Management of Electronic Identities
Individuals' Control Requirements:
- Individuals should be able to review all their own electronic identity information for each ICT system in which they have been authorised through an appropriately authenticated and authorised session. Where an individual finds an item that is incorrect, they should be able to electronically request a change to that item. The update may be automatic or routed for approval depending on the business rules applied to the data.
- Each electronic identity will have a unique identifier.
- Electronic identities are to be consistent across all systems. A change in details of an identity in one location is to be reflected in all locations where that identity is stored.
Self-service password reset functionality is only to be provided for passwords that allow access to information that is classified at AAL 2 (In Confidence) or below. - Staff to be provided with a facility to edit their own data relating to location, phone number, expertise, qualifications and interests in the directory. Changes to this data will be subject to logging and relevant control processes.
Protection of Users:
- As soon as the department is notified of a domestic violence order (DVO) or apprehended violence order (AVO), the protected person's data and any associated student's data (except for username and password) is to be moved out of the standard data store and into a secure data store where the data is protected and access restricted to Highly Protected (AAL 4). (Note this may be a paper based data store)
- As soon as department is notified that a child/adult learner is subject to a protection order, all details except for username and password are to be moved from the standard data store and into a secure data store where the data is protected and access restricted to Highly Protected (AAL 4). (Note this may be a paper based data store)
Staff Control Requirements -Schools:
- A directory of teachers employed both part time and full time including their teacher registration numbers and the locations where they are working is to be maintained. Any cancellations of registration or any failure to renew registration will be processed against this list and the relevant school principal(s) will be informed as soon as possible.
- A directory of all non-teachers employed both part time and full time including their blue card registration numbers and the locations where they are working is to be maintained. Any cancellations of blue cards are to be processed against this list and the relevant school principal(s) informed as soon as possible.
Staff Control Requirements - Institutes:
- Where a TAFE teacher/non teacher has been charged or convicted of an indictable offence, the teacher/non-teacher shall inform the Institute Director, who will decide whether they will retain their electronic identity.
^ Top of page