Skip to content
Reviewed Jul 2026Knowledge base

Security objectives and measurement

Adherence evidenced by 2 mapped controls

Turns the policy's five promises into measurable objectives: what is measured, the target, the source, the cadence, and a permanent append-only measurement log.

Group
Governance
Owner
Founder
Last reviewed
26 July 2026

Request the full policy

What this policy commits us to

  • No cross-tenant access: 100% of daily database-security sweep runs must pass all isolation checks — any failure is an incident, not a metric dip.
  • Zero identifiable-record access by a First Six actor without an active break-glass grant; any non-zero count is a reportable incident.
  • Crisis pathway availability of at least 99.5% monthly, and every all-channels-failed event must be visible: fail loudly, never silently.
  • Every access to an individual student's record is logged, reconciled quarterly.
  • Data at rest 100% in the Australian region, with zero undisclosed cross-border flows.

Controls mapped to this policy

Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.

Standards mappings

Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.

ISO/IEC 27001:2022InfoSec complianceSelf-assessed

A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.

  • 9.1Monitoring, measurement, analysis, evaluation
  • 6.2Information security objectives

Everything mapped to this standard

Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law

The primary legal regime. APP 8 drives the residency objective and every disclosed cross-border flow, APP 11 drives retention and erasure, and the Notifiable Data Breaches scheme's assessment clock is built into the incident runbook with OAIC contacts documented. The privacy policy, terms, and DPA template are counsel-reviewed and approved.

  • APP 8Cross-border disclosure of personal information

Everything mapped to this standard

Need the detail behind this page?

Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.