Legal
Information Security Policy.
The policy that sets our information security direction and holds up the Information Security Management System behind it, published in full. The summary is a reading aid; the policy below it is what applies.
- Version 1.3. Built on ISO 27001: 2013, clauses 5.2 and 5.3.
- Owned by the ISMS Committee; incidents go to the Information Security Officer
- Applies to every ComplyFlow business process, including where third-party suppliers are engaged
In Plain English
What the Information Security Policy Says, in Six Cards.
This summary is a reading aid, not the policy. The full text below is what applies, and it takes precedence wherever the two differ.
-
What it is.
The top of the stack. It sets management’s information security direction and is the backbone of the Information Security Management System, which is built on the ISO 27001: 2013 standard.
See Clauses 1, 1.1, and 3
-
Who owns it.
A dedicated ISMS Committee sets the objectives, decides acceptable levels of risk, keeps the policies accurate and reviews the whole system once a year. Every asset has a named owner, and all staff report incidents to the Information Security Officer.
See Clauses 2.4, 2.5, and 2.6
-
The five policies under it.
IT Security, Data Security & Backup, User Access Control, Supplier Security, and Privacy. Each one is named with its own document reference, and the clause lists what that document covers.
See Clauses 5.1.1 to 5.1.5
-
The five procedures.
Secure Development, Incident Management, Business Continuity & Disaster Recovery, the Access Management Manual, and the Employment Procedure. Together they cover encryption, change management, breach response, role-based access, and what happens to access when someone leaves.
See Clauses 6.1.1 to 6.1.5
-
What it was written against.
The Privacy Act 1988, seven state and territory privacy and information Acts, the Health Records Information Privacy Act, the Protective Security Policy Framework, and the two APRA standards CPS 232 and CPG 234.
See Clause 7
-
What breaking it means.
Non-compliance is a disciplinary matter under staff employment contracts and the broader ISMS Policy. A serious breach may end employment.
See Clause 8.1
Information Security Policy
Version 1.3. Built on ISO 27001: 2013, clauses 5.2 and 5.3.
1. Purpose, Scope & Users
The purpose of this policy and manual is to set out the principles, objectives and components of ComplyFlow’s Information Security Policy. The policy sets out management’s information security direction and is the backbone of ComplyFlow’s Information Security Management System (ISMS), which establishes the framework for ongoing management and continuous improvement of our resilience to information security threats.
Users of this document include ComplyFlow employees, users, delivery partners and external parties who are interested in the principles, policies and procedures which underpin our commitment to information security.
1.1 Reference Documents
This policy references:
- ISO 27001: 2013 standard; clauses 5.2, 5.3
- CF-ISO27001-ISMS Scope Document
- CF-ISO27001-List of Legal, Regulatory and Contractual Requirements
2. Principles & Objectives
2.1 Principles
ComplyFlow is committed to preserving the confidentiality, availability and integrity of information and information systems which are central to our company purpose in providing a secure service for clients and users, and as an employer.
ComplyFlow information - whether processed directly by ComplyFlow or managed by third parties - is an important asset that must be protected. Improper use of information resources may result in harm to ComplyFlow and our users, clients and staff.
This commitment to the protection of information assets forms the foundation of our Information Security Management System (ISMS). ComplyFlow Management accepts responsibility for establishing and maintaining the ISMS and ensuring that sufficient resources are allocated to fulfil its objectives. Importantly, ComplyFlow is committed to the continuous improvement of the ISMS in order to safeguard the organisation’s resilience to evolving information security threats.
The core aim of the ISMS is to fulfil ComplyFlow’s commitment to protect the confidentiality, integrity and availability of information assets across the organisation.
2.2 Objectives
Within the context of this broader aim, ComplyFlow has established the following objectives:
- Proactively identify, mitigate, monitor and manage information security vulnerabilities, threats and risks in order to protect ComplyFlow and its assets, information and data.
- Ensure adequate resources are dedicated to the ongoing maintenance and continuous improvement of ComplyFlow’s ISMS.
- Remain compliant with all information security requirements specified by the ISO 27001: 2013 standard, our own policies and all legal, regulatory and contractual obligations.
2.3 Information Security Terminology
The document uses these terms as follows:
- Confidentiality: characteristic of the information by which it is available only to authorised persons or systems.
- Integrity: characteristic of the information by which it is changed only by authorised persons or systems in an allowed way.
- Availability: characteristic of the information by which it can be accessed by authorised persons when it is needed.
