Information security annual return
On this page
Overview
The Information and cyber security annual return helps the Department of Customer Services, Open Data and Small and Family Business (CDSB) ensure Queensland Government entities are managing information security risks and meeting the requirements of the Information and cyber security policy (IS18).
All entities following IS18 are required to complete and submit this return annually. The return supports whole-of-government situational awareness and enables entities to attest they are implementing appropriate security measures to safeguard government information and systems.
What is required to provide your return
A reporting entity can choose from four different assurance types:
- self-assurance audit
- internal audit
- independent third-party audit
- ISO 27001 certified audit.
The information below summarises what is required for submission of the Information and cyber security annual return for each assurance type.
Submission requirements by assurance type
ISMS assurance audit report | Required |
Attestation from Accountable Officer | Required |
Ongoing incident reports | Required |
Data submission template sections (tabs)
About your entity | Required |
ISMS audit | Required |
Cyber risk | Required |
Required | |
Required | |
Governance context | Required |
Additional documents for ISMS
Supporting documents:
| Required |
ISMS assurance audit report | Required |
Attestation from Accountable Officer | Required |
Ongoing incident reports | Required |
Data submission template sections (tabs)
About your entity | Required, can be provided by self-assurance |
ISMS audit | Required |
Cyber risk | Required, can be provided by self-assurance |
Required, can be provided by self-assurance | |
Required | |
Governance context | Required, can be provided by self-assurance |
Additional documents for ISMS
No additional documents required.
ISMS assurance audit report | Required |
Attestation from Accountable Officer | Required |
Ongoing incident reports | Required |
Data submission template sections (tabs)
About your entity | Required, can be provided by self-assurance |
ISMS audit | Required |
Cyber risk | Required, can be provided by self-assurance |
Required, can be provided by self-assurance | |
Required | |
Governance context | Required, can be provided by self-assurance |
Additional documents for ISMS
No additional documents required.
ISMS assurance audit report | Required |
Attestation from Accountable Officer | Required |
Ongoing incident reports | Required |
Data submission template sections (tabs)
About your entity | Required, can be provided by self-assurance |
ISMS audit | Required |
Cyber risk | Required |
Required, can be provided by self-assurance | |
Required This is likely to be done by the independent third-party ISO 27001 lead auditor as part of the entity’s certification upkeep, however, can be done via any of the assurance types. | |
Governance context | Required, can be provided by self-assurance |
Additional documents for ISMS
- Certification document is required.
Completing and submitting your return
The below steps provide the high-level outline of the submission process.
The Information and cyber security annual return form is provided to nominated representatives within all entities. This form is the starting point for the submission process and will provide the information that is used to facilitate the submissions process.
Important: If your entity is submitting the Information and Cyber Security Annual Returns for the first time, please contact the Cyber Security Unit in CDSB at is18return@cyber.qld.gov.au to request the link to the Information and cyber security annual return form.
Entities must complete and submit the Information and cyber security annual return form.
The form includes basic questions, such as:
- your entity name
- email address of your entity’s IS18 Lead (the person submitting the form)
- name of the Executive who is accountable for information security (i.e. the role that the CIO/CISO reports to e.g. DDG Corporate Services or equivalent).
Once submitted, this form triggers the creation of a private folder for your entity’s submission.
- After the form is submitted, CDSB will automatically create a private folder in the CSU IS18 Annual Return SharePoint using your entity name.
- A share link to this folder will be sent to your IS18 Lead as per the email address provided in the Information and cyber security annual return form.
Important:
- By default, only one person from the entity (the IS18 Lead) will have access to the folder
- If additional entity representatives require access, a written request must be submitted to CDSB by email is18return@cyber.qld.gov.au to grant access.
The IS18 Lead will receive an email containing:
- the link to the private folder
- further guidance on the next steps for the return submission process
- please note, it is the IS18 Lead’s responsibility to monitor their email and to make plans if they are going to be absent.
When endorsed for submission, the IS18 Lead must upload all required documents (as shown in the table above) to the private folder.
Notification to CDSB:
- once all files are uploaded, the IS18 Lead must notify CDSB by emailing is18return@cyber.qld.gov.au.
CDSB will review the submission and send an acknowledgment email to the IS18 Lead within two business days.
During the review, CDSB will check for the following:
- files are named correctly according to the specified format
- the IS18 data submission template spreadsheet must be submitted as a spreadsheet (not as a PDF)
- there are no duplicate files in the folder
- all required evidence for IS18 compliance has been submitted.
- If the submission is incomplete or if any files are missing/incorrect, CDSB will contact the IS18 Lead to:
- request additional information.
- ask for missing files to be uploaded or incorrect files to be reuploaded.
Key points to remember when submitting the Information and cyber security annual return
- Ensure all files are named correctly and submitted in the required format.
- Notify CDSB promptly after uploading your files.
- If additional access to the private folder is needed, submit a written request to CDSB.
Relevant documents and templates
- Data submission template 2026 218.5 KB)
- ISMS Assurance Audit Report ISO 2022 version 386.2 KB)
- Agency information security attestation statement example
- Essential Eight guideline.
Submission deadline
Ensure your annual return is submitted by 30 September.
Need Help?
For assistance or further information, contact the Cyber Security Unit in CDSB at is18return@cyber.qld.gov.au.