OFFICIAL
Sven Bluemmel Victorian Information Commissioner
OVIC
Freedom of Information, Information security and Privacy
Graduate Recruit Induction
16 July 2019
OVIC Freedom of Information, Information security and Privacy - - PowerPoint PPT Presentation
OFFICIAL OVIC Freedom of Information, Information security and Privacy Sven Bluemmel Graduate Recruit Induction Victorian Information Commissioner 16 July 2019 OFFICIAL Presentation Title 2 Overview Who we are What we do
OFFICIAL
Sven Bluemmel Victorian Information Commissioner
Graduate Recruit Induction
16 July 2019
OFFICIAL
Freedom of Information | Privacy | Data Protection 2
Presentation Title
– Freedom of Information – Data Protection – Privacy
digital age
OFFICIAL
Freedom of Information | Privacy | Data Protection 3
OFFICIAL
Freedom of Information | Privacy | Data Protection 4
“The creation of this new office will provide more proactive and
Second reading speech of the Freedom of Information Amendment (Office of the Victorian Information Commissioner) Act 2017
OFFICIAL
Freedom of Information | Privacy | Data Protection 5
Information Commissioner Privacy and Data Protection Deputy Commissioner Information Privacy Information Security Public Access Deputy Commissioner Freedom of Information
OFFICIAL
Freedom of Information | Privacy | Data Protection 6
OFFICIAL
Freedom of Information | Privacy | Data Protection 7
individuals to participate in society
government:
OFFICIAL
Bruce Rego Acting Principal Case Manager
Graduate Recruit Induction
16 July 2019
OFFICIAL
Freedom of Information | Privacy | Data Protection
What is FOI?
mechanism by which anyone can request access to documents held by public authorities Why is the concept of FOI important?
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
Victorian Information Commissioner
administration of the FOI Act
decision making
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
information or documents without the requirement for a formal FOI request.
OVIC GRADS Presentation 2018
OFFICIAL
Processing a request
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
investigations
prevent certain documents from being subject to FOI, including the IBAC Act, and Ombudsman Act
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
Provides Documents & Advice FOI Officer Requests Documents & Advice Non-FOI Officer
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
Agencies may refuse to process a request if:
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
Freedom of Information | Privacy | Data Protection
OVIC GRADS Presentation 2018
OFFICIAL
OFFICIAL
Brett Duke Senior Business Engagement Officer James Dougan Policy Officer
Graduate Recruit Induction
16 July 2019
OFFICIAL
Freedom of Information | Privacy | Data Protection 29
Information Security
OVIC and information security Information security Physical security Personnel security
ICT security
Questions
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 31
Information Security
security@ovic.vic.gov.au 1300 006 842 https://www.ovic.vic.gov.au/
OFFICIAL
Freedom of Information | Privacy | Data Protection 32
Information Security PDP Act 2014
Principles Policy Standards Security guides Agency specific policies and procedures
Assurance
OFFICIAL
Freedom of Information | Privacy | Data Protection 33
Information Security
A position of privilege Manage risks across the information lifecycle Minimising risks to your
you work with
Good information security = good information management
OFFICIALOFFICIAL
Freedom of Information | Privacy | Data Protection 34
Information Security
Confidentiality Integrity Availability
Right people Right information Right time
OFFICIAL
Freedom of Information | Privacy | Data Protection 35
Information Security
Personnel Security ICT Security Information Security Physical Security
There are four domains of protective data security
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 37
Information Security
Good information security doesn’t just happen We all play an integral role No defense is impenetrable Consider the value of the information you work with
OFFICIAL
Freedom of Information | Privacy | Data Protection 38
Information Security
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 40
Information Security
1. How many entrances are there to this building? 2. How many security personnel were in the lobby when you arrived? 3. How many turnstiles were available for you to swipe your pass and gain access to the lift well?
OFFICIAL
Freedom of Information | Privacy | Data Protection 41
Information Security ‘Information’ includes hardcopy, softcopy and verbal Understanding where it is appropriate to view, use or discuss official information Applying appropriate physical security measures to protect information when not actively using it
OFFICIAL
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 43
Information Security
Personnel security and the VPDSF
culture with clear personal accountability
responsibility towards information security
Our greatest strength can also be our greatest weakness
greatest strength, but can be the weakest link.
Social engineering
Government Buildings report (penetration testing)
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 45
Information Security
A mobile workforce We are high value targets Cyber hygiene
Compromised or stolen credentials (method unknown) 40% Brute-force attack (compromised credentials) 7% Phishing (compromised credentials) 20% Hacking 13% Ransomware 7% Malware 13%
OAIC NOTIFIABLE DATA BREACHES QUARTERLY STATISTICS REPORT MAY 2019
OFFICIAL
Freedom of Information | Privacy | Data Protection 46
OVIC security staff session
OFFICIAL
Caitlin Galpin Senior Privacy Guidance Officer
Graduate Recruit Induction
16 July 2019
OFFICIAL
Freedom of Information | Privacy | Data Protection 48
Act 2014 (Vic)
OVIC Privacy Presentation
Responsibilities Act 2006 (Vic)
OFFICIAL
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 51
OVIC Privacy Presentation
OFFICIAL
OFFICIAL
Personal information is defined in the PDP Act as:
OVIC Privacy Presentation
OFFICIAL
Freedom of Information | Privacy | Data Protection 54
OVIC Privacy Presentation
It’s personal information if someone’s identity can be reasonably ascertained from the information.
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 56
OVIC Privacy Presentation
OFFICIAL
OFFICIAL
The IPPs set the minimum standards for the collection and handling of personal information in the VPS.
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
individual (IPP 1.4)
taken to notify the individual of the collection (IPP 1.5)
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
OVIC Privacy Presentation
OFFICIAL
Freedom of Information | Privacy | Data Protection 73
OVIC Privacy Presentation
OFFICIAL
OFFICIAL
Freedom of Information | Privacy | Data Protection 75
OVIC Privacy Presentation
OFFICIAL
Freedom of Information | Privacy | Data Protection 76
OFFICIAL