Information Security Management System (ISMS) Outline
1. Scope and Objectives
Scope:
To protect the confidentiality, integrity, and availability of information within Living School’s information and communication systems, including:
- Google Education Plus
- Google Classroom
- Classter Student Management System (SMS)
- WordPress sites (Living School website, admin portal, and Living Academy)
- Social media platforms (Facebook private/public, Instagram)
- Toddle Learning Management System (LMS)
- WhatsApp groups
Objectives:
- Ensure compliance with NSW and Australian legal requirements.
- Mitigate risks related to data breaches, unauthorised access, and system failures.
- Establish clear accountability for data security management.
- Create robust incident response protocols.
2. Governance and Leadership
Responsibilities:
- Conductor (Principal): Oversees overall security governance and compliance.
- IT Security Manager: Implements, monitors, and audits ISMS policies.
- Data Protection Officer (DPO): Ensures compliance with data protection laws.
Policy Approval: Security policies must be reviewed annually by the school leadership team and approved by the Guardians of Purpose annually.
3. Risk Management
Risk Assessment Process:
- Identify threats (e.g., phishing, ransomware, unauthorised access).
- Evaluate risks (likelihood and impact).
- Mitigate risks (implement controls).
- Monitor and review risks regularly.
Key Risks:
- Google Education Plus and Classroom: Unauthorised sharing of sensitive student data.
- Classter SMS: Data integrity risks and access control weaknesses.
- WordPress Sites: Vulnerabilities from plugins and admin panel breaches.
- Social Media: Privacy breaches via inadvertent sharing.
- Toddle: Cloud data exposure risks.
4. Asset Management
- Asset Inventory: Maintain a detailed inventory of hardware, software, and data assets.
- Classification: Classify data into categories (e.g., Public, Internal, Confidential).
- Ownership: Assign ownership for all assets to specific personnel.
5. Access Control
User Roles and Permissions:
- Implement least privilege principles across all systems.
- Set strict role-based access controls (RBAC) in Google Workspace, Classter, and Toddle.
Authentication:
- Enforce two-factor authentication (2FA) for:
- Google Workspace
- Classter SMS
- WordPress admin portal
- Use strong password policies.
Periodic Reviews:
- Conduct quarterly reviews of user accounts and permissions.
- Revoke access promptly when staff/students leave the school.
6. Data Security
Data Encryption:
- Enable encryption for data at rest and in transit across all systems.
Backups:
- Schedule automated daily backups for Classter SMS, WordPress sites, and Toddle.
- Store backups in secure off-site/cloud locations.
- Google Drive and Toddle:
- Restrict sharing permissions for sensitive files (e.g., restrict “Anyone with the link” options).
WordPress Sites:
- Use SSL/TLS certificates to encrypt all communications.
- Regularly update the Fluent ecosystem plugins to mitigate vulnerabilities.
7. Incident Response Plan
Preparation:
- Develop an Incident Response Team (IRT) with predefined roles and responsibilities.
- Provide regular training on incident response procedures.
Detection:
Implement monitoring tools for:
- Suspicious logins (Google Workspace, WordPress admin).
- Unusual activity (Classter, Toddle).
Response:
Steps for handling breaches:
- Isolate affected systems.
- Notify relevant stakeholders (Conductor, IT Security Manager, DPO).
- Contain and mitigate threats.
Comply with Notifiable Data Breaches (NDB) scheme for reporting breaches.
Recovery:
- Restore backups to resume operations.
- Review incident reports to prevent recurrence.
8. Training and Awareness
Staff Training:
Provide annual mandatory security training on:
- Phishing and social engineering.
- Secure use of systems (Google Classroom, Classter, Toddle, social media).
- Tailor sessions for different roles (e.g., teachers, administrators).
Student Awareness:
- Conduct workshops on safe online practices.
- Integrate cybersecurity lessons into the curriculum.
9. Monitoring and Auditing
System Monitoring:
- Use audit logs in Google Workspace, Classter, and Toddle to track activities.
- Enable logging plugins for WordPress sites.
Regular Audits:
- Perform bi-annual security audits of all systems.
- Engage external auditors for impartial assessments.
Social Media Monitoring:
- Monitor posts on Facebook and Instagram to ensure compliance with privacy policies.
10. Compliance and Documentation
Compliance Requirements:
- Maintain records of compliance with NSW Education Standards Authority (NESA).
- Adhere to the Australian Privacy Principles (APPs) in handling personal information.
Documentation:
Develop and maintain:
- Information Security Policies
- Risk Assessment Reports
- Incident Response Procedures
- Staff and Student Acceptable Use Policies (AUPs)
11. Continuous Improvement
Review Cycle:
- Review ISMS policies annually or after major incidents.
- Update the framework to adapt to evolving threats.
Feedback Mechanism:
- Gather feedback from staff and students on system usability and issues.
Technology Upgrades:
- Regularly assess and upgrade software, hardware, and plugins for security enhancements.