Security and Compliance Framework

NAISAR's security architecture protects the most sensitive personal information in the Australian justice system through defence-in-depth design, sovereign data custody, and uncompromising privacy standards.

Certifications and Standards

The NAISAR security architecture is designed to meet the highest available standards for Australian government systems. As a proposed framework, we have not yet undergone formal certification — rather, we have designed our infrastructure and processes to be certifiable against the rigorous standards that ensure confidentiality, integrity, and availability of all protected information.

  • ISO 27001:2022 — designed for certification as an information security management system
  • ISO 27701:2019 — designed for certification as a privacy information management system
  • Essential Eight — architecture mapped to maturity level three cybersecurity baseline
  • Information Security Registered Assessors Program (IRAP) — designed for protected-level government cloud assessment
  • Australian Signals Directorate (ASD) — designed for protected-level cloud certification

Formal certification will be pursued once NAISAR receives government mandate and funding. Until then, our design documentation, threat models, and control frameworks are available for independent review by qualified assessors.

Four-Layer Security Architecture

NAISAR employs a defence-in-depth architecture that places multiple independent security controls between potential threats and protected data. No single layer provides complete protection; rather, each layer complements the others to create cumulative security that remains robust even if individual controls are compromised.

Layer One: Perimeter Security

The outermost layer controls all access to NAISAR systems. Next-generation firewalls filter traffic based on application awareness, intrusion prevention systems detect and block malicious activity, and distributed denial-of-service protection ensures service availability during attack. All external traffic is encrypted using TLS 1.3 with perfect forward secrecy.

Layer Two: Network Segmentation

Internal networks are segmented into security zones based on data sensitivity and functional requirements. Application servers, databases, and management systems operate in separate network segments with strictly controlled inter-zone communication. Micro-segmentation within zones further limits lateral movement potential for any compromised component.

Layer Three: Application Security

All NAISAR applications undergo secure development lifecycle processes, including threat modelling, static and dynamic security testing, dependency vulnerability scanning, and manual code review. Authentication requires multi-factor verification for all users, with adaptive authentication that adjusts challenge strength based on risk signals. Authorisation follows principle of least privilege, with role-based access controls and just-in-time elevation for sensitive operations.

Layer Four: Data Protection

Data at rest is encrypted using AES-256-GCM with keys managed through hardware security modules. Data in transit uses TLS 1.3 with certificate pinning for mobile applications. Database fields containing highly sensitive information, such as location history and victim identities, employ additional field-level encryption. Backup data is encrypted separately and stored in geographically diverse locations with controlled access.

Data Sovereignty

All NAISAR data is stored exclusively on Australian sovereign infrastructure. No data is transmitted to, processed by, or stored in foreign jurisdictions. This commitment to data sovereignty ensures that Australian law governs all access to NAISAR information and that foreign governments cannot compel disclosure through their own legal processes.

Our primary data centres are located in Sydney and Melbourne, with disaster recovery facilities in Brisbane and Perth. All facilities are operated by Australian-owned and controlled entities. Staff with physical access to infrastructure hold Australian security clearances and are subject to Australian employment law and oversight.

Data sovereignty extends to all third-party services integrated with NAISAR. Any vendor providing services that involve access to NAISAR data must maintain Australian infrastructure, Australian staff oversight, and contractual commitments that prevent foreign data transfer. These requirements are non-negotiable and are verified through regular audit.

Privacy Pillars

NAISAR's privacy framework rests on four pillars that guide every decision affecting personal information:

Minimisation

We collect only the information necessary for operational purposes. Data fields are reviewed regularly to ensure that retention remains justified. When information is no longer required, it is securely deleted according to defined retention schedules.

Purpose Limitation

Information collected for one purpose is not used for unrelated purposes without explicit legal authority or informed consent. Victim information is never used for research without de-identification and ethics approval. Offender information is shared only with authorised agencies performing lawful functions.

Transparency

Individuals have the right to understand what information we hold, how we use it, and who we share it with. Privacy notices are written in plain language, and individuals can request access to their personal information through straightforward processes. Where transparency conflicts with safety, such as revealing protective measures to offenders, qualified personnel make documented decisions that prioritise victim safety.

Control

Victims retain meaningful control over their information. They choose what evidence to submit, what notifications to receive, and what professionals can access their records. While some information sharing is necessary for safety, victims are partners in these decisions, not passive subjects of them.

Compliance Matrix

Requirement Standard Target Status Timeline
Information Security Management ISO 27001:2022 Certification Post-establishment
Privacy Information Management ISO 27701:2019 Certification Post-establishment
Cybersecurity Baseline Essential Eight Maturity Level 3 Full compliance 12 months post-launch
Government Cloud Assessment IRAP Protected Assessed Post-establishment
Privacy Act Compliance Privacy Act 1988 (Cth) Compliant From day one
Notifiable Data Breaches Privacy Amendment (NDB) Act Compliant From day one
State Privacy Legislation State and Territory Acts Compliant From day one
Records Management State Records Acts Compliant From day one

Audit Framework

Independent audit is essential to maintaining trust in systems that handle sensitive personal information. NAISAR operates a comprehensive audit framework that subjects all operations to regular, rigorous scrutiny by qualified external parties.

Financial audits examine expenditure, procurement, and resource allocation, ensuring that public funds are used efficiently and ethically. Security audits test technical controls, review incident response capabilities, and validate compliance with certified standards. Operational audits examine case management, response times, decision quality, and outcome achievement. Privacy audits assess information handling practices, consent management, access controls, and individual rights processes.

Audit findings are reported to the NAISAR Board, relevant ministers, and parliamentary oversight committees. Where audits identify deficiencies, corrective action plans are developed with defined timeframes and accountability. Serious findings trigger immediate intervention and may result in disciplinary action, operational suspension, or referral to integrity bodies.

Breach Response Protocol

Despite comprehensive preventive measures, security incidents may occur. NAISAR's breach response protocol ensures that incidents are detected rapidly, contained effectively, and resolved with minimal harm to affected individuals.

Detection relies on automated monitoring systems that analyse network traffic, system logs, and user behaviour for anomaly indicators. Security operations centre staff monitor alerts 24 hours per day, 7 days per week, with escalation pathways that ensure appropriate expertise is engaged for any incident.

Containment procedures isolate affected systems, preserve forensic evidence, and prevent incident expansion. The response team assesses incident scope, identifies affected individuals and data categories, and determines whether the incident constitutes a notifiable data breach under the Privacy Act.

Where notifiable breaches occur, affected individuals are notified as soon as practicable, typically within 72 hours of discovery. Notifications include clear descriptions of what occurred, what information was involved, what steps NAISAR has taken, and what affected individuals can do to protect themselves. The Office of the Australian Information Commissioner receives simultaneous notification, and public notification occurs where the breach affects a large number of individuals or poses significant public risk.

Post-incident review examines root causes, evaluates response effectiveness, and identifies improvements to prevent recurrence. Lessons learned are incorporated into security controls, staff training, and operational procedures.

Discussion

0 comments

No comments yet. Be the first to share your perspective on this article.