Security and Confidentiality Specifications

Physical Security    Information Security    Personnel Security    Confidentiality

Physical Security

Limited Entry
Only authorised personnel can enter the operations of McNair yellowSquares, there is a pin-number lock on the main doors at all times.  Visitors must be accompanied at all times by a senior staff member.

Server Room
The Server is protected by an APC UPS system in event of electricity failure. Servers, firewall, routers and switches are located in a locked server room.

Clear Desk/ Clear Screen
Respondent identity coding means that identifiable confidential information is limited in hardcopy format.  At the end of the day all printed sensitive information is cleared from desks and securely stored. Visible sensitive information is protected from view when desks are temporarily vacated and screen locking occurs following 15 minutes of inactivity.

Cross Cut Shredder
Rexel Auto Stacker 100x High Security Shredder Particle/Cut Size: 1.9 x 15 mm Micro cut.

Shredding Service

Recyclable material is confidentially handled by Iron Mountain, a service which certifies that all materials received are confidentially handled and shredded and that shredded material is recycled.

All retired electronic equipment is securely destroyed/recycled in an environmentally friendly way as arranged by Sensible Business Solutions (IT provider).

Information Security

Cyber Security
McNair yellowSquares has an Information Security Management System (ISMS), which includes risk assessment, operational planning and control, training and awareness, and monitoring.  The objectives of the ISMS are availability, integrity and confidentiality, with measurable KPIs for each. McNair yellowSquares ISMS Manual includes the following policies related to information security: Information Security, Acceptable Use, Access Control, and the ISMS Manual.  McNair yellowSquares ISO27001 certification is valid to April 2026.

Operating Software
McNair utilise operating system software Microsoft Office 365, SharePoint to securely organize and access information, and multi factor password authentication (Authy) to uniquely identify users.  Working files are stored in the cloud within SharePoint, restricted to Executive staff only.

Network Security

All data traffic entering the local McNair yellowSquares network passes through a firewall (Sophos XGS 126).   NAS (Network-attached storage) is HITACHI 3.5IN 6TB 7.2K SATA 6GB/S ENTERPRISE HDD.

Remote login to the Windows Server (HPE ML350 Gen10 4210R 1P 16G 8SFF Svr running Windows Server 2019) is restricted by username and complex password via separate VPN system on a separate secure device. Network server is restricted to Executive staff and allows access to archived files only.  All such traffic is encrypted. Updating and patching is managed by Sensible Business Solutions (Our ISO27001 accredited IT support provider).  Complex passwords are enforced within the McNair yellowSquares local domain. All computers with connection rights run an Internet Security Suite at all times, including behavioural analysis and automatic blocking of known untrusted domains.  All computers at McNair yellowSquares are password protected.  Interviewers have an IP protected login access to the survey system.

Disaster Recovery

Telephones can switch to 3CX numbers.  This is also available for remote interviewers who use 3CX lines. Further 3CX lines can be set up within this system within 24 hours, if required.

In compliance with ISO27001 certification an annual Incident Response and Disaster Recovery Plan and Audit is conducted.  Last conducted May 2023.

Secure Storage Backups

McNair maintains a multi-layered backup and recovery framework to protect business and research data and ensure continuity of operations.

Daily backups are performed using Veeam backup software. These backups are stored on local network-attached storage (NAS) and within McNair’s hosted Sensible Cloud environment. Backups are retained within a secure Sydney-based data centre and are used solely for data recovery and business continuity purposes. Backups are not replicated or stored outside the data centre.

In addition, Microsoft 365 data (including email and collaboration content) is backed up using Datto SaaS Protection for Microsoft 365. Datto provides cloud-based backup with built-in AES 256-bit encryption for data at rest and in transit. Access to backed-up data is governed by strict role-based controls and the principle of least privilege. Datto SaaS Protection is aligned with recognised security and compliance frameworks, including SOC 1 (SSAE 16) and SOC 2 Type II reporting standards, and supports GDPR and HIPAA-aligned controls.

All backup systems are managed by McNair’s IT service provider and are subject to documented access controls, operational monitoring, and incident response procedures. Backup processes form part of McNair’s broader information security and business continuity framework, which is reviewed regularly and audited as part of McNair’s ISO 20252:2019 certification.

