(1) This standard foregrounds RMIT’s commitment to information management and its approach to the compliant handling of information in digital form, in compliance with relevant legislation. (2) Authority for this document is established by the Information Governance Policy. (3) This standard applies globally to any person or entity of the (4) RMIT must comply with standards issued under the Public Records Act 1973 (Vic) by the Public Record Office Victoria (PROV). These standards specify how the information we create as part of our work – or records - must be managed. (5) The Information Governance Policy establishes a framework for effective information governance. This standard supports the policy by providing clear information management requirements for information in digital form that underpin the embedding of information management into day-to-day practices by default, so that information is complete, authentic and reliable evidence of RMIT’s actions and decision making. (6) These requirements apply to information, also known as unstructured data, wherever it is received, created or managed including (but not limited to) email systems, productivity tools, business or applications in digital form. This compliance by design approach enables RMIT to build compliance into its systems and processes so that we can: (7) These requirements should be implemented using a risk and value-based approach. Measures taken to ensure compliance should be reasonable and commensurate with the risk presented by the information; they should be followed more closely for high-value information or information needed to mitigate high business risk. (8) Indicators of high-value business information include that it: (9) Information is created and managed digitally throughout its life. (10) Information must be retained according to legal and business requirements and disposed of lawfully when their retention period ends. (11) Information is to be shared. Access to information held by RMIT must not be restricted, unless required by legislation or in accordance with policy or authorised criteria. (12) Controls must be designed and implemented to ensure information is only accessed, amended, used, released, or disposed of as authorised. (13) Information must have sufficient description to allow access and management over time. (14) Information must be managed to facilitate migration or relocation over time to ensure required retention. (15) Managing information compliantly is everyone’s responsibility and all staff, students, researchers and affiliates have an obligation to manage the information they receive, create, collect, manage, use or re-use during their engagement with RMIT in accordance with this standard, the Information Governance Policy and relevant information security, information privacy and data governance policies. (16) Managers are required to ensure that information management principles and practices are implemented locally, and suspected or actual breaches of this standard are reported in accordance with the Compliance Breach Management Procedure. (17) Information Trustees as owners of information must review any risks to information within their remit caused by non-compliance with these principles. If residual risk remains, they must take further mitigating steps or accept the risk/s. (18) Information Stewards provide support and advice for information management activities within their area. (19) The Chief Information Security Officer oversees information security controls and responses to enable RMIT to deliver effective protection of data held by RMIT consistent with privacy and corporate management obligations across all its operations. (20) The Chief Data and Analytics Officer (CDAO) is accountable for leading the information governance framework across RMIT and the CDAO team is responsible for enterprise information management standards in accordance with applicable legislation, under the Information Governance Policy. (21) The Information Governance Board provides advice and recommendations for the strategy, policy and risk in relation to RMIT’s information and data. (22) Breaches of this standard will be managed in accordance with the Compliance Breach Reporting Procedure. (23) The Chief Data and Analytics Officer will review this standard at least every three years in accordance with the Policy Governance Framework. Information Management Standard
Section 1 - Purpose
Section 2 - Authority
Section 3 - Scope
Section 4 - Standard
Overview
Application Guidance
Requirements
Responsibilities
Compliance
Review
View Document
This is not a current document. It has been repealed and is no longer in force.