- Information Security: preservation of confidentiality, integrity and availability of information.
- Information Security Management System: overall system responsible for planning, implementing, maintaining, reviewing, and improving the information security.
2.4 Roles & Responsibilities
Responsibility for developing, coordinating and continual improvement of the ISMS is distributed across key ComplyFlow personnel in the form of a dedicated ISMS Committee. The responsibilities of the ISMS Committee include:
- Establishing and communicating information security objectives, and ensuring the provision of sufficient resources to achieve these.
- Monitoring changes to information security, deciding acceptable levels of risk and ensuring these updated risks are communicated throughout the business.
- Ensuring procedures and policies are accurate, updated, communicated and complied with.
- Reporting on the performance of the ISMS and ensuring adequate steps are taken to continually improve its operation.
- Ensuring sufficient information security training and awareness is provided to staff, users and key stakeholders.
- Annual review of the operation of the ISMS (Management Review) to ensure it is compliant with the requirements of interested parties and the ISO 27001 standard.
The protection of the integrity, confidentiality and availability of assets is the responsibility of the owner of each asset, stipulated in CF-ISO27001-Inventory of Assets. All staff are responsible for reporting incidents to the Information Security Officer.
2.5 Leadership & Commitment
ComplyFlow’s Management team are committed to the protection of confidential information which is central to providing a secure service to our users and clients, and in safeguarding employee information.
This commitment forms the foundation of our ISMS, and informs Management’s acceptance of their responsibility for establishing and maintaining the ISMS and ensuring that sufficient resources are allocated to the ISMS to fulfil its objectives.
Importantly, in order to ensure the ongoing protection of the confidentiality, integrity and availability of ComplyFlow information assets, our Management Team here expresses their commitment to the continuous improvement of the ISMS.
2.6 Review
The Information Security Officer and Executive Management are responsible for coordinating the reviews for various components of ComplyFlow’s Information Security Management System (including policies, procedures, risk assessments and controls) in order to ensure the continuous improvement of information security management as the company grows and changes.
3. Scope
The Information Security Management System is based on the ISO 27001: 2013 international standard.
The scope of the certified Information Security Management System is for: ‘The protection of all information and data assets for the delivery of all of ComplyFlow’s organisational functions, services and activities. These include all business processes, including where external third-party suppliers are engaged, involved in the provision of ComplyFlow’s commercial services.’
Further details which define the boundaries of ComplyFlow’s ISMS Scope are outlined in the document titled CF-ISO27001-ISMS Scope.
4. Policy Framework
As part of implementing the ISMS, ComplyFlow reviewed and consolidated our policy framework for information security, in addition to integrating requirements of the ISO 27001: 2013 standard with our existing policy documentation.
5.1 Policies
5.1.1 IT Security Policy
Our IT Security Policy (CF-POL-20190601-IT Security Policy) sets out rules for the acceptable use of information systems and other ComplyFlow assets. Its sections cover IT Acceptable Use, Information Classification, Secure Disposal & Destruction and Information Transfer.
5.1.2 Data Security & Backup Policy
Our Data Security & Backup Policy (CF-POL-20190601-Data Security & Backup Policy) outlines the key technical principles and requirements for the development, use and management of ComplyFlow information systems and other information assets, in order to preserve their confidentiality, integrity and availability for all users and parties covered in the ISMS scope. Its sections cover Data Security, Cryptographic Controls, Change Management, Secure Development & Maintenance, Information Backup, Logging & Monitoring, Technical Vulnerability Management and Network Controls.
5.1.3 User Access Control Policy
Our User Access Control Policy (CF-POL-20910601-User Access Control Policy) establishes our company framework for providing and maintaining secure access to information systems, for all employees, clients, system users, delivery partners and other third parties. Its sections cover Principles of Access Control, User Access Provisioning & De-Provisioning, User Obligations, Information Access Restrictions, Secure Logon, Password Management System and Privileged Utility Management.
5.1.4 Supplier Security Policy
Our Supplier Security Policy (CF-POL-20190601-Supplier Security Policy) sets out our company principles for managing third party risk, and defines clear rules for ComplyFlow’s relationship with suppliers and delivery partners who maintain direct or indirect access to our information systems and data. It covers Relationship with Suppliers & Partners, Contracts, Access Rights, Ongoing Third Party Risk Management and Supplier Training & Awareness.
