset does not lower its classification.
(10) The security classification and, where applicable, privacy classification must be recorded on the Information, its container or metadata when created or collected. Email markings must reflect the highest classification of the subject, body and attachments.
(11) Information may be reclassified to a lower security classification only following a documented decision by the Information owner, in consultation with Macquarie IT Cyber Security. Higher-classified copies must be securely deleted or destroyed before the reclassification takes effect.
(12) Any internal correspondence that has no labelling or Information classification applied will be considered 'MQU - General Internal’.
Table 1: Security Classification
Classification |
Description |
Examples |
Handling and protection |
|
Public |
Information that has been formally authorised for release into the public domain by the Information owner or an authorised delegate. |
Marketing material
Published research Information Student course Information Academic calendar |
May be distributed without restriction. |
|
Internal |
Information that poses a moderate risk to the University if exposed in an unauthorised manner or damaged. |
Teaching materials
General intellectual property IT operational reports
MQU issued staff and student contact details
Project documentation
Permanently de-identified research data |
May be distributed to Macquarie staff using systems and services endorsed for internal use by the CIDO.
This is the default classification level for unclassified Information. |
|
Confidential |
Information that poses a significant risk to the University if exposed in an unauthorised manner or damaged. |
University premises access records
Unpublished research data Strategy, presentations and documents
Financial records Audit reports Council papers
Mailboxes containing student or staff correspondence |
May be distributed to University staff who have a specific and appropriate need to receive the Information.
Information and fields must be limited to only that which is necessary.
May only be processed or stored on systems and services endorsed for internal use by the CIDO. |
|
Highly Sensitive |
Information that poses a high regulatory, reputational or commercial risk to the University if damaged or exposed in an unauthorised manner.
Information that poses a privacy risk to identifiable person:
Health Information (HI)*
Sensitive Personal Information (SPI)* |
Datasets, extracts or reports containing the personal Information of multiple individuals
Identifiable digital activity and access records (including Wi-Fi)
Building access records relating to an individual
Passwords, passphrases and private keys
Cloud and system administration account credentials
API keys, tokens and service account credentials
Records containing data with a Privacy Classification of HI or SPI:
Student academic and administration records
Job applicant, employment and staff administration records
Patient, client and clinical records
Identifiable research data relating to individuals
*See the Privacy Classification table for HI and SPI examples |
Seek guidance from Macquarie IT Cyber Security before sharing data internally or externally.
Additional security measures are required for the capturing, processing, and storing of highly sensitive Information as indicated below.
|
Table 2: Privacy Classification
Classification |
Description |
Examples (not exhaustive) |
Handling and Protection* |
|
N/A |
Information is not related to a reasonably identifiable person. |
De-identified statistics |
N/A |
|
Personal Information (PI) |
Information or an opinion about a reasonably identifiable person. |
Full name
MQU issued Work & Student email address
Job title, position and work unit
Work phone number
Macquarie University ID or student ID
Work or campus address
Login name or username
Screen name or nickname
Staff directory or profile entry |
Minimum Security Classification is Internal |
|
Health Information (HI) |
Health status and care Information that relates to a reasonably identifiable person. |
Patient or client medical records
Diagnoses, illness and disability
Test and laboratory results
Scan images
Prescriptions and medical history
Mental and physical health conditions
Appointments and referrals
Health cover and billing for a health service
Genetic Information
Health opinions about an individual
Identifiable clinical research data
Patient identifiers |
Minimum Security Classification is Highly Sensitive |
|
Sensitive Personal Information (SPI)
SPI Includes Sensitive Information and Critical Personal Information*. |
SPI includes Sensitive Information and Critical Personal Information.
Sensitive Information is an individual’s ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities. |
Ethnic/racial origin, political opinions, religious/philosophical beliefs, trade union membership, sexual activities. |
Additional security measures are required for the processing and storing HI and SPI.
Data controls for Highly Sensitive plus:
Control access and apply Read Auditing inside System of Record
Data Masking outside System of Record
* This is not exhaustive but indicative of the level of protection required
|
|
Critical Personal Information (CPI)* is Information that may present a high privacy risk outcome to an individual:
Locating or contacting an individual in their private capacity
Identity theft or impersonation
Authentication or verification (excluding work email and MQ ID)
Behavioural tracking
Financial fraud
Law enforcement, or vulnerability (children, DV victims)
*As defined by MQU
|
Residential address
Date of birth
Driver licence number
Tax file number
Bank account number
Financial transactions
Passport number
Visa number
Emergency contact details
Behavioural tracking (attendance, location)
Credit card numbers
Biometrics (face image, fingerprints, signature)
Government or third-party ID numbers (excluding MQ and student ID)
Vehicle registration number
Personal (non-work) email address
Personal (non-work) phone number
Authentication credentials and identity verification answers
Details identifying a person at risk (children, DV, law enforcement matters) |
Additional Requirements for Handling Highly Sensitive Information
(13) When capturing, processing, storing or otherwise handling highly sensitive Information University staff, students and other authorised individuals are required to request additional security controls on the computer systems and applications that they use. Additional controls may include, but are not limited to:
- Multi-Factor Authentication for remote access to University systems and cloud applications;
- Multi-Factor Authentication for laptop and mobile device access;
- encryption for cloud storage, computer disks and mobile devices; and
- data backup facility that provides secure transport and storage.
(14) Cardholder data (including credit and debit card numbers) must be handled in accordance with the Payment Card Industry Data Security Standard (PCI DSS) and must not be captured, stored, processed or transmitted on any University system, application or channel that has not been approved for that purpose by Macquarie IT Cyber Security.
(15) The above controls are provided by Central IT and may be different depending on the systems in use. To request the above controls please contact the IT Service Desk through OneHelp.
Top of PageSection 4 - Guidelines
(16) Nil.
Top of PageSection 5 - Definitions
(17) The following definitions apply for the purpose of this Procedure:
- Data Masking means obscuring, truncating, tokenising or redacting data elements so the Information cannot be attributed to an identifiable individual by any one directly accessing the data. This is put in place to stop reading of data when it is being stored outside the System of Record which controls and audits access.
- Information means any information in either physical or electronic format that is generated, created, stored, purchased or received during the conduct of University operations.
- Multi-Factor Authentication is authentication using two or more different authentication factors, being: something the user knows (such as a password or passphrase); something the user has (such as a security key, smart card, passkey, smartphone or one-time password token); or something the user is (such as a fingerprint or facial geometry).
- Read Auditing means logging each access to, or viewing of, a record, attributable to an identified user account, and retaining those logs for review.
- System of Record means the University system, application or repository formally approved to be the authoritative store for Information of that classification.