Skip links and keyboard navigation

Cyber security obligations and better practice

The Information security policy (IS18) is the primary policy for information security in the Queensland Government. It is supported by various frameworks, standards, and guidelines under the Queensland Government Enterprise Architecture (QGEA).

The following cyber security policies, guidelines and standards help Queensland Government entities easily find and navigate available best practice resources, understand their obligations, and improve cyber security. Each of the below resources are divided into three key categories:

  • QGEA cyber security mandatory documents – the core QGEA information and cyber security documents, which are a mandatory requirement under the Information security policy
  • QGEA cyber security better practice – The range of associated non-mandatory documents in the information and cyber security space under the QGEA.
  • Other related documents – Related QGEA documents.  Also includes other relevant and trusted local, national and international better practice resources, that can supplement cyber security advice.

QGEA cyber security mandatory document

Other related documents

  • ISO 27036-1 – Supplier relationships – Part 1: Overview and concepts
  • ISO 27036-2 – Supplier relationships – Part 2: Requirements
  • ISO 27036-3 – Supplier relationships – Part 3: Overview and concepts
  • ISO 27036-4 – Supplier relationships – Part 4: Overview and concepts

Government employees learn how to access ISO standards for Cyber security.

For assistance and guidance in implementing the cyber security policy suite, or to suggest inclusions, please contact cybersecurityunit@qld.gov.au.

To be involved in the cyber security policy review, join the QGEA Reference Group Viva Engage network.