Security Classification and Sensitive Information Procedure
v1.3
Purpose. This procedure explains how staff classify, mark, store, transmit and dispose of official information under the Victorian Protective Data Security Standards so that sensitive information about people, providers and government decisions is protected.
1.Classifying information
The originator must assess the harm that would result from unauthorised disclosure and apply the lowest classification that protects it. Most departmental information is Official. Information about identifiable people, complaints, investigations, tender offers and unreleased ministerial advice is Official: Sensitive. Cabinet material and information whose disclosure could cause serious harm is Protected.
2.Marking
The classification must appear in the header and footer of every document and in the subject line of every email that carries classified content. Files in the records system must carry the classification in their metadata. Unmarked documents are treated as Official.
3.Handling and storage
Official: Sensitive and Protected information must be stored in the records system with access limited to the people who need it, printed only when necessary and kept in locked storage when unattended. It must not be sent to personal email, stored on removable media or discussed in public places. Clear desks and locked screens are mandatory in every office.
- Store in the records system with restricted access
- Print only when necessary and collect immediately
- Lock away paper copies when unattended
- Encrypt Protected information before it leaves the network
- Use the secure destruction bins for disposal
4.Transmitting
Official: Sensitive information can be emailed within government networks with the marking in the subject line. Sending it outside government requires an approved secure channel or password protection with the password sent separately. Protected information must not be emailed outside the department without the approval of the Manager, Corporate Services.
5.Security incidents
Lost devices, misdirected emails, unauthorised access and suspected compromise are security incidents and must be reported to the manager and the security adviser on the day, then recorded in the risk register. The security adviser will assess, contain and, where personal information is involved, apply the data breach process in the privacy policy.
6.Disposal
Classified paper must be placed in the secure destruction bins. Electronic records are disposed of only under the retention and disposal authority through the records manager. Devices must be sanitised by the information technology team before reuse or disposal.