Trust & Security

Information Security Policy

How ICE HRM Pty Ltd organises, manages and continually reviews the security of the information entrusted to IceHrm.

Last updated 26 September 2026 8 sections
Contents
  1. Summary
  2. Importance of Information Security
  3. Objective and Scope
  4. Roles and Responsibilities
  5. Standards and Ownership
  6. Risk Management
  7. Handling Security Incidents
  8. Continual Improvement

Summary

This policy sets out how ICE HRM Pty Ltd ("IceHrm", "we" or "us") protects the information used to run our business and the information our customers entrust to the IceHrm Cloud service.

We define information security as the total of standards, plans and measures that guarantee the availability, confidentiality and integrity of the information we process.

  • The Information Security Officer is responsible for maintaining this policy, giving advice and guiding its implementation.
  • Managers are responsible for the security measures in their area, and all employees and contractors are responsible for following this policy and its supporting standards and procedures.
  • Compliance with this policy is checked regularly through internal reviews.
  • All security incidents, whether actual or suspected, must be reported to the Information Security Officer immediately, so that action can be taken to limit any harm to our customers, their employees and IceHrm.

Importance of Information Security

Our business processes, and those of our customers, depend on the reliability of the information we hold and of the systems that process it. Customers, suppliers and regulators rightly expect that information to be handled securely. Inadequate security could cause serious financial and reputational harm, both to IceHrm and to the customers who have entrusted their information to us, so we address information security systematically.

Quality aspects

Information security covers three quality aspects:

  • Availability – information is available when it is needed. This covers continuity and timeliness.
  • Integrity – information is accurate, complete, up to date, valid, verifiable and authentic.
  • Confidentiality – information is accessible only to those who are authorised to access it, and privacy is protected when information is stored and used.

This policy applies to both automated and non-automated information.

Objective and Scope

The objective of this policy is to establish, record and communicate our objectives, key principles and preconditions for information security, and to make clear who has which tasks, authority and responsibilities.

The policy applies to all IceHrm employees and contractors, to all systems used to provide the IceHrm Cloud service and to operate our business, and to the service providers we engage to host or process information on our behalf.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where it applies, the GDPR. More detail is in our Privacy Policy.

Roles and Responsibilities

Information security is a line responsibility

The Information Security Officer sets the policy. Managers are responsible for putting it into practice in their area, including for the business processes, information and systems they manage, and for choosing, carrying out and maintaining the appropriate security measures.

Security is everyone's responsibility

We expect care and alertness from every employee and contractor, including following our rules on passwords, access and the handling of customer data. Managers are expected to encourage this behaviour.

Security is part of how we operate

Information security is not a goal in itself but an integral part of our business objectives and operations. In deciding on security measures we consider:

  • our legal and contractual obligations for the information we hold, including customers' employee data;
  • the need to minimise security risks;
  • the efficiency and effectiveness of our services; and
  • the cost and practical impact of the measures.

Standards and Ownership

Our security requirements are based on the ISO/IEC 27001 standard and the ISO/IEC 27002 code of practice for information security controls. They are recorded in our internal standards framework, which is applied to each part of our business.

Owners of information and systems

Every information system, resource and data collection has an owner. Resources include applications, network infrastructure, data, computers and mobile devices. Owners are responsible, including where services are outsourced, for:

  • determining the value and importance of the information and systems;
  • classifying the information and systems;
  • assessing risks and identifying the necessary security measures;
  • ensuring security measures are implemented and remain effective; and
  • ensuring personal information is handled in accordance with the law and our policies.

The owner of information and the owner of the system that processes it may be different people.

Access to data

For each data collection, the owner decides who may access the data, who may view, change, delete or disclose it, and who monitors its integrity. Before a new system is introduced, ownership and responsibility for managing it are agreed. IceHrm staff may access a customer's installation only with the customer's written permission, or where it is necessary to maintain the security of the Service.

Risk Management

Reliability requirements

Our standards set out what security is required; each part of the business determines how to meet them. Each area must decide on the security level its systems require, based on classification and risk analysis, and continually consider whether additional measures are needed.

Risk analysis

We carry out regular risk assessments that consider the threats to our systems and data, their likelihood, their potential impact and our vulnerabilities. Based on these assessments we choose security measures that achieve an acceptable level of risk, taking their costs and benefits into account. Systems with higher availability, integrity or confidentiality requirements receive additional measures, which are documented and communicated.

Handling Security Incidents

A security incident is any unlawful or unauthorised access to the IceHrm Cloud service or to customer data, or to the equipment or facilities used to store customer data, that results in, or is likely to result in, the loss, disclosure or alteration of customer data. If we become aware of a security incident, we will promptly:

  • notify the affected customers;
  • investigate the incident and give affected customers information about it; and
  • take reasonable steps to contain it and to minimise any harm.

We assess incidents involving personal information under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth). Where an eligible data breach has occurred, we notify the affected individuals and the Office of the Australian Information Commissioner as required, and we support customers to meet their own notification obligations, including under the GDPR where it applies.

Anyone who notices an actual or suspected incident must report it to the Information Security Officer, who classifies it, manages the response and informs management. After an incident is resolved, we review it and take measures to prevent similar incidents or limit their impact.

Continual Improvement

Information security is a continual process, not a one-off activity. Changes to our organisation, systems and services affect the security that is required, so this policy and its measures are kept under review:

  • Policy – the Information Security Officer records the objectives, principles and preconditions, and how they are translated into concrete measures.
  • Baseline security – our standards framework is translated into security measures by each part of the business, prioritised on the basis of risk.
  • Additional security – systems with higher requirements receive additional measures through a clear and repeatable process.
  • Review – we check that measures are carried out as intended and periodically assess whether they are still adequate, adjusting them where needed.

Questions about this policy can be sent to [email protected].