Bulletin Board - Document Comments

Bulletin Board - Review and Comment

Step 1 of 3: Comment on Document

There are 3 steps in the submission process. You must complete all three steps in one session, otherwise your comments will be lost.

1. Use this Protected Document icon to open a comment box.

2. Type your feedback and then click the"Save Comment" button in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments, go to step 2 by clicking on the “Save and Continue” button at the very bottom of this page.

Important Information

During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity or if you close your browser or go to a different tab/window and try to come back.

To ensure that your comments are received:

  1. DO NOT jump between web pages/applications while logging comments.

  2. DO NOT log comments for more than one document at a time.

  3. DO NOT leave your submission unfinished. If you need to take a break, submit your current set of comments now and return later to make a further submission. You will receive a copy of your comments so that you can see what you have already said.

  4. DO NOT exit from the interface until you have completed all three steps of the submission process.  Simply saving a comment in the comment box does not mean it is submitted and if you exit the system, you will not be able to retrieve it later.

When you finalise your submission in step 3 your comments will be emailed to the Document Author with a copy to you, and to policy@mq.edu.au for record keeping purposes.

Information Classification and Handling Procedure

Section 1 - Purpose

(1) This Procedure specifies the actions required to classify Information that is owned or handled by Macquarie University (the University) and facilitate the application of appropriate security measures in accordance with the Cyber Security Policy.

Scope

(2) This Procedure applies to:

  1. all Information collected, created, stored, or processed by, or for, the University on computer and network resources; and
  2. all individuals who handle Information for the University.
Top of Page

Section 2 - Policy

(3) Refer to the Cyber Security Policy.

Top of Page

Section 3 - Procedures

Responsibilities and Required Actions

Information Handling

(4) Information must be handled in a responsible and appropriate manner. Before collecting, storing or distributing Information, University staff, students and other authorised individuals must:

  1. classify the Information against security classification and privacy classification;
  2. determine the length of time that the Information needs to be retained and how the Information can be securely erased when no longer required;
  3. minimise the Information (fields and records) that is distributed to only that which is required;
  4. engage Macquarie IT to review the compliance of third parties who are required to receive the Information; and
  5. be protected while being transferred in accordance with the Encryption section of the Computer and Network Security Policy.

(5) If Confidential or Highly Sensitive Information is shared with an unauthorised party, exposed in an uncontrolled location, lost, or accidentally received, the following actions must be taken:

  1. immediately notify the relevant manager or supervisor;
  2. log the incident with the IT Service Desk through OneHelp;
  3. do not attempt to investigate, delete or remediate the exposure; and
  4. preserve all relevant records, including emails and logs.

(6) Where an incident involves personal Information, health Information or sensitive personal Information, the Cyber Security team must notify the University Privacy Officer (privacyofficer@mq.edu.au), who will assess the incident under the Data Breach Policy and coordinate mandatory notification obligations.

(7) For urgent cyber security incidents, the Chief Information Security Officer (cyber@mq.edu.au) must be contacted so that the Cyber Team can manage the incident in accordance with the University's cyber security incident response plan.

Information Classification

(8) The minimum-security standards for protecting University Information on computer systems and networks are established in the Computer and Network Security Policy.

(9) Information takes the highest classification of any element it contains. Combining, aggregating or extracting Information into a new record or dataset does not lower its classification.

(10) The security classification and, where applicable, privacy classification must be recorded on the Information, its container or metadata when created or collected. Email markings must reflect the highest classification of the subject, body and attachments.

(11) Information may be reclassified to a lower security classification only following a documented decision by the Information owner, in consultation with Macquarie IT Cyber Security. Higher-classified copies must be securely deleted or destroyed before the reclassification takes effect.

(12) Any internal correspondence that has no labelling or Information classification applied will be considered 'MQU - General Internal’.

Table 1: Security Classification

Classification

Description

Examples

Handling and protection

 
Public
 
Information that has been formally authorised for release into the public domain by the Information owner or an authorised delegate.
 
Marketing material
Published research Information Student course Information Academic calendar
 
May be distributed without restriction.
Internal
 
Information that poses a moderate risk to the University if exposed in an unauthorised manner or damaged.
Teaching materials
General intellectual property IT operational reports
MQU issued staff and student contact details
Project documentation
Permanently de-identified research data
May be distributed to Macquarie staff using systems and services endorsed for internal use by the CIDO.
This is the default classification level for unclassified Information.
Confidential
Information that poses a significant risk to the University if exposed in an unauthorised manner or damaged.
University premises access records
Unpublished research data Strategy, presentations and documents
Financial records Audit reports Council papers
Mailboxes containing student or staff correspondence
May be distributed to University staff who have a specific and appropriate need to receive the Information.
Information and fields must be limited to only that which is necessary.
May only be processed or stored on systems and services endorsed for internal use by the CIDO.
Highly Sensitive
Information that poses a high regulatory, reputational or commercial risk to the University if damaged or exposed in an unauthorised manner.
 
