AusISA teaches capabilities that can be used for good or ill. This policy sets out your obligation to use what you learn here ethically and lawfully.
This policy sets out the obligations of every participant to use the subject matter taught in AusISA activities in an ethical and lawful way.
Some of the content AusISA teaches, particularly content concerning information operations, intelligence, warfare, Defence, cyber security, and offensive cyber operations, can be applied to both ethical and unethical ends. The content itself is not inherently unethical: it reflects real capabilities, real threats, and real tradecraft that security professionals must understand to defend against and lawfully employ them. What matters is how it is used. This policy governs that use.
This policy applies to all knowledge, skills, techniques, tools, and materials taught, demonstrated, provided, or discussed in any AusISA activity, including courses, workshops, labs, competitions, CTFs, events, and associated materials.
This policy applies to all participants, and continues to apply after an activity ends. The obligation to use taught content ethically does not expire.
This policy applies in addition to the Participant Conduct Policy and the law. Compliance with this policy does not excuse non-compliance with any law, and the law prevails over this policy to the extent of any inconsistency.
Taught Content means any knowledge, skill, technique, procedure, tool, code, dataset, or material acquired through an AusISA activity.
Authorised Engagement means an activity conducted with the informed, lawful authority of the owner of the affected system, network, organisation, or information: for example, a contracted penetration test, an IRAP assessment, an authorised red team exercise, or duties lawfully performed for a government agency.
Dual-Use Content means Taught Content that can serve both defensive/lawful and offensive/unlawful purposes, including content concerning information operations, intelligence tradecraft, warfare, Defence, cyber security, and offensive cyber operations.
Capability carries responsibility: the more powerful the technique, the greater the care its use demands.
Authority before action: capability is exercised only where lawful authority exists.
Australian law and values: Taught Content is used consistently with Australian law and in a manner that does not harm Australia's national interest.
Proportionality and minimisation: even within an Authorised Engagement, participants act within the authorised scope and minimise harm and collateral effect.
Participants must use Taught Content only for lawful purposes.
Participants must not apply offensive techniques (including exploitation, credential attacks, social engineering, malware use, or denial of service) against any system, network, person, or organisation except within an Authorised Engagement, and then only within the authorised scope, timeframe, and rules of engagement.
Participants must not use Taught Content to conduct, support, or enable unauthorised access to or interference with computers or data. Such conduct may constitute an offence under Part 10.7 of the Criminal Code Act 1995 (Cth) and equivalent state and territory law.
Participants must not use Taught Content concerning information operations, influence, or intelligence tradecraft to deceive, manipulate, harass, or target individuals or communities, to interfere in democratic processes, or to conduct disinformation activity.
Participants must not provide, sell, or transfer Taught Content, tools, or tradecraft to any person or entity where the participant knows, or reasonably ought to suspect, that it will be used unlawfully or against Australia's interests, including sanctioned entities, hostile foreign actors, and criminal groups.
Participants must comply with Australian export control and sanctions law where Taught Content or related technology is shared across borders, including the Defence Trade Controls Act 2012 (Cth) and the Defence and Strategic Goods List, and the Autonomous Sanctions Act 2011 (Cth).
Participants who discover a vulnerability, whether in an AusISA environment or elsewhere through the use of Taught Content, must handle it responsibly: report it to the owner (or to AusISA under the Continuous Improvement Policy where it concerns AusISA systems or labs), do not exploit it beyond what is needed to demonstrate it, and do not disclose it publicly before the owner has had a reasonable opportunity to remediate.
Participants holding, or seeking, positions of trust (including security clearances, IRAP endorsement, or Defence industry roles) must recognise that their use of Taught Content reflects on their suitability for those positions, and must conduct themselves accordingly.
Where a participant is unsure whether a proposed use of Taught Content is ethical or lawful, they must not proceed until they have obtained appropriate advice, whether from their organisation's legal or security function, from AusISA, or from independent legal counsel.
A suspected breach of this policy may be reported to AusISA at courses@ausinfosec.academy, and is handled in accordance with the Participant Conduct Policy and the Complaints & Appeals Handling Policy.
Where AusISA reasonably believes Taught Content has been or will be used unlawfully, AusISA may report the matter to police, ASD, or another appropriate authority, and may exclude the person from current and future activities, withhold or revoke certification outcomes issued by AusISA, and notify an Endorsing Entity where certification integrity is affected.
Nothing in this policy limits AusISA's obligations, or any person's obligations, to report suspected crimes or security incidents under applicable law.
Acceptance of this policy is a condition of participation in AusISA activities that include Dual-Use Content.
AusISA may decline enrolment, or apply vetting under the Participant Vetting Policy, where the intended use of Taught Content raises ethical or security concerns.
There are no exceptions to the requirement to act lawfully. Exceptions to other requirements of this policy may be approved in writing by AusISA Administration only where the proposed conduct is lawful and consistent with the principles in section 4.
Participant Conduct Policy (GOV-002); Participant Vetting Policy (GOV-011); Continuous Improvement Policy (GOV-012); Complaints & Appeals Handling Policy (GOV-005); Participant Handbook (GOV-001).
Criminal Code Act 1995 (Cth), Part 10.7 (Computer offences); Defence Trade Controls Act 2012 (Cth) and the Defence and Strategic Goods List; Autonomous Sanctions Act 2011 (Cth); Security of Critical Infrastructure Act 2018 (Cth); Intelligence Services Act 2001 (Cth); state and territory computer offence provisions.
This policy is reviewed at least every 12 months (P-016), and earlier where a legal change, incident, or continuous-improvement finding warrants an out-of-cycle review.