Skip links and keyboard navigation

Use of ICT services, facilities and devices policy (IS38)

Document type:
Policy
Version:
Final v2.0.6
Status:
CurrentMandated
Owner:
QGCDG
Effective:
December 2015–current
Security classification:
OFFICIAL-Public
Category:
Employee experience

Purpose

A range of government provided information and communication technology (ICT) services, facilities and devices are available to employees in order to fulfil their functions. The use and management of these resources imposes an obligation of responsibility and accountability. The purpose of this policy is to ensure the implementation of consistent policies and practices in the management of employee use of ICT services, facilities and devices. This policy should be read in conjunction with:

Policy statement

The use of government provided ICT services, facilities and devices is for officially approved purposes. Limited personal use of these resources may be made available to employees on a basis approved by the department's chief executive officer. All use and access must be able to withstand public scrutiny and/or disclosure.

Policy benefits

The implementation of this policy will:

  • establish an accountable, open and transparent use of government resources, minimising instances of misuse
  • reduce risks associated with public scrutiny in the use of government resources
  • support an open, fair and transparent disciplinary process where rules are clearly articulated
  • reduce departmental vulnerability to threats posed by inappropriate use which can potentially lead to legal liability.

Scope

Personal ICT services, facilities and devices are out of scope, however the access to and use of government provided ICT services, facilities and devices by these (e.g. accessing government email, Wi-Fi via a personal device) is in scope. Personal ICT services, facilities and devices which are authorised to be used for work purposes should be included in departmental Bring your own device (BYOD) policies.

Limited personal and professional use of social media is within the scope of this policy. Official use of social media is outside the scope of this policy and is addressed in the Principles for the official use of social media networks and emerging social media.

Applicability

This policy applies to all Queensland Government departments (as defined by the Public Sector Act 2022). This policy also applies to accountable officers (not already in scope of the Public Sector Act 2022) and to statutory bodies under the Financial and Performance Management Standard 2019 in the context of internal controls, financial information management systems and risk management. Please see How to apply the QGEA for further information.

Policy requirements

Policy Requirement 1: Departments must implement policies addressing employee use and monitoring of ICT services, facilities and devices

Departments must develop and implement policies addressing employee use and monitoring of ICT services, facilities and devices, including clear definitions, comprehensive examples and permitted levels of authorised and unauthorised use.

Policy Requirement 2: Departments must ensure all employees are aware of, understand and acknowledge their responsibilities and policy obligations when using ICT services, facilities and devices

Departments must ensure that all employees are aware of, understand, acknowledge and have access to the relevant policies on use of government provided ICT services, facilities and devices including their responsibilities.

Advice

The following documents provide advice on implementing this policy:

Issue and review

Issue date: 15 December 2015

This QGEA policy is published within the QGEA which is administered by the Queensland Government Customer and Digital Group. It was developed by the Department of Justice and Attorney-General, the Crime and Misconduct Commission, Crown Law, Public Sector Commission and Queensland Government Chief Information Office and approved by the Queensland Government Chief Information Officer.

Implementation

This policy comes into effect from the issue date.