Information Security Policy
Information Security Policy
Unite Solutions
Our Commitment
Unite Solutions is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our clients, partners, and service providers.
Information security is an essential part of how we deliver services. We recognise that protecting information assets helps maintain client trust, reduce business risk, and support the reliable delivery of technology solutions.
Unite Solutions is committed to implementing and maintaining appropriate security practices that protect information from unauthorised access, disclosure, alteration, loss, or disruption.
Scope
This policy applies to:
- The CEO & Senior IT Consultant of Unite Solutions.
- Contractors engaged by Unite Solutions.
- Third-party service providers involved in the delivery of services on behalf of Unite Solutions.
- Information, systems, devices, applications, cloud services, and technology resources used to deliver services to clients.
Information Security Objectives
Unite Solutions is committed to:
- Safeguarding information from unauthorised access, use, disclosure, modification, destruction, or loss.
- Maintaining the confidentiality, integrity, and availability of information throughout its lifecycle.
- Protecting client, business, and commercially sensitive information using appropriate security controls.
- Applying the principle of least privilege when granting access to systems, applications, and information.
- Restricting access to authorised individuals only.
- Reviewing access requirements and removing access when it is no longer required.
- Using secure authentication methods to protect access to systems and services.
- Identifying and assessing information security risks relevant to business operations and client engagements.
- Implementing security controls appropriate to the level of identified risk.
- Reviewing security risks and controls periodically to ensure ongoing effectiveness.
- Maintaining awareness of current cybersecurity threats, vendor security advisories, industry best practices, and emerging risks relevant to client environments.
- Ensuring contractors and service providers understand their security and confidentiality obligations where applicable.
- Promoting responsible handling of information and technology resources.
- Reporting, investigating, and responding to suspected or actual information security incidents in a timely manner.
- Taking appropriate corrective action to minimise impacts and reduce the likelihood of recurrence.
- Using lessons learned to improve security practices and processes.
- Engaging contractors and service providers who are capable of meeting appropriate security and confidentiality requirements.
- Limiting access to information and systems to the minimum necessary to perform agreed services.
- Taking reasonable steps to ensure third parties protect information entrusted to them.
- Complying with applicable Australian laws, regulations, privacy requirements, and contractual obligations.
- Respecting client confidentiality and handling information in accordance with agreed requirements.
- Maintaining information security practices that support client expectations and recognised industry standards.
- Regularly reviewing information security practices, risks, and controls.
- Monitoring emerging threats and adapting security measures where appropriate.
- Continually improving information security practices to support the evolving needs of clients and the business.
Responsibilities
The CEO & Senior IT Consultant of Unite Solutions is responsible for:
- Establishing and maintaining information security practices.
- Assessing and managing information security risks.
- Ensuring appropriate safeguards are implemented to protect information assets.
- Selecting and overseeing contractors and service providers involved in service delivery.
- Responding to and managing information security incidents.
Contractors and service providers engaged by Unite Solutions are responsible for:
- Protecting information entrusted to them.
- Complying with applicable confidentiality, privacy, and security obligations.
- Promptly reporting any actual or suspected security incidents, vulnerabilities, or breaches.
Use of Contractors and Service Providers
Where contractors or third-party service providers are engaged, Unite Solutions takes reasonable steps to ensure appropriate confidentiality, privacy, and information security obligations are in place.
Access to client information is granted only where necessary to perform agreed services and is restricted to authorised individuals.
Security Commitment
Unite Solutions delivers services using secure and reputable technology platforms and works with trusted contractors and service providers where required. Access to client information is restricted to authorised individuals and granted only when necessary to deliver agreed services.
We are committed to maintaining practical, effective, and continually evolving security practices that help protect our clients, our business, and the information entrusted to us.