INDUCTION & COMPLIANCE MADE EASY

Security & data protection

Data Safety Policy

How Induct For Work safeguards data and supports its confidentiality, integrity and availability.

This policy applies to Induct For Work employees, casuals and contractors and covers electronic data, paper records and information stored on other media.

Reviewed annually and after significant security incidents

01–02

Purpose and scope

Purpose

The Data Safety Policy of Induct For Work Pty Ltd aims to safeguard all data handled by the company, ensuring confidentiality, integrity and availability. It explains how data is protected against unauthorised access, disclosure, alteration and destruction.

Scope

The policy applies to all employees, casuals and contractors of Induct For Work Pty Ltd. It covers all data managed by the company, including electronic data, paper records and data stored on other media.

Confidentiality Limiting information access to authorised people and systems. Integrity Protecting data against unauthorised alteration or destruction. Availability Maintaining reliable access and recovery when required.
03

Roles and responsibilities

Data Protection Officer

The DPO oversees implementation of and compliance with this policy, leads responses to data breaches and coordinates regular policy reviews and updates.

IT Department

The IT Department is responsible for the technical implementation of security measures, regular security audits and incident response.

Employees, casuals and contractors

All personnel must follow the policy's protocols and report any suspected security incident immediately.

04

Data classification

Data managed by Induct For Work is classified according to its sensitivity and permitted use.

01
Confidential

Personal data, financial information and proprietary business information. Unauthorised disclosure could cause significant harm or a data breach.

02
Internal use

Information intended for internal company use that should not be disclosed publicly.

03
Public

Information that can be shared freely without creating risk for the company.

05.1

Access control and authentication

Induct For Work applies the principle of least privilege. Access is granted only where required for a person's role and work responsibilities.

  • Role-based access Employees receive unique credentials and access only to the information and resources needed to perform their duties.
  • Multi-factor authentication MFA is required when accessing sensitive systems and data, adding another verification step beyond a password.
  • AWS Identity and Access Management AWS IAM is used to manage and control access to AWS resources securely.
05.2–05.6

Technical security controls

Layered controls protect stored information, data in transit, cloud environments and service availability.

Data encryption

Sensitive data stored on AWS is encrypted at rest using AWS Key Management Service. Data in transit is protected with secure TLS/SSL protocols to reduce the risk of interception.

Network security

AWS Security Groups and Network Access Control Lists control inbound and outbound traffic. Virtual Private Clouds isolate and secure cloud environments.

Monitoring and logging

AWS CloudTrail records API activity to support traceability and unusual-activity detection. AWS CloudWatch provides real-time system monitoring and security alerts.

Backup and recovery

Critical data is backed up regularly and stored securely. A disaster recovery plan supports restoration following system failure, data loss or corruption.

Patch management

Systems, applications and software are updated with current security patches. AWS Systems Manager automates patch-management processes and helps reduce exploitable vulnerabilities.

06

Third-party vendor management

Induct For Work conducts security assessments before engaging third-party vendors. These assessments consider whether a vendor's security practices meet Induct For Work requirements.

Contractual protection

Data protection agreements are established to require vendors to handle data in accordance with Induct For Work security standards.

07

Security awareness and training

Employees and contractors receive regular training covering data-security practices, recognition of phishing attempts and appropriate response protocols.

  • Regular training Personnel are instructed on the security protocols relevant to their responsibilities.
  • Phishing simulations Periodic simulations reinforce recognition and response skills.
  • Immediate reporting Suspected incidents must be escalated without delay.
Incident response

A defined process from detection to review.

The incident response plan establishes procedures for identifying, containing and recovering from security incidents and data breaches.

  1. 01
    Detection

    Identify potential incidents through monitoring tools and reports.

  2. 02
    Response

    Contain the incident and mitigate its immediate impact.

  3. 03
    Recovery

    Restore affected systems and information to normal operation.

  4. 04
    Communication

    Inform relevant stakeholders and authorities when required.

  5. 05
    Documentation

    Record the incident, response and lessons for future improvement.

09

Compliance and audits

Regular security audits evaluate compliance with this policy and relevant legal requirements. Audits help identify vulnerabilities, control gaps and opportunities for improvement.

The policy supports compliance with applicable requirements, including the Australian Privacy Act 1988 and the General Data Protection Regulation.

10

Policy review and continuous improvement

The DPO reviews this policy annually and after significant security incidents. Lessons learned are incorporated into security measures so the policy remains effective and aligned with evolving threats and regulatory requirements.

Through AWS security services, defined internal controls and ongoing improvement, Induct For Work works to maintain the confidentiality, integrity and availability of the data it manages.

Policy enquiries: dpo@inductforwork.com.au

Independent assessment
96% SecurityScorecard report

Independent security rating.

The published SecurityScorecard report provides an independent view of the organisation's security posture. The existing report is retained here as supporting evidence.

Independent SecurityScorecard summary report for Induct For Work