Practitioner Guide: Assessing the Security Value of Public Sector Information V2.0
This Practitioner Guide provides guidance on conducting an information security value assessment under the Victorian Protective Data Security Framework (VPDSF) using Business Impact Levels.
Disclaimer: The Commonwealth Protective Security Policy Framework (PSPF) has recently issued a policy update recognising OFFICIAL: Sensitive as a security classification. As OVIC aligns with the protective marking scheme of the PSPF, OVIC will be updating its guidance material and associated resources (BIL app, etc.) in due course to reflect these changes.
The change does not:
- trigger changes to the Commonwealth Email Protective Marking System (EPMS)and OVIC’s Technical Specification for Email Protective Markings, as OFFICIAL: Sensitive is already treated as a security classification within these documents
- change the access to information security clearance requirements for OFFICIAL: Sensitive, as employment screening for entity personnel remains sufficient
- change minimum protections and handling requirements for OFFICIAL: Sensitive detailed in Annexes A-C of PSPF policy 8, and
- require changes to the Australian Government Security Caveat Guidelines, as caveats that allow use with OFFICIAL: Sensitive are already indicated.