Systems and Services Upgrade & Application Security Improvement Programs

Welcome to the Systems and Services Upgrade Program
and Application Security Improvements Program Hub.

The Systems and Services Upgrade Program and Application Security Improvements Program have been established to ensure a targeted and proactive response to delivering on key priorities of the UQ Technology Masterplan.

The Application Security Improvement Project  focuses on enhancing the security of key applications by conducting risk assessments, implementing prioritized controls, and providing training to application owners.

The Digital Inclusive Design Project focuses on embedding accessibility and inclusive design principles across UQ’s digital platforms in alignment with WCAG standards to ensure equitable and user-friendly experiences for all. 

The Systems and Services Upgrade Program involves working with service leads and business owners to understand areas for improvement and enhancement in their current infrastructure, supporting the enablement of key outcomes

About the Application Security Improvement Project 

Ensuring UQ has effective security measures for its key applications is vital and the program builds upon the extensive investment in IT infrastructure and identity security controls which have taken place across recent years.

Cyber security is everyone’s business. Find out more about UQ's Cyber Security Strategy

The Application Security Improvements Project will work to secure the University’s key applications by performing risk assessments and based on these, executing a prioritised programme of control implementation in alignment with the Application Security Standard.
 

Focus Areas:

  1. Develop a comprehensive list of web and client-server applications in use at UQ, identifying technical, business and service owners and classifying applications into High, Medium, and Low risk categories. 
  2. Communicate responsibilities to application owners and providing suitable training and guidance.
  3. Complete compliance and risk assessments for high and medium risk applications and remediate high severity vulnerabilities and control weaknesses. 
  4. Address gaps in existing application control capabilities so they can be deployed across existing applications and/or applied as applications are acquired and or developed.
  5. Deploy controls to applications as required by the Application Security Standard, prioritising higher risk applications. 
  6. Support transition to application lifecycle processes that permits an adequate level of security to be sustained by:  
    1. Develop a model of the level of required resourcing, related to the size and complexity of the application landscape.
    2. Identify and implement tools and processes to optimise security management of applications. 

 

About the Digital Inclusive Design Project 

The Digital Inclusive Design Project is focused on strengthening accessibility and inclusivity across UQ’s digital ecosystem. The project aims to embed Universal Design and Inclusive Design principles into every stage of application development, maintenance, and procurement. This ensures not only technical compliance but also equitable, intuitive access for all users. 

Our approach is grounded in internationally recognised accessibility standards, with WCAG 2.2 Level AA serving as the foundation for all digital platforms, services and systems. These standards align with UQ’s Disability Action Plan, equity objectives, and the Technology Master Plan, supporting the University’s strategic vision for inclusive digital transformation. 

 

Focus Areas:  

  1. Implement accessibility controls across UQ’s digital platforms to reduce friction and ensure equal access for all users.  
  2. Integrate inclusive design principles into application lifecycle processes to create consistent scalable solutions that work for diverse needs. 
  3. Ensure compliance with WCAG 2.2 Level AA and other relevant technical standards to create accessible experiences for all users while meeting legal requirements. 
  4. Establish governance and capability frameworks for accessibility practices to embed accountability and sustain long-term improvements. 
  5. Conduct accessibility testing and audits across Tier 0 and Tier 1 digital products and develop a testing framework to standardise practices and support ongoing compliance. 
  6. Provide training and build capability to embed a culture of accessibility so teams can confidently apply accessibility principles in their work. 
  7. Include user feedback and lived experience in design and testing to validate real-world usability and improve outcomes for all users. 
  8. Support and align with strategic objectives for equity, diversity, and inclusive service delivery, positioning UQ as a leader in accessible and inclusive digital transformation 

 

About the Systems and Services Upgrade Program

The Systems and Services Upgrade Program involves working with service leads and business owners to understand areas for improvement and enhancement in their current infrastructure, supporting the enablement of key outcomes for their respective areas.

Working together – ITS and UQ teams

ITS is a critical partner for business functions across UQ, helping the University achieve its mission of delivering for the public good through excellence in education, research and engagement with our communities and partners – local, national, and global.
From systems and applications support through to solution architecture and service desk delivery, the provision of software and ensuring effective data governance and security, the role of ITS is widespread, varied, and critical to UQ’s operations and reputation.

Collaborating with our customers

ITS is partnering with its customers to ensure change and continuous improvement is underpinned by collaboration and putting the end user viewpoint at the heart of what we do.

