IS18 — Queensland Information and Cyber Security Policy

Queensland's information and cyber security policy, requiring agencies to run an ISO 27001-based ISMS and report through an annual return.

Queensland Government, through the Department of Customer Services, Open Data and Small and Family Business. Developed by the Cyber Security Unit and published within the QGEA.

What it is

The Information and cyber security policy — universally called IS18 — is Queensland's whole-of-government information security policy. It sits within the Queensland Government Enterprise Architecture, is administered by the Department of Customer Services, Open Data and Small and Family Business, and was developed by the Cyber Security Unit.

IS18 requires agencies to apply a consistent, risk-based approach to information security, maintaining confidentiality, integrity and availability. Its central requirement is that agencies implement an information security management system based on ISO 27001, covering information, application and technology assets.

It is supported by two things worth knowing about:

  • The Queensland Government Information Security Classification Framework (QGISCF), which sets the minimum requirements for classifying information assets and aligns to national approaches, including the Commonwealth PSPF, where practical. Departments must comply with it.
  • An Essential Eight guideline. Queensland has adopted a control effectiveness-based risk approach when applying the Essential Eight, citing the limited flexibility of ASD's maturity model.

Compliance runs through an annual return to the Cyber Security Unit, and through assurance obtained by the accountable officer proportionate to the criticality of the information held.

IS18 is not a certification scheme, though it does point agencies toward independent external assessment as the most objective form of assurance.

Who it's for

Queensland Government departments and public service entities

Entities in Schedule 1 of the Public Sector Act 2022 (Qld) are in scope, along with government entities directed by their shareholding minister or responsible head to apply IS18.

Statutory bodies

Bodies that must have regard to the QGEA under the Financial and Performance Management Standard 2019 (Qld).

Other Queensland government entities, including local government

Strongly encouraged to apply the policy as recommended better practice rather than bound by it.

Suppliers to Queensland agencies

Where obligations flow through contracts, particularly for providers handling classified or critical agency information.

Why implement it

  • For in-scope agencies it is mandatory policy, with an annual return and accountable officer assurance obligations attached.
  • It builds on a recognised standard. Because the ISMS requirement is ISO 27001-based, the work is portable — the same system supports commercial certification later if it is ever needed.
  • Classification drives sensible spending. The QGISCF forces agencies to establish what information they hold and what it is worth protecting, which is the prerequisite for proportionate controls.
  • The Queensland Essential Eight approach is more workable. A control effectiveness-based risk approach avoids the all-or-nothing maturity mechanic that frustrates many organisations under the ASD model.
  • Assurance is scaled to criticality, so agencies are not forced into external assessment where internal audit is proportionate.

How implementation works

IS18 is risk-based, so the output is a set of justified decisions rather than a checklist.

1. Confirm applicability

Departments and Schedule 1 public service entities are in scope. Statutory bodies that must have regard to the QGEA, and entities directed by a shareholding minister or responsible head, also apply it. Other entities including local government are encouraged to adopt it as better practice.

2. Implement an ISMS

The policy requires an information security management system based on ISO 27001, covering information, application and technology assets. Where ISO 27001 is already held, most of this exists.

3. Classify information against the QGISCF

The Queensland Government Information Security Classification Framework sets the minimum requirements for classifying information assets and aligns to national approaches including the Commonwealth PSPF where practical. Departments must comply with it.

4. Implement the Essential Eight

Queensland has adopted a control effectiveness-based risk approach rather than applying ASD's maturity model rigidly, citing its limited flexibility. Supporting guidance covers how assessments feed whole-of-government reporting.

5. Obtain assurance

Accountable officers must obtain assurance appropriate to the criticality of information and assets. The most objective assurance is independent external assessment; lower levels come from management systems, internal assessment and audit.

6. Complete the annual return

Entities following IS18 complete the information and cyber security annual return each year, which supports the Cyber Security Unit's whole-of-government view.

How Soveriq helps

For agencies, Soveriq builds the ISMS the policy requires, classifies information assets against the QGISCF, runs the Essential Eight assessment in the control-effectiveness form Queensland uses, and prepares the annual return position.

For suppliers, we establish which obligations flow through your agency contract and build evidence proportionate to them.

Where ISO 27001 is held or in progress, the ISMS requirement is largely satisfied and the work concentrates on classification and Queensland-specific reporting.

On internal review. Where Soveriq has built your management system, we do not then assess it and present that as independent assurance — which matters here, because IS18 explicitly values independent assessment as the most objective form. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not approve annual returns, does not speak for the Cyber Security Unit, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the policy requirements, or against the subset flowing to you by contract.
  • Module 02 — Build. ISMS, information asset register and classification against the QGISCF, and Essential Eight uplift.
  • Module 03 — Internal review ahead of the annual return, subject to the impartiality position above.
  • Module 04 — Representation where the Cyber Security Unit or an agency client engages directly.
  • Module 05 — Continuous compliance, including the annual return cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Does IS18 require ISO 27001 certification?

No. It requires agencies to implement an information security management system based on ISO 27001, which is not the same as holding a certificate. Certification is one way to evidence maturity, and some agencies pursue it, but the policy asks for the system rather than the certificate.

How does Queensland handle the Essential Eight?

Queensland has adopted a control effectiveness-based risk approach when applying the Essential Eight, citing the limited flexibility of ASD's maturity model. Supporting guidance sets out how assessments feed whole-of-government IS18 reporting. The guidance is advisory rather than a mandatory component of the policy.

Can we get an exception?

Yes. Agencies can apply for exceptions from policy or reporting requirements through the QGEA alignment and exception process. Where the departure is from a sub-requirement within a mandated standard — a single control, for instance — agencies can seek sign-off from the accountable officer instead.

Does IS18 apply to local government?

Not mandatorily. Other Queensland government entities, including local governments, are strongly encouraged to apply the policy as recommended better practice.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope