St Joseph's School

Contents

Home

Computer Security and Cybersecurity

At St Joseph's School, we manage our school digital, physical, and information assets in a way that is financially responsible and protects personal privacy (Education and Training Act 2020, Privacy Act 2020). We aim to create a secure and safe online school environment and use a range of cybersecurity practices that are appropriate to the needs of our school to protect IT infrastructure, data, and digital resources from unauthorised access (e.g. suspicious or criminal activity). This may include implementing access security measures, firewall and antivirus software, back up strategies, regular system updates and maintenance. We also use a secure and safe internet provider and take measures to safeguard school networks.

The principal and board are responsible for school computer security and cybersecurity and reviewing our procedures at least annually. Staff using school devices (e.g. staff laptops) are expected to take appropriate care of their devices, including storing them securely and maintaining digital security measures.

Access security

We aim to use the principle of least privilege to ensure that access to school accounts is specific to each person's role and responsibilities. We restrict access to personal information or sensitive data (e.g. limiting access to staff who require it as part of their duties, ensuring discussions of sensitive information are confidential). See Personal Information.

All school devices and accounts are password protected and we expect school community members to create, use, and manage passwords securely and keep them confidential.

If staff have a concern that their password has been compromised, they should:

We are guided by Ministry of Education recommendations to implement our access security measures.

Data protection

We aim to maintain the integrity and confidentiality of school information. We regularly back up critical data needed for the day-to-day operations of our school. Back up data is stored in a different location to original data and can be used if something happens to the original (e.g. lost devices, stolen information). This reduces the risk of data loss and helps us to quickly recover information.

We store data for an appropriate length of time. See School Records Retention and Disposal.

We are guided by Ministry of Education recommendations for backing up important school data.

Software security

We take a number of measures to ensure school software settings are managed effectively, including:

We are guided by Ministry of Education recommendations for configuring security settings.

Upgrades and maintenance

As required by the Ministry of Education, when upgrading our ICT network, we:

We also guided by the recommended Ministry of Education process for school-led ICT project upgrades.Our property maintenance plan includes a budget for ICT network maintenance. See ICT network upgrades and maintenance Website link icon (Ministry of Education).

Also see Property Management and Property Maintenance and Repairs.

Managing computer and cybersecurity incidents

Staff, students, and our school community are encouraged to keep alert for cybersecurity concerns and breaches (e.g. checking sender details, acting with caution if emails contain attachments). In the event an incident occurs, we act immediately to minimise distress and harm, safeguard the safety and wellbeing of those affected, and resolve the matter as soon as possible.

Supporting policies

At St Joseph's School, we have other policies that support our approach to computer security and cybersecurity:

Legislation

Resources

Release history: Term 3 2025, Term 4 2022, Term 2 2021

Topic Number: 866

Last Modified Date: 15/08/2025 12:57:18

Topic Version: 1

Published Date: 30/01/2026

 

 

Last review

Term 4 2024

Topic type

Core