Our Programs of work engage with a range of stakeholders, primarily split into the following key groups :

  • Business Owner
  • Business Process Owner
  • Service Owner
  • Technical Owner

With the following suite of services:

  • Business IT Service
  • Application Service
  • Platform Service
  • Technical Service

(please see the glossary tab for definitions)

Contact

Program Manager: Ian Duncan

Digital Inclusive Design Project: digitalinclusivedesign@its.uq.edu.au

The Systems and Services Upgrade Program and Application Security Improvements Program help achieve two of the key themes within the UQ Technology Masterplan, namely:

  1. C: Engaging and enriching communities through technology 
  2. D: Optimising our corporate systems to support effective and efficient operations 
  3. F: Evolving a strong and sustainable digital operating model (F1 – Optimising technology service design and sustainable support models)

 Evolving a strong and sustainable digital operating model (F1 – Optimising technology service design and sustainable support models)

 

Overview

These programs are part of the ongoing ITS commitment to strengthening cyber security and maintaining compliance with UQ’s organisational and regulatory requirements.  To ensure we have accurately captured details on key applications and services as well as the relevant roles and individuals involved in them, we have the following process to develop, refine, and maintain an accurate service register. 

Effective communication is essential to the success of ITS services, ensuring that the relationship between business requirements, technical capability and strategy, and service levels are clearly understood by the relevant people.  This program promotes engagement between technical and business cohorts, ensuring that all engagement with service owners, technical owners, and business stakeholders is clear, consistent, and well understood.    

There are four owner roles which are critical for this process: 

Business Owner: The strategic role that defines the purpose of the IT Service and owns the benefits that the IT Service delivers.   

Service Owner: The strategic role responsible for delivering the IT Service and ensuring that it aligns with the Business Owner's vision and service strategy, and meets the agreed functional, performance, quality and service level requirements, within the agreed resourcing.   

Technical Owner: The operational role responsible for the day-to-day operational support of the IT Service. 

Budget Owner: The role which is ultimately responsible for providing or ensuring the provision of the budget to support the development and operation of the service. 

 (These roles are defined in the IT Glossary which can be found here

Please refer to this page regularly if you have any questions about the project or status.

1 - Tiering

The initial step in reviewing services is defining their relative “importance” to UQ.  This can refer to the impact on UQ operations were the service to become unavailable or the impact to UQ or individuals should a data breach take place.  We use the Enterprise Risk Management Framework to set an objective floor to impact and risk and from this we are able to use the CIA (Confidentiality, Integrity, Availability) yardstick to place each service in the register.

Our tiering runs from Tier 0 (highest impact) to tier 4 (lowest impact) with each tier requiring specific controls and treatments to comply with the relevant standards.  Once a service has been tiered the relevant assessment of that service takes place.

2 - Assessments

Every service is assessed against the cyber security standard via a checklist interview based on the following areas:

  • Access and Privileges Management 
  • Service Availability 
  • Compensatory Controls (for example is network access restricted to UQ networks) 
  • Issue detection, response and monitoring and alerts 
  • Data management (backup, retention, purging, archiving) 
  • Change management 
  • Hosting (security, on/off-site etc) 
  • Third Party Risks 
  • Vulnerability management (Patch management, penetration testing, etc) 

The differing tiers require differing levels of control in these areas and where multiple services require similar treatments the project can initiate activities with other teams (for example data governance or identity) to create simplified and standard mechanisms to address issues.

The resulting checklist forms the basis for discussion between the Service Owner and the Business owner in communicating and addressing any outstanding risks.

3 - Engagement

Once assessed treatments for any areas requiring attention are developed by the Service Owner, in cooperation with the Business and Technical owners. This process ensures all stakeholders are aware of the current state and any items requiring attention as well as outlining strategies for addressing issues. The assessment process highlights potential gaps and these discussions can form the basis for future project proposals, areas for attention through existing budgets, or broader activities across multiple services.

This program has limited funding available for addressing individual risks but we do have resources available on a needs basis to assist in one-off development, upgrade, or maintenance activities for services with significant issues and inadequate resourcing to address those issues.  Please contact the project team if you believe your service may qualify for this assistance. 

4 - Review

Once the assessment is complete and the treatment plans are developed in concert with the Business Owner, the last step is to complete the “Risk Acknowledgement Form”.  This forms documents that the Business Owner and Service Owner have reached agreement on a statement of the current state of the service including any outstanding risks and proposed treatments.  It does not form a project or resourcing plan and should be considered as a knowledge sharing and collaborative tool between “the business” and ITS.

For key services the entire process should be re-visited at least every two years.