This policy describes the requirements for entities planning digital investments involving hosting. It refers to the facilities that will host government data and systems internally, on premises, or externally, on cloud.
Applicability
Digital investment proposals are assessed against this policy by the DTA through the Digital and ICT Investment Oversight Framework (IOF).
Commonwealth entities are encouraged to apply this policy to all digital investments.
Policy
-
Ensure the secure hosting of security-classified government information and data using certified services and associated infrastructure by applying the Hosting Certification Framework (HCF).
-
Assess data and hosting sensitivities to ensure the suitability of hosting providers.