Skip to main content
NexusGroup Employee Portal

IT & Service Desk

Information assets & security

The information we hold, how sensitive it is, and how to protect it. Classifying information correctly tells you how to handle it.

Workplace context

Before you handle, store or share information, check how it's classified and what that means. Personal and financial information needs extra care. This sits alongside the Information Security policy, the Privacy Policy and the data classification guide.

Classification levels

Public

Approved for sharing outside Nexus Group.

No restrictions — but check it’s the approved version.

Internal

For staff generally; not for people outside Nexus.

Share within Nexus on a work-need basis; don’t post publicly.

Confidential

Limited to those who need it; includes personal information.

Access on a need-to-know basis; store securely; follow the Privacy Policy.

Restricted

Tightly controlled, sensitive or financial information.

Strict access controls; never copy off approved systems; report any exposure.

Information asset register

Asset Classification
Staff contact & employment records Confidential
Customer records & complaints Confidential
Finance transaction records Restricted
WHS incident records Confidential
Service desk tickets Internal
Operations reports Internal
Supplier details Internal
Templates & published policies Public

Access by role

Access is granted on a work-need basis. This shows the usual level for each role.

Role People Hub CRM Finance Service Desk
Support Assistant None Read None Read & write
Team Leader Read Read & write Read Read & write
Manager Read & write Read & write Read Read
IT Service Desk None None None Admin
Finance None Read Admin Read

Protecting information — quick checklist

  • Only open information you need for your work.
  • Lock your screen when you step away.
  • Store work files on approved systems — not personal devices or accounts.
  • Share with specific people, not “anyone with the link”.
  • Use multi-factor authentication and a strong passphrase.
  • Report a lost device or suspected data exposure to the Service Desk straight away.