Information Security Document
McNair continually assess risk and review security policies.  The Information Security Document Classification Policy outlines levels of documents controlled by password security.

Encryption
McNair yellowSquares documents its encryption policy and key management policy within the McNair yellowSquares ISMS Manual.  All data transmitted over the internet from any McNair yellowSquares systems must be encrypted whilst in transit.  McNair yellowSquares ensures its software vendors encrypts all data at rest.  All data in transit to, from and internally is encrypted using TLS (Transport Layer Security) 1.2+ to establish an encrypted link between a web server and a browser to ensure that all data passed between the web server and browsers remain private and integral.

Secure Transfer of Sensitive data

Information is identified indicating the level of risk.  Transfer of digital products which are sensitive (confidential to the client) or identified as high level (ie containing personal data) will be protected during transfer, use, retention, and storage.  Secure storage inclusive of all formats and locations in which the information may be held is addressed within these specifications. McNair will ensure information security controls are in place that are administrative, technical and physical as outlined in this table.

The preferred methods of secure transfer are via SharePoint or via secure File Transfer Protocol.  If transfer is required by email, data will be encrypted.

Offsite Operation

All laptops or tablets issued for offsite work have a password for accessing survey software.

Security procedures for offsite network access are in place including:

  • Password protected email access and use of Microsoft Exchange Security Certificates;
  • Password protected access to servers;
  • and WEP WSK protected Wireless.

Survey Software Security (IDSurvey)

IDSurvey data security measures follow ENISA (European Union Agency for Cybersecurity) standards and implement security policies.  The server vendor that hosts on-cloud installations (OVH) is ISO27001 certified.  SSL Security, Safe connections with https protocol, Redundant servers, Advanced balancing system of ARR load, Up-time service 99,99%, Up-time storage 99,999999999%, GDPR compliant. IdSurvey is compliant with the WCAG 2.1 accessibility standard.

All McNair yellowSquares IDSurvey survey sites and data are held on a Cloud Server located in a secure Equinix data centre in Alexandria, NSW. It is monitored 24 hours x 7 days. It has been configured to only publicly allow http and https traffic. The data centre is certified SOC1 – Type II, PCCI-DSS, SOCT2 – Type II, ISO27001.  The environment is protected by a managed Cisco Firewall.  IPSec VPN to McNair office (if required).  1 Public IP per server.  1gig Network Access.  No hard bandwidth limits (fair use does apply).  Nightly Onsite Backup

Packets are inspected and any prohibited requests are stopped at the firewall. All servers are backed up daily with a full backup. This process is managed and monitored 24x7.

Survey Software Security (WebSurveyCreator/ MySpeak)

All WebSurveyCreator survey sites and data are stored in a Google Cloud Platform data centre located in Sydney, NSW. Google Cloud Platform is certified SOC1/2/3 ISO 27001, 27017, 27018, PCCI-DSS, CSA-STAR.  Servers are run behind a GCP firewall. It has been configured to only publicly allow https traffic. Http traffic is forwarded to Https. Prohibited traffic is stopped at the firewall. All servers are backed up daily. This process is managed and monitors 24x7. Access to any McNair yellowSquares’ server is restricted to key programming staff who hold a unique complex password for each of the 3 remote servers. Passwords have a limited lifespan. All data is encrypted at rest using industry standard best practice. All labels and field descriptors are stored as ID numbers on the SQL server and give no clues to content or meaning.

All MySpeak survey sites and data are hosted on Amazon Web Services (AWS) in Australia.  AWS has ISO27001 compliance.

Personnel Security

Access to Australian Government Resources (as applicable)
McNair yellowSquares agree to comply with the Government’s policies, standards, protocols and guidelines that safeguard Department resources from harm.  McNair will seek agreement from their personnel granted access to Department resources to comply with the Government’s policies, standards, protocols and guidelines as outlined by the Australian Government’s Protective Security Policy Framework and any additional Security Instructions issued by the Department.

Interviewer Security
Interviewers are casual employees of McNair and are bound by various conditions of employment, including a confidentiality agreement.  Telephone interviewers have a protected login access to the survey system. All transactions are logged, including every time that a respondent record is logged.  Information tracked includes the time, the person accessing the record, and the transaction undertaken – such as looking at a record, altering a record etc.

