INFORMATION SECURITY POLICY
- Home
- INFORMATION SECURITY POLICY
1. Intent and Scope
- This information security policy (policy) provides the basis of information security management within JL & Partners Pty Ltd ACN 642 106 910(Company).
- Effective protection of business information creates a competitive advantage, both in the ability to preserve the reputation of the Company and in reducing the risk of the occurrence of negative events and incidents.
- This policy aims to balance the following priorities:
- Meeting the Company’s legislative
- Keeping data and documents confidential as required by the Company and its
- Ensuring the integrity of the Company’s data and IT
- Upholding the Company’s reputation as a trusted recipient of
- Maintaining storage and back-up systems that meet the needs of the Company and its employees, contractors, volunteers, vendors and anyone else who may have any type of access to the Company’s systems, software, hardware, data and/or documents (collectively referred to as the Participants).
2. Responsibilities
- This policy applies to all Participants who are given access to the Company’s systems, software, hardware, data and/or documents.
- All Participants are responsible for protecting business information and systems. Where there is any doubt about the security of any action, the Participants should take a cautious approach and avoid any potential risks.
- The Information Security Officer is responsible for implementing this
3. Authorisation and Access
Managers should exercise caution when:
- Sharing information and documents with the
- Authorising the Participants to enter and control information
- Giving the Participants access to information
As a general rule, managers should follow a need-to-know basis. If there is any uncertainty regarding how information and documents should be shared, contact the Information Security Officer at sheng@jlandpartners.com.
4. Password and Authentication Requirements
- To avoid the Participants’ work account passwords being compromised, these best practices are advised for setting up passwords:
- Passwords set up by an administrator must be uniquely and randomly generated, then immediately changed by the user.
- Use at least 8 characters (must contain capital and lower-case letters, numbers and symbols).
- Do not write down password and leave it
- Do not exchange credentials when not requested or approved by
- Change passwords when there is any possibility that an existing password may have been
- We encourage the use of a password management tool, whether integrated into a mobile app or an internet browser.
- Multifactor authentication tools should be used where
5. Email Security
Emails can contain malicious content and malware. In order to reduce harm, the Participants should employ the following strategies:
- Do not open attachments or click any links where content is not well
- Check the email addresses and names of
- Search for
- Block junk, spam and scam
- Avoid emails that contain common scam subject lines such as prizes, products and money
- Where an email requests financial payment, confirmation of password, or prompts to login to a Company system, extreme care should be taken to ensure that it is genuine, such as by calling the sender.
If the Participant is not sure that an email, or any type of data is safe, the Participant should contact the Information Security Officer at security@connorhunter.com.au.
6. Transferring Data
Data transfer is a common cause of cybercrime. The Participants should follow these best practices when transferring data:
- Avoid transferring personal information such as customer data and employee information (this includes anything that can or may identify an individual including first name, last name, age, address and email address).
- Adhere to the relevant personal information legislation including the Australian Privacy
- Data should only be shared over authorised
- If applicable, destroy any sensitive data when it is no longer
7. Working Remotely
When working remotely, all the information security policies and procedures must be followed.
8. Company Systems
- When accessing the internet from any system set up by the Company:
- Participants must use the standard process and not bypass any security
- Reasonable care must be taken in relation when downloading documents and transmitting data over the internet. Access only trusted websites.
- When accessing accounts on Company systems:
- User accounts on work systems are only to be used for the business purposes of the Company and not to be used for personal activities.
- Participants are responsible for protecting all confidential information used and/or stored on their accounts. This includes their user logins and passwords. Participants are prohibited from making unauthorised copies of such confidential information and/or distributing it to unauthorised persons outside of the
- Participants must not purposely engage in any activity with the intent to: harass other users; degrade the performance of the system; divert system resources to their own use; or gain access to Company systems for which they do not have
9. General Security Requirements
- Participants must not install unauthorised software. The Company may at any time introduce a whitelist of approved/trusted If this occurs then only these programs may be used by the Participants.
- Participants should stay up-to-date with any other Company-wide recommendations, such as recommended browser settings.
- Participants should perform daily backups of important new/changed data, software and configuration settings.
- Participants must not attempt to turn off or circumvent any security
- Participants must report any security breaches, suspicious activities or issues that may cause a cyber security breach to the Information Security Officer immediately, and await their instructions regarding the appropriate response to the breach.
10. Other Companies Policies
This Policy must be followed in conjunction with the Company’s Privacy Policy, Workplace Health and Safety Policy, Code of Conduct, Acceptable Use Policy, Data Breach Response Policy, Client Confidentiality Policy, which can be accessed All policies are accessible on the firm’s internal employee portal at https://intranet.connorhunter.com.au/policies or by contacting the Practice Manager at the Wynnum or Cleveland office.
11. Training
All Participants must maintain working knowledge of basic information security protocols. All new Participants will be given training on information security.
12. Disciplinary Action
If this policy is breached, one or more of the following disciplinary actions will take place:
- Incidents will be assessed on a case-by-case
- In case of breaches that are intentional or repeated or cases that cause direct harm to the Company, Participants may face serious disciplinary action, including termination of your employment, engagement or services.
- Subject to the gravity of the breach, formal warnings may be issued to the offending
13. Review
The Company will periodically review this policy and update as required to ensure the continued security of the Company. It is important for those to whom this policy applies to stay up-to-date with changes to this policy, as this is a rapidly-changing area of technology.