Skip to content

Information Security Policy

Field Value
Reference POL-002
Type Policy
Version 1.00
Status Approved
Owner Technical Lead
Approver Board
Approval Record
Effective Date 2026-08-05
Next Review 2027-08-05
Review Requirements As defined in STD-001
Classification Internal

Purpose

This policy defines BRSA's commitment to protecting the confidentiality, integrity and availability of its information, systems and digital services.

Scope

This policy applies to:

  • All Board members and volunteers.
  • All BRSA-owned information.
  • All systems, services and devices used to process BRSA information.
  • Third-party services used to support BRSA operations.

Policy

BRSA shall:

  • Protect information appropriate to its sensitivity and value.
  • Grant access only where there is a legitimate organisational need.
  • Apply the principle of least privilege wherever practical.
  • Use strong authentication for systems containing sensitive information.
  • Maintain supported software and apply security updates within an appropriate timeframe.
  • Protect personal data in accordance with the Data Protection Policy.
  • Maintain appropriate backup arrangements for critical information and services.
  • Record and investigate suspected security incidents.
  • Remove access when individuals no longer require it.
  • Periodically review access to systems holding organisational or personal information.

Roles and Responsibilities

Board

The Board is responsible for:

  • approving this policy;
  • ensuring appropriate governance arrangements exist; and
  • supporting information security across the organisation.

Technical Lead

The Technical Lead is responsible for:

  • implementing appropriate technical security controls;
  • managing access to BRSA systems;
  • maintaining secure infrastructure;
  • responding to technical security incidents; and
  • advising the Board on information security risks.

Volunteers

All volunteers are responsible for:

  • protecting BRSA information;
  • using systems responsibly;
  • safeguarding authentication credentials; and
  • promptly reporting suspected security incidents or weaknesses.

Compliance

Failure to comply with this policy may result in access being restricted or withdrawn and may lead to further action by the Board where appropriate.

Exceptions

Any exception to this policy shall be approved by the Board and documented together with the associated risks.

  • POL-001 Data Protection Policy
  • PROC-001 Document Lifecycle
  • REG-002 Technology and Service Register

Review Requirements

This policy shall be reviewed in accordance with STD-001 or following any significant security incident, major infrastructure change or material change in legal or regulatory requirements.

Change History

Version Date Author Change
0.10 2026-07-23 Technical Lead Initial draft
0.50 2026-07-24 DC Version -> 0.50; Status -> Review
1.00 2026-08-05 DC Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05