Security

Under review. Expected release by December 2026.

Use of the protective markings described in sections 6.4.3, 6.4.4 and 6.4.5 apply only to PSOs listed as an agency in the Administrative Arrangements Order, which are referred to in this standard as NTG PSOs. Other PSOs are encouraged to model their protective markings and associated handling procedures on the NTG PSO requirements if applicable.

6.4.1 Secure access to records

6.4.1.1 Records and information must be protected from unauthorised or unlawful access, destruction, loss, deletion or alteration.

  • Access to sensitive records and information should be on a need-to-know basis, i.e. information access is to be determined by whether it is required in order to perform a duty or meet a legal right or obligation.
  • Business unit managers are responsible for determining who should have a ‘need-to-know’ regarding official records and information, and to allocate and document appropriate personnel security profiles.
  • Penalties may apply if an organisation fails to store information securely and this results in a privacy breach. Penalties may apply to an individual, if the individual mishandles information in accordance with offence provisions of the Information Act.

6.4.1.2 Access to record and information systems must be monitored and controlled.

  • Access to official records is restricted to users with the appropriate security profile.
  • The movement and alteration of official records is undertaken in compliance with security requirements of the records.
  • Audit logs of records management systems are to be monitored to ensure compliance with security requirements.

6.4.1.3 All personnel accessing records and information systems must have an approved security profile mapped to the record and information systems to which they have access.

6.4.1.4 PSOs must assess the value of information contained in the records they possess and implement appropriate security handling procedures based on a risk analysis of the likely impact of unauthorised disclosure.

6.4.2 Protective markings

6.4.2.1 A protective marking must be assigned to a record identified as being sensitive or requiring a security classification, indicating the level of protection required during the use, storage, transmission, transfer and disposal of the information.

  • Appropriate protective markings for sensitive information are defined and any related handling procedures documented. Protective markings should be based on risk analysis of the likely impact of unauthorised disclosure of the information.
  • Personnel creating a record, or actioning a record received from outside the organisation, are responsible for allocating an appropriate protective marking in accordance with approved standard operating procedures.
  • Protective markings available for use by NTG PSOs are: Security Classifications; Dissemination Limiting Markers; and Caveats.

6.4.3 NTG PSO: Security classification system

6.4.3.1 NTG PSOs must apply the NTG Security Classification System to protect sensitive information from unauthorised access.

  • Information security in NTG PSOs is to be aligned with requirements detailed in the Australian Government’s Protective Security Policy Framework (PSPF) where appropriate and applicable. (9)
  • The NTG Security Classification System is modelled on the Australian Government Security Classification System (AGSCS) and applies to information in any format. The AGSCS is part of the PSPF. (10)

NTG security classifications aligned with the PSPF classifications:

Classifications Comments
PUBLIC Information which can be feely published.
UNCLASSIFIED Official information which does not require a security classification (though may be marked with a Dissemination Limiting Marker (DLM)). For internal NTG use only. Must be examined and deemed public before release.
PROTECTED (security classification) Where compromise could cause damage to the national interest, organisations or individuals.
CONFIDENTIAL
(security classification)
Where compromise could cause significant damage to the national interest, organisations or individuals.
SECRET
(security classification)
Where compromise could cause serious damage to the national interest, important economic and commercial interests or threaten life.
TOP SECRET
(security classification)
Where compromise could cause exceptionally grave damage to the national interest.
  • Security classifications are to be determined in line with the degree of protection the information in the record requires.
  • Records should only be security classified when the consequences of compromise warrant the expense and effort of increased security protection.
  • When a decision is made to security classify a record, an organisation should consider whether a time limit for the classification be set.

6.4.3.2 Security classifications must be applied by the originator of the document at the time it is created or received.

6.4.3.3 The default classification for documents will be UNCLASSIFIED, with the creator of the document required to assess whether an alternative classification or DLM is required.

  • The vast majority of NTG PSO records will fit into the UNCLASSIFIED classification.
  • The classification of UNCLASSIFIED is applied to records and information not requiring a security classification. Although the information does not require a security classification it may still be of a sensitive nature which requires protection through the use of a DLM.
  • Documents at the UNCLASSIFIED level are not open for immediate public release. A change of classification to PUBLIC is required before release or publication.
  • UNCLASSIFIED and PUBLIC records may remain unmarked.

6.4.3.4 All Cabinet documents and associated records are to be marked as ‘Sensitive: Cabinet’ and carry a security classification of at least PROTECTED or higher.

  • Some classes of law enforcement information may have a minimum classification of PROTECTED

6.4.3.5 Use of CONFIDENTIAL, SECRET and TOP SECRET classifications, which are considered national security classifications, is limited within the NTG.

  • Refer to the Australian Government guides listed as key references for more information and guidance on use of these classifications.

6.4.4 NTG PSO: Dissemination limiting markers

6.4.4.1 DLMs, other than For Official Use Only (FOUO), must be used where disclosure of the information marked by the DLM may be limited or prohibited by legislation or regulation, or other legal obligation.

  • The PSPF defines a base set of DLMs: FOUO; Sensitive; Sensitive: Cabinet; Sensitive: Legal; Sensitive: Personal.
  • More than one DLM may be applied to documents where appropriate and justified (Exclusion: FOUO is used as a stand-alone marker only).
  • The NTG allows the authorised definition of new DLMs if they are based on a legislative or regulatory requirement, or other legal obligation, which is dependent on the information contained in the document.
  • A DLM should not reference the business unit responsible for the management of the information. System access controls should be used where access needs to be limited to organisational units.
  • The “Sensitive” DLM cannot be used without an annotation that indicates the reason for the sensitive marking of the document. Annotations may specifically, or in a generic manner, reference legislation and regulations, or contractual arrangements, which require the protection of the information.

6.4.4.2 FOUO must only be used to mark UNCLASSIFED information and cannot be used in combination with another DLM.

  • The FOUO DLM can be used where no specific legislative or regulatory protection of information is required but the information is still considered sensitive.
  • The FOUO DLM does not require an annotation as to the reason why the information has been marked.

6.4.5 NTG PSO: PSPF Caveats

6.4.5.1 NTG PSOs must refer directly to the PSPF guides for advice on caveats as the requirement within the NTG is unlikely and if used, would be very limited.

  • Caveats, when described within the context of the PSPF, are supplementary markings which indicate additional special handling requirements. Examples of caveat categories include: Codewords; Source Codewords; Eyes Only; Australian Government Access Only; Releasable to; Accountable material.

6.4.6 Reclassification and review of protective markings

6.4.6.1 A PSO must have procedures in place to review and declassify classified records.

  • Records can be reclassified if protection is no longer necessary or is no longer needed at the original level. Classifications should be reviewed when records become inactive or are transferred to secondary storage or the NT Archives Service.
  • If a record is transmitted to another PSO, only the originating organisation (i.e., the organisation that assigned the original classification) can reclassify or declassify a record.
  • If an organisation is abolished or amalgamated, the organisation assuming the former agency’s responsibilities is deemed the originating organisation for the purpose of re-classification and declassification.
  • Inappropriate over-classification can have detrimental effects, e.g., the volume of security classified records becomes too large for an organisation to protect adequately, or the discoverability of records is impaired where the classification is unwarranted.

6.4.6.2 Records must be declassified or downgraded when protection is no longer necessary or is no longer needed at the original level.

6.4.7 Physical security

6.4.7.1 Access to areas where security classified records are held or used must be restricted.

  • All the organisation’s systems, workplaces and storage areas which contain official records are to be designed and managed to protect them from unauthorised access, alteration or deletion, and personnel are aware of and follow the procedures to ensure this.

6.4.7.2 When security classified records are not in use, they must be stored in an appropriately secured environment.

  • During absences from their workplace and at close of business personnel are responsible for ensuring that records and systems are secured appropriately.