When and how participants are vetted for courses, events, and competitions, what vetting can and cannot be based on, and what happens if you are not accepted.
This policy sets out how participants may be vetted for AusISA courses, events, competitions, and activities, the basis on which vetting decisions are made, and the rights of a person affected by a vetting decision.
This policy applies to any AusISA activity for which eligibility criteria, vetting, or an invitation applies, including courses, events, competitions, and other activities.
This policy applies to prospective participants, applicants, and any person seeking access to a gated or vetted activity.
This policy must be read with the Privacy Policy, which governs the handling of personal information collected for vetting, and the Complaints & Appeals Handling Policy.
This policy operates subject to applicable Australian law, which prevails to the extent of any inconsistency.
Vetting means the assessment of a prospective participant against stated criteria before access to an activity is granted.
Vetting Criteria means the requirements a person must meet to be accepted into a vetted activity.
Gated or Vetted Activity means an activity to which access is conditional on meeting Vetting Criteria, holding an invitation, or both.
Controlling Party means an organisation other than AusISA that controls, endorses, or imposes requirements on an activity, including the Australian Signals Directorate (ASD), the Department of Defence, and other government agencies.
Protected Attribute means a personal characteristic protected under Australian anti-discrimination law, as described in clause 6.2.
Vetting is purposeful: every criterion exists for a reason connected to the course or event: its content sensitivity, legal requirements, safety, security, or the integrity of an endorsement pathway.
Vetting is transparent: the criteria for a vetted activity are clearly expressed to prospective participants before or at the point of application.
Vetting is lawful and non-discriminatory: vetting is never based on a Protected Attribute.
Vetting decisions are explainable: a person refused under vetting is always told why.
AusISA may apply vetting to any course, event, competition, or activity where the nature of the content, the audience, a legal obligation, or a Controlling Party's requirement makes it appropriate.
The Vetting Criteria for an activity must be clearly expressed in the published information for that activity, or provided to the prospective participant during the application process.
Some courses and events are invite-only. An invitation may be required in addition to, or instead of, published Vetting Criteria, and AusISA is not obliged to issue an invitation to any particular person.
Vetting requirements may be imposed by Controlling Parties that control or endorse a course or event, such as ASD, Defence, or other government agencies, and AusISA must apply those requirements as a condition of running the activity. Where a Controlling Party imposes a requirement, AusISA will identify that the requirement originates with the Controlling Party wherever it is able to do so.
Vetting may include verification of identity, citizenship, professional certifications, employment or professional background, security clearance status, sanctions or watchlist screening required by a Controlling Party, and references or evidence supplied by the applicant.
Evidence provided for vetting is collected, stored, and retained in accordance with the Privacy Policy and the Record Management Policy, and is used only for the vetting decision and any review of it.
Vetting decisions are never based on a Protected Attribute.
Protected Attributes under Australian law include race, colour, descent, national or ethnic origin, and immigrant status (Racial Discrimination Act 1975 (Cth)); sex, sexual orientation, gender identity, intersex status, marital or relationship status, pregnancy, breastfeeding, and family responsibilities (Sex Discrimination Act 1984 (Cth)); disability, including physical, intellectual, psychiatric, sensory, and neurological disability and disease (Disability Discrimination Act 1992 (Cth)); and age (Age Discrimination Act 2004 (Cth)). Additional attributes (including religion, political opinion, trade union activity, and criminal record in some circumstances) are protected under the Australian Human Rights Commission Act 1986 (Cth), the Fair Work Act 2009 (Cth), and state and territory anti-discrimination legislation, including:
Discrimination Act 1991 (ACT);
Anti-Discrimination Act 1977 (NSW);
Anti-Discrimination Act 1992 (NT);
Anti-Discrimination Act 1991 (Qld);
Equal Opportunity Act 1984 (SA);
Anti-Discrimination Act 1998 (Tas);
Equal Opportunity Act 2010 (Vic);
Equal Opportunity Act 1984 (WA).
Vetting may lawfully be based on citizenship, language comprehension, professional background, or personal experiences, where that criterion is a genuine requirement of the course or event. For example: Australian citizenship is required by ASD for IRAP assessor endorsement, so citizenship is a criterion for courses on that pathway; a course delivered and assessed in English may require sufficient English comprehension to participate safely and be assessed fairly; a masterclass may require demonstrated professional experience in the relevant field; and an activity handling sensitive scenarios may consider relevant personal or professional experience.
Where a criterion could correlate with a Protected Attribute (for example, language comprehension), AusISA applies it only to the extent genuinely required by the activity, and considers reasonable adjustments that would allow participation without compromising the purpose of the criterion.
Nothing in this policy prevents AusISA from taking special measures permitted by law to promote equal opportunity.
Where a person is prevented from taking a course or participating in an event because of a vetting decision, AusISA will always clearly articulate the reason for the decision to that person.
The reason given will be purposeful: it will identify the specific criterion of the course or event that was not met, and why that criterion exists.
Where the decision was made by, or required by, a Controlling Party, AusISA will say so, and will identify the Controlling Party where it is permitted to do so.
Where a vetting refusal occurs after payment, the participant is refunded in accordance with the Fees, Refunds & Cancellations Policy (in full, subject to any disclosed non-refundable transaction costs).
A vetting refusal for one activity does not automatically exclude a person from other AusISA activities.
Prospective participants are always welcome to contact AusISA where they do not agree with a vetting decision, at courses@ausinfosec.academy. AusISA will review the concern, correct any factual error, and explain the outcome. A vetting refusal with a reviewable reason may be appealed under the Complaints & Appeals Handling Policy, except where the decision is owned by a Controlling Party, in which case AusISA will refer or assist with referral where appropriate.
Vetting criteria, decisions, and reasons are recorded in accordance with the Record Management Policy.
AusISA Administration reviews vetting criteria for each activity before publication to confirm each criterion is purposeful and lawful.
Any exception to a Vetting Criterion must be approved in writing by AusISA Administration, and cannot be granted where the criterion is imposed by a Controlling Party or by law.
Participant Handbook (GOV-001); Fees, Refunds & Cancellations Policy (GOV-009); Privacy Policy (GOV-013); Record Management Policy (GOV-006); Complaints & Appeals Handling Policy (GOV-005); Ethical Use Policy (GOV-010).
Racial Discrimination Act 1975 (Cth); Sex Discrimination Act 1984 (Cth); Disability Discrimination Act 1992 (Cth); Age Discrimination Act 2004 (Cth); Australian Human Rights Commission Act 1986 (Cth); Fair Work Act 2009 (Cth); state and territory anti-discrimination Acts listed in clause 6.2; Privacy Act 1988 (Cth); IRAP Policy and Procedures (ASD).
This policy is reviewed at least every 12 months (P-016), and earlier where a legal change, Controlling Party requirement, or continuous-improvement finding warrants an out-of-cycle review.