Information Security Policy

Information Security Policy

Unite Solutions

Our Commitment

Unite Solutions is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our clients, partners, and service providers.

Information security is an essential part of how we deliver services. We recognise that protecting information assets helps maintain client trust, reduce business risk, and support the reliable delivery of technology solutions.

Unite Solutions is committed to implementing and maintaining appropriate security practices that protect information from unauthorised access, disclosure, alteration, loss, or disruption.

Scope

This policy applies to:

  • The CEO & Senior IT Consultant of Unite Solutions.
  • Contractors engaged by Unite Solutions.
  • Third-party service providers involved in the delivery of services on behalf of Unite Solutions.
  • Information, systems, devices, applications, cloud services, and technology resources used to deliver services to clients.

Information Security Objectives

Unite Solutions is committed to:

Protecting Information Assets
  • Safeguarding information from unauthorised access, use, disclosure, modification, destruction, or loss.
  • Maintaining the confidentiality, integrity, and availability of information throughout its lifecycle.
  • Protecting client, business, and commercially sensitive information using appropriate security controls.
Managing Access Securely
  • Applying the principle of least privilege when granting access to systems, applications, and information.
  • Restricting access to authorised individuals only.
  • Reviewing access requirements and removing access when it is no longer required.
  • Using secure authentication methods to protect access to systems and services.
Managing Security Risks
  • Identifying and assessing information security risks relevant to business operations and client engagements.
  • Implementing security controls appropriate to the level of identified risk.
  • Reviewing security risks and controls periodically to ensure ongoing effectiveness.
Supporting Security Awareness
  • Maintaining awareness of current cybersecurity threats, vendor security advisories, industry best practices, and emerging risks relevant to client environments.
  • Ensuring contractors and service providers understand their security and confidentiality obligations where applicable.
  • Promoting responsible handling of information and technology resources.
Managing Security Incidents
  • Reporting, investigating, and responding to suspected or actual information security incidents in a timely manner.
  • Taking appropriate corrective action to minimise impacts and reduce the likelihood of recurrence.
  • Using lessons learned to improve security practices and processes.
Managing Contractors and Service Providers
  • Engaging contractors and service providers who are capable of meeting appropriate security and confidentiality requirements.
  • Limiting access to information and systems to the minimum necessary to perform agreed services.
  • Taking reasonable steps to ensure third parties protect information entrusted to them.
Meeting Legal and Contractual Obligations
  • Complying with applicable Australian laws, regulations, privacy requirements, and contractual obligations.
  • Respecting client confidentiality and handling information in accordance with agreed requirements.
  • Maintaining information security practices that support client expectations and recognised industry standards.
Continual Improvement
  • Regularly reviewing information security practices, risks, and controls.
  • Monitoring emerging threats and adapting security measures where appropriate.
  • Continually improving information security practices to support the evolving needs of clients and the business.

Responsibilities

The CEO & Senior IT Consultant of Unite Solutions is responsible for:

  • Establishing and maintaining information security practices.
  • Assessing and managing information security risks.
  • Ensuring appropriate safeguards are implemented to protect information assets.
  • Selecting and overseeing contractors and service providers involved in service delivery.
  • Responding to and managing information security incidents.

Contractors and service providers engaged by Unite Solutions are responsible for:

  • Protecting information entrusted to them.
  • Complying with applicable confidentiality, privacy, and security obligations.
  • Promptly reporting any actual or suspected security incidents, vulnerabilities, or breaches.

Use of Contractors and Service Providers

Where contractors or third-party service providers are engaged, Unite Solutions takes reasonable steps to ensure appropriate confidentiality, privacy, and information security obligations are in place.

Access to client information is granted only where necessary to perform agreed services and is restricted to authorised individuals.

Security Commitment

Unite Solutions delivers services using secure and reputable technology platforms and works with trusted contractors and service providers where required. Access to client information is restricted to authorised individuals and granted only when necessary to deliver agreed services.

We are committed to maintaining practical, effective, and continually evolving security practices that help protect our clients, our business, and the information entrusted to us.