Cyber security policies
Cyber Security NSW develops and implements cyber security policies for the NSW Government.
NSW Cyber Security Policy
The NSW Cyber Security Policy outlines the Mandatory Requirements to which all NSW Government agencies must adhere to in order to ensure cyber security risks to their information and systems are appropriately managed.
By 31 October each year, Cyber Security NSW must be provided with a report for each agency, either via the portfolio CISO or directly to Cyber Security NSW. Reporting must include:
- an assurance assessment against all Mandatory Requirements in the NSW Cyber Security Policy for the previous financial year
- cyber security risks with a residual rating of high or extreme
- an attestation on cyber security.
Tools and resources
Cyber Security NSW can provide guidance documents and toolkits to assist agencies with implementation of the NSW Cyber Security Policy. For copies of these documents, or for advice regarding the policy, please contact info@cyber.nsw.gov.au.
Cyber Security NSW Circulars
Cyber Security NSW assists with the development of Circulars to advise of and/or mandate certain cyber security practices for NSW Government entities and staff, as required.
- DCS-2021-02 NSW Cyber Security Policy – requires all NSW Government departments and agencies to implement the NSW Cyber Security Policy, to ensure an integrated approach to preventing and responding to cyber security threats
- DCS-2022-03 Accessing NSW Government digital systems while overseas – mandates staff seeking approval from their department/agency cyber security team if they intend to access their NSW Government ICT accounts while overseas
- 22-39 Release of Cyber Security Guidelines for NSW Local Government – outlines cyber security standards and controls recommended by Cyber Security NSW of NSW local government entities
- DCS-2023-01 Cyber Security NSW Directive - Protecting NSW Government information on government-issued devices – prevents the installation and mandates the removal of existing instances of the TikTok application on government-issued devices.