Simulated workplaceCAQA Department of Community Programs is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
PSPCAQA Department of Community ProgramsSimulated workplace
Back to library
CAQA Department of Community Programs · Simulated workplace

Security Classification and Sensitive Information Procedure

ProcedureControlled document
DCP-PRO-005
v1.3
Document ownerManager, Corporate Services
Version1.3
Approved28 May 2026
Next review28 May 2027
StatusCurrent

Purpose. This procedure explains how staff classify, mark, store, transmit and dispose of official information under the Victorian Protective Data Security Standards so that sensitive information about people, providers and government decisions is protected.

1.Classifying information

The originator must assess the harm that would result from unauthorised disclosure and apply the lowest classification that protects it. Most departmental information is Official. Information about identifiable people, complaints, investigations, tender offers and unreleased ministerial advice is Official: Sensitive. Cabinet material and information whose disclosure could cause serious harm is Protected.

2.Marking

The classification must appear in the header and footer of every document and in the subject line of every email that carries classified content. Files in the records system must carry the classification in their metadata. Unmarked documents are treated as Official.

3.Handling and storage

Official: Sensitive and Protected information must be stored in the records system with access limited to the people who need it, printed only when necessary and kept in locked storage when unattended. It must not be sent to personal email, stored on removable media or discussed in public places. Clear desks and locked screens are mandatory in every office.

  • Store in the records system with restricted access
  • Print only when necessary and collect immediately
  • Lock away paper copies when unattended
  • Encrypt Protected information before it leaves the network
  • Use the secure destruction bins for disposal

4.Transmitting

Official: Sensitive information can be emailed within government networks with the marking in the subject line. Sending it outside government requires an approved secure channel or password protection with the password sent separately. Protected information must not be emailed outside the department without the approval of the Manager, Corporate Services.

5.Security incidents

Lost devices, misdirected emails, unauthorised access and suspected compromise are security incidents and must be reported to the manager and the security adviser on the day, then recorded in the risk register. The security adviser will assess, contain and, where personal information is involved, apply the data breach process in the privacy policy.

6.Disposal

Classified paper must be placed in the secure destruction bins. Electronic records are disposed of only under the retention and disposal authority through the records manager. Devices must be sanitised by the information technology team before reuse or disposal.

DCP-PRO-005 v1.3 · CAQA Department of Community ProgramsUncontrolled when printed. Simulated document created by CAQA for training and assessment.