Hiring Personnel
McNair’s assurances regarding suitability of personnel and the recruitment and training of interviewing personnel, including the requisite signed agreement to confidentiality stipulations is outlined within these specifications. Specific security undertakings for a project are addressed during briefing, including undertakings for respondent information and authorised access to resources.  Checks for Australian citizenship are undertaken via the provision of Medicare card and/or driver’s licence evidence which is kept on file.  If this cannot be provided both passport and relevant visa are required to be shown and the visa is verified via the Department of Home Affairs website.  Additional training and security checks for staff, are addressed as required.  Executive staff complete regular cybersecurity training conducted by our ISO27001 accredited IT provider, Sensible Business Solutions.

Hiring Personnel Departing Personnel
McNair yellowSquares applies considerable care to the selection of interviewing personnel experienced in dealing with sensitive privacy issues.  Controls that limit access to specific personnel with need, and denying access to departing personnel, are also implemented.

Confidentiality

ISO 20252:2019

McNair yellowSquares has meaningful mechanisms in place to ensure security standards applicable to market and social research by operating a management system which complies with the requirements of ISO 20252:2019.  McNair’s current certification is valid until August 2026.  ISO 20252:2019 demands adherence to the highest quality standards required to achieve accuracy and completeness of information and controls processing methods that will safeguard the integrity of information.

Information supplied by clients for project purposes will only be used by McNair yellowSquares in the context for which it was supplied.  Identifiable participant data are confidential and all assurances given to participants shall be fulfilled.  McNair yellowSquares requests that clients confirm that use of databases/contact lists provided conform to industry codes.

Privacy Act

McNair yellowSquares is committed to compliance with principles and legislations governing the research industry through adherence to codes and standards of The Research Society and to the Privacy Act and Principles.  McNair Privacy Policy is publicly available via their website, www.mcnair.com.au and has been amended to include a statement regarding the Privacy Amendment (Notifiable Data Breaches) Act 2017.

Policies have also been implemented to enable compliance with the Cybercrime Act (2001) and Spam Act (2003).

Risk
When designing research McNair yellowSquares will include assessment for inconvenience, discomfort or harm and will be sensitive to the welfare and interests of participants.  McNair has a Risk Management Plan, reviewed regularly, which includes risk mitigation for business continuity, confidentiality and security, privacy and participant harm, compliance with legal and ethical requirements, and work health and safety.  McNair also considers risk associated with individual projects and monitors critical planning, delivery of research methodologies, milestones, and reporting to ensure conformance with agreed specifications and the ISO20252:2019 standard.

Respondent Reassurance
All approaches to respondents include a brief description of the principles of respondent confidentiality, the general research purposes for which the data may be used and advice that co-operation is voluntary in compliance with ISO 20252 and The Research Society Code of Professional Behaviour.

De-Identifying Data
On completion of surveys a database of results is created which removes personal identifiers, unique variables and descriptive variables that would allow an identity to be inferred.

Qualitative Research
Personal data about any individual participants cannot be used.  Recordings can only be used for internal research purposes unless otherwise agreed with the participant.

Interviewer Training
McNair yellowSquares has in place policies and procedures for training, observations, appraisals and validations of supervisors and fieldworkers, including obligations regarding confidentiality, in accordance with the requirements of accreditation under ISO 20252 and the Privacy Act.  Additional training is provided for interviewers or supervisors who require further expertise in specific interviewing methods including trauma training for dealing with trauma and torture survivors. Translating ability is tested by a native speaker.  Additional checks are undertaken as appropriate, including Working With Children and police checks. Training for interviewers is continuous with a five-minute training session prior to the commencement of the daily interviewing shift, and including subjects regarding privacy, accuracy, cybersecurity and respect.

Interviewer Briefing
Briefing sessions by senior staff reiterate for interviewers the responsibility for protecting confidentiality, integrity and availability of participant details and any related data sets in line with McNair yellowSquares Privacy Policy and the Privacy Act 1988.

Validations
All interviewing is fully supervised and regular monitoring of calls either via live monitoring, listening to recordings, or call-backs is performed in compliance with ISO 20252.  Validation records are kept in compliance with ISO 20252 and verified by ISO 20252 surveillance audits.

Confidentiality Deeds
All employees sign confidentiality agreements upon commencement, and this is verified by ISO 20252 certification and audits.

Content last updated: February 2026