Information security annual return

Document type:
Template
Version:
Final v4.0.1
Status:
CurrentNon-mandated
Effective:
August 2026–current
Security classification:
OFFICIAL-Public
Category:
Cyber security

Overview

The Information and cyber security annual return helps the Department of Customer Services, Open Data and Small and Family Business (CDSB) ensure Queensland Government entities are managing information security risks and meeting the requirements of the Information and cyber security policy (IS18).

All entities following IS18 are required to complete and submit this return annually. The return supports whole-of-government situational awareness and enables entities to attest they are implementing appropriate security measures to safeguard government information and systems.

What is required to provide your return

A reporting entity can choose from four different assurance types:

  • self-assurance audit
  • internal audit
  • independent third-party audit
  • ISO 27001 certified audit.

The information below summarises what is required for submission of the Information and cyber security annual return for each assurance type.

Submission requirements by assurance type

ISMS assurance audit report

Required

Attestation from Accountable Officer

Required

Ongoing incident reports

Required

Data submission template sections (tabs)

About your entity

Required

ISMS audit

Required

Cyber risk

Required

QGEA mandatory frameworks
(QGISCFQGAFDES)

Required

Essential Eight

Required

Governance context

Required

Additional documents for ISMS

Supporting documents:

  • Information security policy
  • Statement of Applicability (SoA)
  • Information security objectives
  • ISMS scope / documentation that   includes ISMS Scope
  • Risk appetite and risk tolerance   documentation
  • Risk assessment and treatment methodology
  • Risk treatment plan
  • Risk register

Required

ISMS assurance audit report

Required

Attestation from Accountable Officer

Required

Ongoing incident reports

Required

Data submission template sections (tabs)

About your entity

Required, can be provided by self-assurance

ISMS audit

Required

Cyber risk

Required, can be provided by self-assurance

QGEA mandatory frameworks
(QGISCF, QGAF, DES)

Required, can be provided by self-assurance

Essential Eight

Required

Governance context

Required, can be provided by self-assurance

Additional documents for ISMS

No additional documents required.

ISMS assurance audit report

Required

Attestation from Accountable Officer

Required

Ongoing incident reports

Required

Data submission template sections (tabs)

About your entity

Required, can be provided by self-assurance

ISMS audit

Required

Cyber risk

Required, can be provided by self-assurance

QGEA mandatory frameworks
(QGISCF, QGAF, DES)

Required, can be provided by self-assurance

Essential Eight

Required

Governance context

Required, can be provided by self-assurance

Additional documents for ISMS

No additional documents required.

ISMS assurance audit report

Required

Attestation from Accountable Officer

Required

Ongoing incident reports

Required

Data submission template sections (tabs)

About your entity

Required, can be provided by self-assurance

ISMS audit

Required

Cyber risk

Required

QGEA mandatory frameworks
(QGISCF, QGAF, DES)

Required, can be provided by self-assurance

Essential Eight

Required

This is likely to be done by the independent third-party ISO 27001 lead auditor as part of the entity’s certification upkeep, however, can be done via any of the assurance types.

Governance context

Required, can be provided by self-assurance

Additional documents for ISMS

  • Certification document is required.

Completing and submitting your return

The below steps provide the high-level outline of the submission process.

The Information and cyber security annual return form is provided to nominated representatives within all entities. This form is the starting point for the submission process and will provide the information that is used to facilitate the submissions process.

Important: If your entity is submitting the Information and Cyber Security Annual Returns for the first time, please contact the Cyber Security Unit in CDSB at is18return@cyber.qld.gov.au to request the link to the Information and cyber security annual return form.

Entities must complete and submit the Information and cyber security annual return form.

The form includes basic questions, such as:

  • your entity name
  • email address of your entity’s IS18 Lead (the person submitting the form)
  • name of the Executive who is accountable for information security (i.e. the role that the CIO/CISO reports to e.g. DDG Corporate Services or equivalent).

Once submitted, this form triggers the creation of a private folder for your entity’s submission.

  • After the form is submitted, CDSB will automatically create a private folder in the CSU IS18 Annual Return SharePoint using your entity name.
  • A share link to this folder will be sent to your IS18 Lead as per the email address provided in the Information and cyber security annual return form.

Important:

  • By default, only one person from the entity (the IS18 Lead) will have access to the folder
  • If additional entity representatives require access, a written request must be submitted to CDSB by email is18return@cyber.qld.gov.au to grant access.

The IS18 Lead will receive an email containing:

  • the link to the private folder
  • further guidance on the next steps for the return submission process
  • please note, it is the IS18 Lead’s responsibility to monitor their email and to make plans if they are going to be absent.

When endorsed for submission, the IS18 Lead must upload all required documents (as shown in the table above) to the private folder.

Notification to CDSB:

CDSB will review the submission and send an acknowledgment email to the IS18 Lead within two business days.

During the review, CDSB will check for the following:

  • files are named correctly according to the specified format
  • the IS18 data submission template spreadsheet must be submitted as a spreadsheet (not as a PDF)
  • there are no duplicate files in the folder
  • all required evidence for IS18 compliance has been submitted.

  • If the submission is incomplete or if any files are missing/incorrect, CDSB will contact the IS18 Lead to:
    • request additional information.
    • ask for missing files to be uploaded or incorrect files to be reuploaded.

Key points to remember when submitting the Information and cyber security annual return

  • Ensure all files are named correctly and submitted in the required format.
  • Notify CDSB promptly after uploading your files.
  • If additional access to the private folder is needed, submit a written request to CDSB.

Relevant documents and templates

Submission deadline

Ensure your annual return is submitted by 30 September.

Need Help?

For assistance or further information, contact the Cyber Security Unit in CDSB at is18return@cyber.qld.gov.au.