Security objectives and measurement
Turns the policy's five promises into measurable objectives: what is measured, the target, the source, the cadence, and a permanent append-only measurement log.
What this policy commits us to
- No cross-tenant access: 100% of daily database-security sweep runs must pass all isolation checks — any failure is an incident, not a metric dip.
- Zero identifiable-record access by a First Six actor without an active break-glass grant; any non-zero count is a reportable incident.
- Crisis pathway availability of at least 99.5% monthly, and every all-channels-failed event must be visible: fail loudly, never silently.
- Every access to an individual student's record is logged, reconciled quarterly.
- Data at rest 100% in the Australian region, with zero undisclosed cross-border flows.
Controls mapped to this policy
Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.
Standards mappings
Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.
ISO/IEC 27001:2022InfoSec complianceSelf-assessed
A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.
- 9.1Monitoring, measurement, analysis, evaluation
- 6.2Information security objectives
Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law
The primary legal regime. APP 8 drives the residency objective and every disclosed cross-border flow, APP 11 drives retention and erasure, and the Notifiable Data Breaches scheme's assessment clock is built into the incident runbook with OAIC contacts documented. The privacy policy, terms, and DPA template are counsel-reviewed and approved.
- APP 8Cross-border disclosure of personal information
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.