Security approach
The Board applies administrative and technical safeguards appropriate to the services and information under its control.
Data protection
Reasonable measures are used to protect information against unauthorised access, disclosure, alteration, loss and misuse. Protected connections are used where supported by the relevant service.
Access control
Access to administrative systems and non-public records is restricted according to authorised duties. Accounts, roles and activity records may be used to support accountability.
System monitoring
Security events, access attempts and service availability may be monitored to detect misuse, investigate incidents and maintain the reliability of online services.
User responsibilities
Users should protect account credentials, use current software, verify website addresses and avoid sharing confidential information through unapproved channels.
Prohibited activity
Unauthorised access, interference, automated abuse, malicious uploads, credential attacks and attempts to bypass security controls are prohibited and may be referred to the appropriate authority.
Reporting a security issue
Reports should include the affected page or service, the time observed and a clear description. Sensitive technical details should be sent privately rather than posted publicly.
No internet service can be guaranteed to be completely secure. The Board reviews safeguards and responds to identified risks according to operational priorities.
