Protective Security Policy Framework update

The Protective Security Policy Framework has now superseded the Protective Security Manual (R.I.P PSM)
The PSPF applies to Government agencies and any organisations working on behalf of, or handling Australian Government information and assets. This may include other governments, and contract service or goods providers.

The various components are available http://www.ag.gov.au/www/agd/agd.nsf/Page/Protective_Security_Policy_Framework
The information security policy and Australian Government information security management protocol and guidelines (including the classification system)
 are worth reading closely, particularly as those classifications we have used and loved for many years have changed – no more ‘xx-in-confidence’ for one!

The guidance from AGIMO about applying the classifications in email provides a fairly straightforward explanation which you can use in implementing in an EDRMS - pages 9, 10 and 11
http://www.finance.gov.au/e-government/security-and-authentication/docs/Email_Protective_Marking_Standard_2011_1.pdf

The PSPF also has 33 mandatory elements which must be reported against to the Minister so well worth looking closely and seeing where recordkeeping and information management are covered or affected and how you can use this to get greater resources, profile or penetration of RK and EDRMS in the agency - best to think about it and be proactive because otherwise your Security area might start dictating how RIM should be .....
Implementation is to be complete by mid 2013 and the first report later that year. Read the Attorney's speech for a good overview (though lacking a reference to recordkeeping sadly)
http://www.attorneygeneral.gov.au/www/ministers/mcclelland.nsf/Page/Speeches_2011_ThirdQuarter_26July2011-SecurityinGovernmentConference2011

You need to be a member of Archives Live to add comments!

Join Archives Live

Email me when people reply –