Information that poses a privacy risk to identifiable person:
Health Information (HI)*
Sensitive Personal Information (SPI)*
 
Datasets, extracts or reports containing the personal Information of multiple individuals
Identifiable digital activity and access records (including Wi-Fi)
Building access records relating to an individual
Passwords, passphrases and private keys
Cloud and system administration account credentials
API keys, tokens and service account credentials
Records containing data with a Privacy Classification of HI or SPI:
Student academic and administration records
Job applicant, employment and staff administration records
Patient, client and clinical records
Identifiable research data relating to individuals
 
*See the Privacy Classification table for HI and SPI examples
Seek guidance from Macquarie IT Cyber Security before sharing data internally or externally.
 
Additional security measures are required for the capturing, processing, and storing of highly sensitive Information as indicated below.
 
 

Table 2: Privacy Classification

Classification

Description

Examples (not exhaustive)

Handling and Protection*

N/A 
Information is not related to a reasonably identifiable person. 
De-identified statistics
N/A 
Personal Information (PI) 
Information or an opinion about a reasonably identifiable person. 
Full name 
MQU issued Work & Student email address 
Job title, position and work unit 
Work phone number 
Macquarie University ID or student ID 
Work or campus address 
Login name or username 
Screen name or nickname 
Staff directory or profile entry 
Minimum Security Classification is Internal
Health Information (HI) 
Health status and care Information that relates to a reasonably identifiable person. 
Patient or client medical records 
Diagnoses, illness and disability 
Test and laboratory results 
Scan images 
Prescriptions and medical history 
Mental and physical health conditions 
Appointments and referrals 
Health cover and billing for a health service 
Genetic Information 
Health opinions about an individual 
Identifiable clinical research data 
Patient identifiers 
Minimum Security Classification is Highly Sensitive
Sensitive Personal Information (SPI)
SPI Includes Sensitive Information and Critical Personal Information*.
SPI includes Sensitive Information and Critical Personal Information. 
 
Sensitive Information is an individual’s ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities. 
Ethnic/racial origin, political opinions, religious/philosophical beliefs, trade union membership, sexual activities. 
Additional security measures are required for the processing and storing HI and SPI. 
 
Data controls for Highly Sensitive plus: 
Control access and apply Read Auditing inside System of Record 
Data Masking outside System of Record
 
* This is not exhaustive but indicative of the level of protection required 
 
Critical Personal Information (CPI)* is Information that may present a high privacy risk outcome to an individual: 
Locating or contacting an individual in their private capacity  
Identity theft or impersonation 
Authentication or verification (excluding work email and MQ ID) 
Behavioural tracking 
Financial fraud 
Law enforcement, or vulnerability (children, DV victims) 
 
*As defined by MQU 
 
Residential address 
Date of birth 
Driver licence number 
Tax file number 
Bank account number 
Financial transactions 
Passport number 
Visa number 
Emergency contact details 
Behavioural tracking (attendance, location) 
Credit card numbers 
Biometrics (face image, fingerprints, signature) 
Government or third-party ID numbers (excluding MQ and student ID) 
Vehicle registration number 
Personal (non-work) email address 
Personal (non-work) phone number 
Authentication credentials and identity verification answers 
Details identifying a person at risk (children, DV, law enforcement matters) 

Additional Requirements for Handling Highly Sensitive Information

(13) When capturing, processing, storing or otherwise handling highly sensitive Information University staff, students and other authorised individuals are required to request additional security controls on the computer systems and applications that they use. Additional controls may include, but are not limited to:

  1. Multi-Factor Authentication for remote access to University systems and cloud applications;
  2. Multi-Factor Authentication for laptop and mobile device access;
  3. encryption for cloud storage, computer disks and mobile devices; and
  4. data backup facility that provides secure transport and storage.

(14) Cardholder data (including credit and debit card numbers) must be handled in accordance with the Payment Card Industry Data Security Standard (PCI DSS) and must not be captured, stored, processed or transmitted on any University system, application or channel that has not been approved for that purpose by Macquarie IT Cyber Security.

(15) The above controls are provided by Central IT and may be different depending on the systems in use. To request the above controls please contact the IT Service Desk through OneHelp.

Top of Page

Section 4 - Guidelines

(16) Nil.

Top of Page

Section 5 - Definitions

(17) The following definitions apply for the purpose of this Procedure:

  1. Data Masking means obscuring, truncating, tokenising or redacting data elements so the Information cannot be attributed to an identifiable individual by any one directly accessing the data. This is put in place to stop reading of data when it is being stored outside the System of Record which controls and audits access.
  2. Information means any information in either physical or electronic format that is generated, created, stored, purchased or received during the conduct of University operations.
  3. Multi-Factor Authentication is authentication using two or more different authentication factors, being: something the user knows (such as a password or passphrase); something the user has (such as a security key, smart card, passkey, smartphone or one-time password token); or something the user is (such as a fingerprint or facial geometry).
  4. Read Auditing means logging each access to, or viewing of, a record, attributable to an identified user account, and retaining those logs for review.
  5. System of Record means the University system, application or repository formally approved to be the authoritative store for Information of that classification.