Key cyber risk domains and corresponding EduSwap controls
1. Identity & Access Management (IAM)
These controls are intended to reduce the risk of unauthorised account access, credential misuse and excessive privilege.
Unauthorised access to accounts
ISO 27001 A.9 / NIST AC-1
Multi-factor authentication for administrative accounts, secure password hashing and optional single sign-on support.
Designed to support stronger account assurance and enterprise sign-in options.
Credential theft
OWASP ASVS 2.1
Strong password hashing, rate limiting and session expiry controls.
Intended to reduce brute-force and credential stuffing risk.
Privilege escalation
ISO 27001 A.9.2
Role-based access control and least-privilege enforcement.
Privileged actions may be logged and reviewed.
2. Authentication & Session Security
Session controls are intended to support secure user access and reduce cross-tenant or shared-device risk.
Session hijacking
OWASP ASVS 3.1
Secure cookies, session rotation and HTTP-only protections where supported.
Designed to reduce token theft and reuse risk.
Weak session termination
NIST IA-5
Automatic timeout and user logout controls.
Intended to reduce shared-device exposure.
Cross-tenant access
ISO 27001 A.9.4
Tenant-aware access logic and scoped authorisation controls.
Supports strong school-level separation.
3. Data Security (At Rest & In Transit)
These controls are intended to protect data during transmission, storage and backup retention.
Data interception
ISO 27001 A.10
TLS 1.2 or higher for data in transit.
Intended to support school-sector encryption expectations.
Data theft from storage
NIST SC-28
Strong encryption at rest for supported storage services.
Designed to provide industry-aligned storage protection.
Exposure of backups
ISO 27001 A.12.3
Encrypted Australian-hosted backups with controlled retention.
Intended to reduce recovery and storage risk.
4. Application Security
Application controls are intended to reduce common web application risks and support secure software operation.
Injection flaws
OWASP Top 10 / OWASP A1
Structured data access patterns and input validation.
Designed to reduce injection-related risk.
Broken authentication
OWASP Top 10 / OWASP A2
Secure sign-in controls, admin MFA and password protections.
Supports stronger account integrity.
Sensitive data exposure
OWASP Top 10 / OWASP A3
Encrypted storage and restricted access controls.
Designed to reduce unnecessary data exposure.
XSS and unsafe output handling
OWASP Top 10 / OWASP A7
Output encoding and browser security headers where appropriate.
Intended to reduce client-side injection risk.
Broken access control
OWASP Top 10 / OWASP A5
Role-based access, tenant checks and school-linked authorisation.
Supports school boundary enforcement.
5. Infrastructure Security
Infrastructure controls are intended to support hardened cloud deployment, external attack resistance and vulnerability management.
Infrastructure exploitation
ISO 27001 A.12
Hardened cloud environment and controlled deployment practices.
Supports baseline infrastructure security expectations.
External attacks
NIST SC-7
WAF coverage, DDoS mitigation and IP-based protections where supported.
Cloud-native protections help reduce internet-facing risk.
Vulnerability exploitation
ISO 27001 A.12.6
Automated scanning, dependency review and patch management.
Supports proactive remediation of known issues.
6. Monitoring, Logging & Detection
Monitoring and logging support visibility, investigation and misuse detection across the platform.
Undetected breaches
ISO 27001 A.12.4
Centralised logging and anomaly-oriented review practices.
Supports observability and investigation readiness.
Insider misuse
ISO 27001 A.18
Administrative activity auditing and retained logs.
Logs may be retained for up to 24 months.
Fraudulent transactions
NIST AU-6
Behavioural monitoring and manual review pathways.
Supports tiered escalation where needed.
7. Data Governance & Privacy
Privacy controls are intended to reduce unnecessary data handling and support lawful retention and storage practices.
Privacy breaches
APP 1–11
Minimal staff-data collection and no intended student-data storage.
Supports alignment with Australian privacy expectations.
Overseas disclosure
APP 8
Australian-hosted core production data.
Designed to reduce offshore disclosure risk.
Excessive retention
APP 11.2
Documented retention and deletion practices.
Supports controlled lifecycle management.
8. Third-Party / Supply Chain Risk
Third-party controls are intended to reduce dependency risk across hosting, email and payment services.
Vendor compromise
ISO 27001 A.15
Vendor selection, API key restrictions and limited trusted services.
Supports tighter external service control.
Payment fraud
PCI DSS
Payment processors handle card data rather than EduSwap storing card details directly.
Reduces direct card data exposure.
Email spoofing
DMARC / SPF / DKIM
Authenticated mail-sending configuration where supported.
Intended to reduce phishing and spoofing risk.
9. Operational & Business Continuity Risk
Continuity controls are intended to support resilience, backup availability and disaster recovery readiness.
Outage or downtime
NIST CP-2
Resilient cloud infrastructure and autoscaling-capable services where supported.
Designed to support stable service availability.
Data loss
NIST CP-6
Daily encrypted backups with controlled retention.
Supports recoverability of critical platform data.
Disaster recovery
ISO 27001 A.17
Documented recovery objectives and restoration procedures.
Indicative targets may include RTO under 2 hours and RPO under 1 hour.
10. Incident Response & Breach Management
Incident response controls are intended to support containment, notification and corrective action following security events.
Slow or unmanaged breaches
NDB Scheme
Documented incident response workflow and escalation process.
Supports legal and operational breach handling.
Failure to notify
APP 11 / NDB
Notification pathways for affected schools, regulators and other stakeholders where required.
Notification depends on applicable legal thresholds and circumstances.
Repeat compromise
ISO 27001 A.16
Root cause review and remediation actions after significant incidents.
Supports learning and control improvement.