Information security incident notifications
What is an information security incident?
An information security incident is defined as:
one or multiple related and identified security events that can harm/damage an organisation, its assets, individuals or compromise its operations. Information security incidents may take many forms, such as compromises of electronic information held on government systems and services and include information in physical formats e.g., printed, photographs, or recorded information either audio or video, and verbal discussions.
Information security incidents can include privacy breaches.
Who can notify OVIC when an incident occurs?
Any organisation that is subject to the Privacy and Data Protection Act 2014 (Vic) (PDP Act) can use this form to report incidents to OVIC.
The form should not be used by members of the public to report incidents, data breaches or alleged wrongdoing by VPS employees or organisations to OVIC. Individuals wishing to do so, should instead use OVIC’s Privacy Complaint Form.
For those submitting a notification on behalf of their organisation, please follow internal incident management authorisation processes to avoid duplicate submissions for the same incident.
What sort of incidents does OVIC accept?
Under element E9.010, VPS organisations are encouraged to notify OVIC of incidents that have an adverse impact on the confidentiality, integrity and/or availability of public sector information with a business impact level (BIL) of 2 (limited) or higher.
This includes information with a protective marking of OFFICIAL: Sensitive, PROTECTED, Cabinet-In-Confidence or SECRET. Refer to your organisation’s BIL table or the VPDSF BIL table to assess the potential business impact level of the information affected in the incident.
Incidents may take many forms. They are not just limited to compromises of electronic information held on government systems and services but also include compromises of information held in physical formats (e.g., printed, photographs, recorded information either audio or video) or unauthorised verbal discussions.
Incidents may affect different types of public sector information. OVIC encourages organisations to notify us of incidents that affect all types of information for example financial, policy, operational, legal, and not just personal information.
If the incident is of a criminal nature or involves fraud/corruption, please follow your organisation’s policy on reporting these types of incidents to the relevant bodies.
Privacy breach considerations
If an incident relates to a breach of personal information, consider the impact on individuals and the need to notify them in a timely manner. Although some impacts may not appear high to the business, they may be for individual(s).
For more information regarding incidents involving a privacy breach, refer to Managing the Privacy Impacts of a Data Breach on OVIC’s website.
Accessing the notification form
Please download the form in the sidebar and email a completed copy to incidents@ovic.vic.gov.au
Understanding the information security incident notification scheme
Please download the information sheet in the sidebar for details of the scheme.
Collection of personal information
The incident notification form collects personal information in the way of contact details. This includes your name, position title, organisation, contact number and email address for the purpose of follow up, research projects or activities set out in OVIC’s Regulatory Action Policy.
Where you provide personal information, OVIC may use it to provide you with return confirmation of receipt of your form, seek clarification on the contents of your form or report on any trends. If you do not provide the information requested in this form, it may limit OVIC’s ability to follow up with you. When submitting your form via email, we may be able to identify you from your email address.
OVIC will not disclose your personal information without your consent, except where required or authorised to do so by law. OVIC does publish de-identified information (or aggregated data) in our monitoring and assurance reports.
You may contact OVIC to request access to any personal information you have provided to us by emailing enquiries@ovic.vic.gov.au.
For further information on how OVIC handles personal information, please review our privacy policy.
Important! Do not include the personal information of any employees or individuals involved in, or impacted by, the incident. The only personal information requested is that of the organisation’s nominated contact representative which should be noted in the designated fields on this form.
OVIC is always looking to improve the quality of its website resources. If you have feedback to share, please email enquiries@ovic.vic.gov.au.