Security and Protection

Information Security Management System (ISMS) Outline

1. Scope and Objectives

Scope:

To protect the confidentiality, integrity, and availability of information within Living School’s information and communication systems, including:

  •       Google Education Plus
  •       Google Classroom
  •       Classter Student Management System (SMS)
  •       WordPress sites (Living School website, admin portal, and Living Academy)
  •       Social media platforms (Facebook private/public, Instagram)
  •       Toddle Learning Management System (LMS)
  •       WhatsApp groups

Objectives:

  •       Ensure compliance with NSW and Australian legal requirements.
  •       Mitigate risks related to data breaches, unauthorised access, and system failures.
  •       Establish clear accountability for data security management.
  •       Create robust incident response protocols.

 

2. Governance and Leadership

Responsibilities:

  • Conductor (Principal): Oversees overall security governance and compliance.
  • IT Security Manager: Implements, monitors, and audits ISMS policies.
  • Data Protection Officer (DPO): Ensures compliance with data protection laws.

Policy Approval: Security policies must be reviewed annually by the school leadership team and approved by the Guardians of Purpose annually.

 

3. Risk Management

Risk Assessment Process:

  •       Identify threats (e.g., phishing, ransomware, unauthorised access).
  •       Evaluate risks (likelihood and impact).
  •       Mitigate risks (implement controls).
  •       Monitor and review risks regularly.

Key Risks:

  •       Google Education Plus and Classroom: Unauthorised sharing of sensitive student data.
  •       Classter SMS: Data integrity risks and access control weaknesses.
  •       WordPress Sites: Vulnerabilities from plugins and admin panel breaches.
  •       Social Media: Privacy breaches via inadvertent sharing.
  •       Toddle: Cloud data exposure risks.

 

4. Asset Management

  •       Asset Inventory: Maintain a detailed inventory of hardware, software, and data assets.
  •       Classification: Classify data into categories (e.g., Public, Internal, Confidential).
  •       Ownership: Assign ownership for all assets to specific personnel.

 

5. Access Control

User Roles and Permissions:

  •       Implement least privilege principles across all systems.
  •       Set strict role-based access controls (RBAC) in Google Workspace, Classter, and Toddle.

Authentication:

  •       Enforce two-factor authentication (2FA) for:
  •       Google Workspace
  •       Classter SMS
  •       WordPress admin portal
  •       Use strong password policies.

Periodic Reviews:

  •       Conduct quarterly reviews of user accounts and permissions.
  •       Revoke access promptly when staff/students leave the school.

 

6. Data Security

Data Encryption:

  •       Enable encryption for data at rest and in transit across all systems.

Backups:

  •       Schedule automated daily backups for Classter SMS, WordPress sites, and Toddle.
  •       Store backups in secure off-site/cloud locations.
  •       Google Drive and Toddle:
  •       Restrict sharing permissions for sensitive files (e.g., restrict “Anyone with the link” options).

WordPress Sites:

  •       Use SSL/TLS certificates to encrypt all communications.
  •       Regularly update the Fluent ecosystem plugins to mitigate vulnerabilities.

 

7. Incident Response Plan

Preparation:

  •       Develop an Incident Response Team (IRT) with predefined roles and responsibilities.
  •       Provide regular training on incident response procedures.

Detection:

Implement monitoring tools for:

  •       Suspicious logins (Google Workspace, WordPress admin).
  •       Unusual activity (Classter, Toddle).

Response:

Steps for handling breaches:

  1.     Isolate affected systems.
  2.     Notify relevant stakeholders (Conductor, IT Security Manager, DPO).
  3.     Contain and mitigate threats.

Comply with Notifiable Data Breaches (NDB) scheme for reporting breaches.

Recovery:

  •       Restore backups to resume operations.
  •       Review incident reports to prevent recurrence.

 

8. Training and Awareness

Staff Training:

Provide annual mandatory security training on:

  •       Phishing and social engineering.
  •       Secure use of systems (Google Classroom, Classter, Toddle, social media).
  •       Tailor sessions for different roles (e.g., teachers, administrators).

Student Awareness:

  •       Conduct workshops on safe online practices.
  •       Integrate cybersecurity lessons into the curriculum.

 

9. Monitoring and Auditing

System Monitoring:

  •       Use audit logs in Google Workspace, Classter, and Toddle to track activities.
  •       Enable logging plugins for WordPress sites.

Regular Audits:

  •       Perform bi-annual security audits of all systems.
  •       Engage external auditors for impartial assessments.

Social Media Monitoring:

  •       Monitor posts on Facebook and Instagram to ensure compliance with privacy policies.

 

10. Compliance and Documentation

Compliance Requirements:

  •       Maintain records of compliance with NSW Education Standards Authority (NESA).
  •       Adhere to the Australian Privacy Principles (APPs) in handling personal information.

Documentation:

Develop and maintain:

  •       Information Security Policies
  •       Risk Assessment Reports
  •       Incident Response Procedures
  •       Staff and Student Acceptable Use Policies (AUPs)

 

11. Continuous Improvement

Review Cycle:

  •       Review ISMS policies annually or after major incidents.
  •       Update the framework to adapt to evolving threats.

Feedback Mechanism:

  •       Gather feedback from staff and students on system usability and issues.

Technology Upgrades:

  • Regularly assess and upgrade software, hardware, and plugins for security enhancements.
Version history: 01/02/2025
How easy is this information to understand