Queensland's information and cyber security policy, requiring agencies to run an ISO 27001-based ISMS and report through an annual return.
The Information and cyber security policy — universally called IS18 — is Queensland's whole-of-government information security policy. It sits within the Queensland Government Enterprise Architecture, is administered by the Department of Customer Services, Open Data and Small and Family Business, and was developed by the Cyber Security Unit.
IS18 requires agencies to apply a consistent, risk-based approach to information security, maintaining confidentiality, integrity and availability. Its central requirement is that agencies implement an information security management system based on ISO 27001, covering information, application and technology assets.
It is supported by two things worth knowing about:
Compliance runs through an annual return to the Cyber Security Unit, and through assurance obtained by the accountable officer proportionate to the criticality of the information held.
IS18 is not a certification scheme, though it does point agencies toward independent external assessment as the most objective form of assurance.
Entities in Schedule 1 of the Public Sector Act 2022 (Qld) are in scope, along with government entities directed by their shareholding minister or responsible head to apply IS18.
Bodies that must have regard to the QGEA under the Financial and Performance Management Standard 2019 (Qld).
Strongly encouraged to apply the policy as recommended better practice rather than bound by it.
Where obligations flow through contracts, particularly for providers handling classified or critical agency information.
IS18 is risk-based, so the output is a set of justified decisions rather than a checklist.
Departments and Schedule 1 public service entities are in scope. Statutory bodies that must have regard to the QGEA, and entities directed by a shareholding minister or responsible head, also apply it. Other entities including local government are encouraged to adopt it as better practice.
The policy requires an information security management system based on ISO 27001, covering information, application and technology assets. Where ISO 27001 is already held, most of this exists.
The Queensland Government Information Security Classification Framework sets the minimum requirements for classifying information assets and aligns to national approaches including the Commonwealth PSPF where practical. Departments must comply with it.
Queensland has adopted a control effectiveness-based risk approach rather than applying ASD's maturity model rigidly, citing its limited flexibility. Supporting guidance covers how assessments feed whole-of-government reporting.
Accountable officers must obtain assurance appropriate to the criticality of information and assets. The most objective assurance is independent external assessment; lower levels come from management systems, internal assessment and audit.
Entities following IS18 complete the information and cyber security annual return each year, which supports the Cyber Security Unit's whole-of-government view.
For agencies, Soveriq builds the ISMS the policy requires, classifies information assets against the QGISCF, runs the Essential Eight assessment in the control-effectiveness form Queensland uses, and prepares the annual return position.
For suppliers, we establish which obligations flow through your agency contract and build evidence proportionate to them.
Where ISO 27001 is held or in progress, the ISMS requirement is largely satisfied and the work concentrates on classification and Queensland-specific reporting.
On internal review. Where Soveriq has built your management system, we do not then assess it and present that as independent assurance — which matters here, because IS18 explicitly values independent assessment as the most objective form. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve annual returns, does not speak for the Cyber Security Unit, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. It requires agencies to implement an information security management system based on ISO 27001, which is not the same as holding a certificate. Certification is one way to evidence maturity, and some agencies pursue it, but the policy asks for the system rather than the certificate.
Queensland has adopted a control effectiveness-based risk approach when applying the Essential Eight, citing the limited flexibility of ASD's maturity model. Supporting guidance sets out how assessments feed whole-of-government IS18 reporting. The guidance is advisory rather than a mandatory component of the policy.
Yes. Agencies can apply for exceptions from policy or reporting requirements through the QGEA alignment and exception process. Where the departure is from a sub-requirement within a mandated standard — a single control, for instance — agencies can seek sign-off from the accountable officer instead.
Not mandatorily. Other Queensland government entities, including local governments, are strongly encouraged to apply the policy as recommended better practice.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope