[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-164440-105":53,"doc-detail-164440-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","the-five-step-action-plan-step-1","The Five Step Action Plan - Step 1","","The document outlines the Five-Step Action Plan for securing information assets in Victorian public-sector organisations and explains how Step 1 fits within the Victorian Protective Data Security Framework and Standards. It describes the legal and practical need for disciplined information security management under the PDP Act. Step 1 focuses on identifying information assets through an information review and establishing an Information Asset Register (IAR), enabling effective future risk assessments and protection actions.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":11,"@type":70,"position":76},"https://docshare.wps.com/template/presentations/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/the-five-step-action-plan-step-1/164440/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/the-five-step-action-plan-step-1/164440.png","ImageObject",442,249,{"name":88,"@type":89},"Terk","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-20","2026-08-31",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",6,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What is the purpose of the Five-Step Action Plan overview?","Question",{"text":109,"@type":110},"It provides an overview of the Five-Step Action Plan and explains how it relates to the Victorian Protective Data Security Framework and Standards.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"Who is the intended audience for this document?",{"text":114,"@type":110},"It targets VPS organisations, including employees, contractors, and external parties covered by Part 4 of Victoria’s PDP Act, supporting executives and information security practitioners.",{"name":116,"@type":107,"acceptedAnswer":117},"What does Step 1 require for identifying information assets?",{"text":118,"@type":110},"Step 1 requires performing an information review to discover information assets and establishing an Information Asset Register (IAR) to centrally record and manage them.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},164440,1788153371,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":8,"category_name":11,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":136,"language":137,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":138,"faqs":139,"seo_title":140,"seo_description":61,"update_tm":126,"read_time":76},1099525198933,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","Information Security\nThe Five Step Action Plan\nVictorian Protective Data Security Framework\nVersion Information\n© State of Victoria (Office of the Victorian Information Commissioner) 2017 - 2020\nThis work, Overview of the Framework and Five Step Action Plan, is licensed under a Creative Commons Attribution 4.0 licence. You are free to re-use the work under that licence, on the condition that you credit the State of Victoria (Office of the Victorian Information Commissioner) as author, indicate if changes were made and comply with the other licence terms. The licence does not apply to any branding, including the Victorian Government logo and the Office of the Victorian Information Commissioner logo.\nCopyright queries may be directed to \u0013 HYPERLINK \"mailto:enquiries@ovic.vic.gov.au\" \\h \u0014enquiries@ovic.vic.gov.au\u0015\nBackground\nThe secure management of information is critical to Government service delivery, public trust, and confidence. In 2014, the Privacy and Data Protection Act (PDP Act) was passed by the Parliament, ushering in Australia’s first broad-based legislated information security requirements.\nThe PDP Act significantly changed the information security regulatory landscape, empowering the Victorian Information Commissioner to:\ndevelop the Victorian Protective Data Security Framework (the Framework) for monitoring and assuring public sector data security; and\nissue the Victorian Protective Data Security Standards (the Standards).\nThe Framework and Standards have been developed to help Victorian public-sector organisations:\nidentify information assets,\nassess the value of information,\nidentify and manage information security risks,\napply security measures,\ncreate a positive security culture, and\nmature their information security capability.\nTo assist organisations in meeting the requirements of the Framework and Standards, OVIC has developed a five-step action plan that sets out practical activities designed to assist in managing information security risks.\nPurpose\nThis document provides an overview of the Five-Step Action Plan and explains its relationship to the Framework and Standards.\nAudience\nThis document is intended for VPS organisations (including employees, contractors, and external parties) that are subject to the protective data security provisions under Part 4 of Victoria’s PDP Act. This document is primarily written to inform executives and designed to support information security practitioners.\nWhat is the Five-Step Action Plan?\nThe Five-Step Action Plan presents a risk-based approach to securing information assets in a logical and staged manner, whilst meeting the requirements of the Framework and Standards.\nSome organisations will have existing business practices or programs of work that complement the activities set out in the Five-Step Action Plan.\nStep 1:\nIdentify the organisation’s information assets\nAn essential first step in establishing an information security program, is identifying the organisation’s information assets. Simply put: you cannot protect what you do not know.\nStep one helps prompts an organisation to:\nconduct an information review, where they survey of their information holdings to discover all their information assets; and\nestablish an Information Asset Register (IAR) where information assets can be centrally recorded and managed.\nOrganisations who complete this step will have a central record of the organisation’s information assets that not only promotes good but also acts as an essential input in any future risk assessments.\nStep 2:\nDetermine the security value of information assets\nBusiness Impact Levels (BIL) are a common assessment tool used by VPS organisations to determine the security value of public sector information. BILs also inform the protective marking needed for certain types of public sector information.\nAssessing information in a standardised manner means VPS organisations can collaboratively articulate and manage information security risks.\nThe standardised BIL ass","cbCaiaKa9WiZ40DA","https://ap.wps.com/l/cbCaiaKa9WiZ40DA","docx",246931,9,"English","# Background\n# Purpose\n# Audience\n# What is the Five-Step Action Plan?\n# Step 1: Identify the organisation’s information assets\n## Establishing an information security program\n## Information review and Information Asset Register (IAR)","[{\"question\":\"What is the purpose of the Five-Step Action Plan overview?\",\"answer\":\"It provides an overview of the Five-Step Action Plan and explains how it relates to the Victorian Protective Data Security Framework and Standards.\"},{\"question\":\"Who is the intended audience for this document?\",\"answer\":\"It targets VPS organisations, including employees, contractors, and external parties covered by Part 4 of Victoria’s PDP Act, supporting executives and information security practitioners.\"},{\"question\":\"What does Step 1 require for identifying information assets?\",\"answer\":\"Step 1 requires performing an information review to discover information assets and establishing an Information Asset Register (IAR) to centrally record and manage them.\"}]","The Five Step Action Plan - Step 1 | DOCX"]