5.1.5 Privacy Policy
Our Privacy Policy (CF-POL-20190601-Privacy Policy) establishes our company commitment to protecting confidential information and data.
6. Procedures Framework
As part of implementing the ISMS, ComplyFlow reviewed and consolidated our company procedures for managing information security, in addition to building continuous improvement into our processes through adoption of key ISO 27001: 2013 controls.
6.1 Procedures
6.1.1 Secure Development Procedures
Our Secure Development Procedures (CF-PRO-20190601-Secure Development Procedures) outline the key requirements and processes for secure development of software and information systems in order to safeguard the integrity, confidentiality and availability of information assets and systems. This document covers Data Security, Cryptographic Controls & Key Management, Change Management, Backup, Network Security Management, Information Transfer and System Monitoring.
6.1.2 Incident Management Procedure
Our Incident Management Procedure (CF-PRO-20190601-Incident Management Procedure) sets out the key processes to be followed to ensure quick detection of security events and weaknesses, and appropriate reaction and response to security incidents. It covers Receipt & Classification of Incidents, Treatment Process, Learning From Incidents and Disciplinary Action.
6.1.3 Business Continuity & Disaster Recovery Plan
Our Disaster Recovery Plan (CF-PRO-20190601-Business Continuity & Disaster Recovery Plan) covers the critical disaster scenarios or disruption events which fundamentally threaten business continuity and ComplyFlow information assets. It defines clearly and precisely the action steps necessary to recover IT infrastructure and services, including critical databases and information. Its sections cover General Information, Personnel and Authorisations, Key Contacts and the Disaster Recovery Process for several critical scenarios.
6.1.4 Access Management Manual
Our Access Management Manual (CF-PRO-20190601-Access Management Manual) outlines the key components of user access for both ComplyFlow staff and our cloud-service customers, which aim to preserve the confidentiality, integrity and availability of information assets and systems. It sets out principles for managing Role-based access control (RBAC) procedures, and covers Employee Onboarding, Managing Privileged Access, Revoking Staff Access, Password Management, Additional Procedures for Developers and Support Team Access Procedures.
6.1.5 Employment Procedure
Our Employment Procedure (CF-PRO-20190601-Employment Procedure) outlines steps that ComplyFlow managers must take when setting up new employees with accounts, and granting access to ComplyFlow information systems. It covers Commencement of Employment (Screening Processes, Documentation, Legal, Training and Access), Induction Training, Developer Onboarding, Role Changes and Termination of Employment.
7. Legislative & Prudential Framework
Our Information Security Management System was developed in consideration of the following legislative and prudential requirements:
- Privacy Act 1988
- The Information Privacy Act 2014 (ACT)
- Privacy and Personal Information Protection Act 1998 (NSW)
- Information Act (NT)
- Information Privacy Act 2009 (QLD)
- Information and Protection Act 2004 (TAS)
- Privacy and Data Protection Act 2014 (VIC)
- Health Records Information Privacy Act 2002 (HRIP Act)
- The Protective Security Policy Framework (Attorney-General’s Department)
- Prudential Standard CPS 232 Business Continuity Management (APRA)
- Prudential Practice Guide CPG 234 Management of Security Risk in Information and Information Technology
8. Document Information
Our ISMS has been developed within the security domains of ISO 27001: 2013, and seeks to outline the application of this standard to our existing information security management practices.
8.1 Adherence to the Standard and Policy
ComplyFlow takes non-compliance with all policies and related standards very seriously. If any employee or user breaches the standards of use it may result in disciplinary action in accordance with the terms stipulated within staff Employment Contracts and the broader ISMS Policy. In the case of serious breaches, this may include termination of employment.
The Other Documents
The Rest of the Set.
Five documents, each on its own page and each controlled. Four are sections of the one policy; the Information Security Policy stands on its own.
-
Section 1
Privacy Policy.
ComplyFlow's Privacy Policy: how we collect, use, disclose, and protect your personal information across our website and platform.
-
Section 2
Terms of Service.
The terms governing use of the ComplyFlow website and services: what you may not do, content you post, liability, governing law, and the Starter plan.
-
Section 3
Fair Usage Policy for API Usage.
How ComplyFlow keeps its API and MCP server fair for everyone: usage limits, acceptable use, monitoring, and what happens when limits are exceeded.
-
Section 4
Website Cookie Policy.
Which cookies the ComplyFlow website and web application use, what each kind does, the third-party services involved, and how to refuse them.