GLOBAL SKILLS. AUSTRALIAN DELIVERY.
Security, Privacy & Governance
Least privilege, client-controlled systems, disclosed service locations, and human oversight of AI—designed per engagement.
Required sections
Security principles: least privilege, MFA where supported, role-based access, approved devices, secure remote connectivity.
Data handling: client data remains in client-controlled systems wherever feasible; define any copying/exporting explicitly in contract.
Cross-border access: clearly disclose service locations and overseas access where relevant.
Workstation controls: dedicated devices, endpoint controls, account separation, patching and approved software.
People controls: confidentiality agreements, onboarding/offboarding, access revocation, training and supervision.
Incident response: detection, escalation, containment, client notification and post-incident review.
Business continuity: connectivity redundancy, staffing continuity and recovery procedures.
Privacy: processor/service-provider role where applicable. See the current Australian privacy policy.
AI governance: disclose AI use, model/data boundaries and human oversight per engagement.
Company identifiers such as ABN and legal name are published from Company Settings once registration is finalised. No stale entity number is shown here.
Privacy policyDiscuss your security and governance requirements
Security, privacy and access requirements vary by organisation and engagement. Remote Shifts can work through the relevant controls, data-handling requirements and delivery arrangements before work begins.