Library cybersecurity upgrade safeguards public trust

Library Cybersecurity Upgrade

The State Library of New South Wales in Sydney has officially approved its revised Information Security Policy Version 4.2 to enhance cybersecurity across its systems and data landscape. This policy applies to all library personnel, including staff, contractors, vendors and partners. Its purpose is to protect sensitive information, guarantee adherence to the NSW Cyber Security Policy, and fulfil ISO/IEC 27001 standards. The implementation includes enhanced user access controls, improved vendor security protocols, robust incident response measures, and mandatory staff training requirements. 

The recent update aligns with the NSW Government’s Beyond Digital Strategy and tackles the increasing risks associated with information integrity and privacy within public sector data infrastructure. The Executive Committee enforces the policy and supports it with obligatory annual audits to ensure compliance with the Essential Eight requirements set forth by the Australian Cyber Security Centre.

Library strengthens cybersecurity

Key updates to the Information Security Policy (v4.2) include:

  1. Access control and user access management: The library now provides access to its systems based on necessity and job duties, ensuring all users are distinctly identifiable through a single-sign-on system. A digital collections archivist will have access only to archival management systems and will not access financial records or HR data. This minimises the risk of exposing sensitive information and helps prevent internal misuse.
  2. Supplier and vendor security: All vendor agreements must incorporate explicit data protection clauses. Third-party suppliers must formally acknowledge their responsibilities in writing. A cloud storage provider must ensure the security of catalogue metadata for the duration of the contract lifecycle. This feature ensures outside entities uphold the library’s security protocols.
  3. Incident response planning and exercises: The Library tests its Cyber Security Incident Response Plan annually and follows the NSW Cyber Security Policy. Employees must notify the ICT Service Desk about any phishing attempts or suspicious system activity. This proactive approach minimises the impact of potential breaches and facilitates a swift recovery.
  4. Information classification, labelling, and handling: Employees must now apply one of four specific markers to documents based on their content, like Sensitive: Legal or Sensitive: Health Information. Classify donor records as sensitive and personal and store them securely. This practice safeguards privacy and fulfils the requirements set forth by the Privacy and Personal Information Protection Act 1998 (NSW).
  5. Annual cyber maturity reporting and compliance: The Library submits its annual report to Cyber Security NSW by 30 September. It evaluates risks, adherence to the NSW Cyber Security Policy, and maturity levels in relation to the Australian Cyber Security Centre’s Essential Eight. When patching processes are inadequate, the library must formally record the measures taken to address these shortcomings. This openness builds public confidence and drives ongoing enhancement.

 

Check out: “Australian cybersecurity reinforces business trust”

Library advances governance

The Information Security Policy of the State Library bolsters the NSW Government’s Beyond Digital Strategy and enhances cybersecurity and data governance within public-facing institutions. The Library commits to ensuring its digital services are secure by design and comply with legal requirements by aligning with ISO/IEC 27001 standards and the NSW Cyber Security Policy v5. 

The policy emphasises the importance of user access controls, risk assessments, and incident responses in accordance with the Australian Cyber Security Centre’s Essential Eight, a required framework for NSW agencies. The initiative promotes secure cloud storage practices and addresses challenges associated with data silos by ensuring system compatibility and regulated data sharing. 

They safeguard sensitive personal and health data in accordance with the Privacy and Personal Information Protection Act 1998 and the Health Records and Information Privacy Act 2002. The recent changes allow government agencies to work together with data, keep personal information safe, and strengthen the library’s digital systems against new risks, like misuse of artificial intelligence and weaknesses in the system.

Library confirms compliance

The State Library of NSW submits a formal annual attestation to Cyber Security NSW by the 30 September deadline each year in accordance with the NSW Cyber Security Policy v5. This document confirms that the library evaluated its cybersecurity risks, has a tested incident response plan, and maintains a functional Information Security Management System in accordance with ISO/IEC 27001 standards. 

The library must provide a report that details its adherence to all mandatory requirements and includes a maturity assessment aligned with the Australian Cyber Security Centre’s Essential Eight mitigation strategies. Record significant or severe residual risks and tackle them with focused corrective measures. The library identifies its most vital information assets, or crown jewels, and prioritises their protection. 

The Executive Committee and the Audit and Risk Committee provide ongoing oversight of the policy and its outcomes. They conduct regular reviews of governance alignment, resource sufficiency, and security controls’ effectiveness. This reporting framework promotes transparency and accountability while enhancing the library’s digital operations.

The State Library of NSW implemented a robust and enforceable information security framework that complies with state and federal regulations and advances the overarching objectives of the NSW Beyond Digital Strategy. The Library integrates ISO/IEC 27001 standards and the ACSC Essential Eight into its daily operations to maintain a low-risk posture for its information systems and services. Essential insights include enhanced access governance, clear vendor responsibilities, and a proactive incident response framework. 

The recent adjustments offer actionable strategies for public sector organisations that want to enhance their cybersecurity capabilities and maintain operational effectiveness. The library commits to ongoing improvement through annual audits and required reporting processes. These efforts enhance policy development and strengthen resilience. They safeguard data infrastructure, privacy, and digital service delivery against the constantly evolving cyber threats that public institutions across Australia face.

Website |  + posts

Public Spectrum is the first knowledge-sharing platform in Australia to embrace the entire public sector. This website is a platform where you can connect, collaborate, empower, inspire, and upskill with public sector professionals.

Leave a Reply

Your email address will not be published. Required fields are marked *