Barrister AI
All legislation
VICRegulation
In force
This is the latest official compilation.Check the official source →
reg 6

Dealing with documents and information received

In force

6 Dealing with documents and information received

(1)

The Public Interest Monitor and IBAC must develop written procedures for dealing with documents and information, including the creation and maintenance of the following—

(a)

an information security policy;

(b)

an access control policy;

(c)

procedures for monitoring access activities;

(d)

procedures for ensuring that documents and information are adequately protected;

(e)

a risk management policy for identifying, analysing and treating security risks to documents and information;

(f)

reporting, escalation and response procedures for information security events or identified weaknesses in information security that may affect documents and information;

(g)

a process of continual monitoring and improvement to mitigate and avoid information security incidents.

(2)

In this regulation—

information security event means an identified occurrence of an information system, service or network state indicating—

(a)

a possible breach of an information security policy; or

(b)

a failure of safeguards; or

(c)

a previously unknown situation that may be relevant to security;

information security incident means a single or a series of information security events that are likely to have compromised the security of information.

Research tools for this sectionPro

The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.

Human Source Management Regulations 2024 s 6 — Dealing with documents and information received (Victoria) — Barrister AI