VIC.GOV.AU | Policy and Advisory Library

School operations

Information Security

1. Information security risk management

All school staff must take reasonable steps to ensure that any school information they create, handle or have responsibility for is securely stored and protected from loss, unauthorised access, modification, inaccessibility, disclosure or destruction. This includes when information is being transmitted, transported, migrated or converted.

Schools must consider information security risks as part of standard risk management practices. While security incidents cannot be eliminated, risks can be significantly reduced through informed decision making and effective operating controls.

When assessing information security risks, schools must:

In addition, schools must include the results of the school risk register in the school’s emergency and critical incident response plan following the Emergency and Critical Incident Management Planning policy.

Includes information on steps all school staff must take to ensure that any school information they create, handle or have responsibility for is securely stored and protected from loss

Reviewed 18 June 2025

Was this page helpful?