Our commitment to keeping courses current, relevant, and correct, and how to report errors, issues, or vulnerabilities you find, which we genuinely welcome.
This policy sets out AusISA's commitment to the continuous improvement of its courses, events, content, and operations, and establishes how anyone can report errors, issues, vulnerabilities, or other problems with training or content.
This policy applies to all AusISA courses, events, competitions, content, platforms, and supporting operations.
This policy applies to reports and feedback from any source: participants, facilitators, staff, partners, Endorsing Entities, and members of the public.
This policy must be read with the Complaints & Appeals Handling Policy: a report seeking a remedy or review for the reporter is a complaint and is handled under that policy; a report identifying something to fix or improve is handled under this policy.
Currency: improvement is undertaken continuously so that courses and events remain current, relevant, and up to date, including alignment with the latest versions of the frameworks AusISA teaches, such as the ISM, PSPF, Essential Eight, and IRAP policy and assessment frameworks.
Career value: the goal of continuous improvement is that participants gain contemporary skills that build their careers, not skills that were current when a course was first written.
Openness: any error, issue, vulnerability, or other problem with training or content can be reported, and such reports are welcomed under this policy. A good-faith report is a contribution, not a criticism.
No blame: reports are handled on a no-blame basis focused on fixing the issue, and no one will suffer detriment for making a good-faith report.
Feedback loop: reporters who identify themselves are told what happened as a result of their report.
Course owners must review their courses for currency and accuracy at least annually, and promptly when a framework the course teaches is updated.
Facilitators must report content errors, lab issues, and delivery problems they encounter, and must pass on improvement suggestions raised by participants during delivery.
AusISA Administration must maintain the improvement register, triage incoming reports, and track actions to closure.
Leadership must review improvement trends, complaint trends, and survey data periodically and direct resources to systemic issues.
AusISA draws improvement from: end-of-course and end-of-event surveys; participant feedback and reports made under this policy; facilitator debriefs and post-activity reviews; complaint and appeal trends; assessment and moderation outcomes; changes to the frameworks, law, and threat landscape the courses cover; and input from Endorsing Entities and industry partners.
Every input is triaged, recorded in the improvement register, and either actioned, scheduled, or closed with a reason.
Anyone may report an error, issue, vulnerability, or other problem with AusISA training, content, platforms, or operations. Reports are welcomed; they make the training better for everyone who follows.
Reports may be made through the reporting form on this page, or by email to courses@ausinfosec.academy.
Reports may be made anonymously. An anonymous report will still be triaged and actioned, but AusISA cannot provide feedback on the outcome or seek clarification.
Reports of security vulnerabilities in AusISA lab environments, platforms, or infrastructure are prioritised. Vulnerability reporters must follow responsible disclosure: report privately through the channels in clause 6.2, do not exploit the vulnerability beyond what is needed to demonstrate it, and do not disclose it publicly before AusISA has had a reasonable opportunity to remediate. The Ethical Use Policy applies.
AusISA will acknowledge a non-anonymous report within 3 business days (P-001), triage it within 5 business days (P-002), and tell the reporter the outcome once the matter is closed.
A report that is really a complaint (one seeking a remedy, review, or investigation for the reporter) will be redirected into the Complaints & Appeals Handling Policy, and the reporter told.
Confirmed content errors are corrected in the source material, and corrections that affect a live cohort are communicated to that cohort.
Where an error affected an assessment, AusISA reviews affected results under the Assessment Policy and corrects any outcome that the error made wrong.
Confirmed vulnerabilities are remediated with priority proportionate to their severity, and lessons are fed back into course and lab design.
Systemic issues, meaning those appearing across multiple reports, complaints, or cohorts, are escalated to leadership with a proposed corrective action.
The improvement register records each report, its triage outcome, the action taken, and the closure date, in accordance with the Record Management Policy.
AusISA Administration reports improvement activity and trends to leadership periodically.
The operation of this policy is itself reviewed as part of the annual policy review cycle.
Complaints & Appeals Handling Policy (GOV-005); Assessment Policy (GOV-004); Ethical Use Policy (GOV-010); Record Management Policy (GOV-006); Participant Handbook (GOV-001).
Information Security Manual (ASD); Protective Security Policy Framework; ASD Essential Eight Maturity Model; IRAP Policy and Procedures (ASD); ISO 9001:2015 (Quality management systems) as informative guidance.
This policy is reviewed at least every 12 months (P-016), and earlier where a systemic issue or framework change warrants an out-of-cycle review.
Found something wrong? A content error, a broken lab, a vulnerability, or anything else worth fixing can be reported here. Reports are welcomed under clause 3.3 of this policy. Name and email are optional; include them if you would like to hear the outcome.