Information Security Policy¶
| Field | Value |
|---|---|
| Reference | POL-002 |
| Type | Policy |
| Version | 1.00 |
| Status | Approved |
| Owner | Technical Lead |
| Approver | Board |
| Approval Record | |
| Effective Date | 2026-08-05 |
| Next Review | 2027-08-05 |
| Review Requirements | As defined in STD-001 |
| Classification | Internal |
Purpose¶
This policy defines BRSA's commitment to protecting the confidentiality, integrity and availability of its information, systems and digital services.
Scope¶
This policy applies to:
- All Board members and volunteers.
- All BRSA-owned information.
- All systems, services and devices used to process BRSA information.
- Third-party services used to support BRSA operations.
Policy¶
BRSA shall:
- Protect information appropriate to its sensitivity and value.
- Grant access only where there is a legitimate organisational need.
- Apply the principle of least privilege wherever practical.
- Use strong authentication for systems containing sensitive information.
- Maintain supported software and apply security updates within an appropriate timeframe.
- Protect personal data in accordance with the Data Protection Policy.
- Maintain appropriate backup arrangements for critical information and services.
- Record and investigate suspected security incidents.
- Remove access when individuals no longer require it.
- Periodically review access to systems holding organisational or personal information.
Roles and Responsibilities¶
Board¶
The Board is responsible for:
- approving this policy;
- ensuring appropriate governance arrangements exist; and
- supporting information security across the organisation.
Technical Lead¶
The Technical Lead is responsible for:
- implementing appropriate technical security controls;
- managing access to BRSA systems;
- maintaining secure infrastructure;
- responding to technical security incidents; and
- advising the Board on information security risks.
Volunteers¶
All volunteers are responsible for:
- protecting BRSA information;
- using systems responsibly;
- safeguarding authentication credentials; and
- promptly reporting suspected security incidents or weaknesses.
Compliance¶
Failure to comply with this policy may result in access being restricted or withdrawn and may lead to further action by the Board where appropriate.
Exceptions¶
Any exception to this policy shall be approved by the Board and documented together with the associated risks.
Related Documents¶
- POL-001 Data Protection Policy
- PROC-001 Document Lifecycle
- REG-002 Technology and Service Register
Review Requirements¶
This policy shall be reviewed in accordance with STD-001 or following any significant security incident, major infrastructure change or material change in legal or regulatory requirements.
Change History¶
| Version | Date | Author | Change |
|---|---|---|---|
| 0.10 | 2026-07-23 | Technical Lead | Initial draft |
| 0.50 | 2026-07-24 | DC | Version -> 0.50; Status -> Review |
| 1.00 | 2026-08-05 | DC | Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |