Security Policy
v2.1
Purpose. States how the business protects Defence information, materiel and sites in line with its membership of the Defence Industry Security Program.
1.Purpose and scope
This policy applies to all Sentinel staff, contractors and visitors and to all sites, systems and records. It supports the requirements of the Defence Industry Security Program and the Protective Security Policy Framework as they apply to a defence industry contractor. The Safety, Security and Compliance Manager is the appointed security officer for the business.
2.Personnel security
Every role is assessed for the level of clearance it requires. No person will be given unescorted access to a controlled area, or access to classified or sensitive information, until their clearance has been confirmed and recorded. Staff must report changes in their personal circumstances that affect their clearance to the security officer within the time required by the program.
3.Physical security
Controlled areas will be fenced, locked and alarmed to the standard required for the material they hold. Keys and access cards must be signed out and in, and the register must be reconciled weekly. Visitors must sign the visitor register, be escorted at all times inside a controlled area and wear a visitor pass that is returned on exit.
- Explosives area gate locked outside working hours
- Alarm activations recorded and investigated
- Key and access card register reconciled weekly
- Visitors escorted in every controlled area
4.Information security
Classified and official information must be handled, stored and transmitted only on approved systems and in approved containers. Desks and screens must be cleared at the end of each day. Removable media will not be used on customer connected systems without written approval from the security officer.
5.Reporting
Any suspected security incident, including lost keys, an unescorted visitor, an unattended classified document or a suspicious approach, must be reported to the security officer within 24 hours and recorded. The security officer will assess every report and will notify the customer where the program requires it.
6.Training
All staff will complete security awareness training on induction and annually. Completion will be recorded in the training and competency register, and staff without a current record will not be rostered to a controlled area.