SecurityPolicy.com.au
Home/How we verify

Methodology and audit trail

Every claim on this site traces to a primary source.

These guides are only useful if they are true. So the whole library is built from sourced claims, each one checked against the official record and labelled with how confident we are in it. This page shows exactly how, and keeps a dated trail of what has been checked.

1,629
sourced claims
1,017
source references
95
distinct sources
83
tracked law changes

What counts as a source

We cite primary and official sources only: the legislation registers (legislation.gov.au, legislation.govt.nz), the regulators (the OAIC and the Office of the Privacy Commissioner, Home Affairs, the Cyber and Infrastructure Security Centre, DPMC, the GCSB and the NCSC), and the standards and framework bodies (the ACSC, ISO/IEC, Standards Australia and Standards New Zealand). Law-firm articles, vendor pages and news are useful for orientation but are never the source a date or an obligation rests on.

VERIFIED and INFERRED

Every claim carries one of two labels, and we show it:

  • VERIFIED — the statement is directly supported by the official source cited, in its own words. 1,335 of 1,629 claims are verified.
  • INFERRED — the statement is a reasonable reading of sourced material, but the source does not state it in exactly those terms, or the timing is imprecise. 294 claims are inferred. We label these so you can weigh them, not hide them.

The same discipline applies to the 83 tracked regulatory changes: 82 are verified against a primary source, and where an exact date could not be confirmed on an official source we leave it out rather than estimate it.

How a fact gets onto the site

  1. Research against the official sources for that topic and jurisdiction.
  2. Re-check — each date and claim is opened again on the source it came from and confirmed before it is published.
  3. Independent re-check — the regulatory change data has additionally been re-checked against the primary and official sources by a separate review, with corrections applied (see the audit trail below).
  4. Correct in the open — when a source says something different, we change the record and note it here. Unverifiable items are dropped, not guessed.

Reviewed, versus changed

These are two different dates and we keep them apart. Reviewed is when we last checked a guide against its sources. Source last amended is when the underlying law or framework itself last moved. On every law and framework guide you will also find a What's changing timeline: the dated history of that instrument and any officially-scheduled next change, each entry linked to its official source. Where nothing is officially scheduled, we say so, rather than imply a change is coming.

Audit trail

A dated record of what has been researched, checked and corrected. Guides were reviewed between 2026-07-12 and 2026-07-13.

  1. 12 July 2026

    Guide corpus researched and published

    The 44 guides (22 Australian, 22 New Zealand) were built from 1,629 individually sourced claims across 440 questions. Every claim was labelled VERIFIED or INFERRED and linked to a source.

  2. 15 July 2026

    Regulatory change tracking added

    For every law and framework guide, dated change events (amendments, commencements, guidance updates and officially-scheduled future changes) were researched from official sources and each date re-checked against the source it came from before being included. 71 events across 17 guides.

  3. 15 July 2026

    Independent source re-check of the change events

    The change events were independently re-checked against the primary and official sources. The majority were confirmed as recorded; a number were corrected — mostly reclassifying a registration or compilation date to the date the law actually changed — and further sourced events were added. The change set now stands at 83 events across 18 guides, 82 verified against a primary source.

  4. 16 July 2026

    Glossary published

    64 security, privacy and compliance terms used across the guides defined in plain English — tagged Australia, New Zealand or both, with statutory terms linked to their official source and each term cross-linked to the guides that use it. Guide pages also link terms inline — dotted-underlined, first occurrence only — with a hover definition and a jump to the glossary.

  5. 16 July 2026

    Articles section launched

    Three launch articles published, every date and obligation drawn from the verified change events and cited to its official source: the two 10 December 2026 Privacy Act deadlines (AU), the Biometric Code transition ending 3 August 2026 (NZ), and the Cyber Security Act 2024 obligations now in force (AU).

What this is not

This is a sourcing and verification process for educational guides and editable templates. It is not legal advice, it is not a professional or accredited compliance audit, and it is not a guarantee that any template makes you compliant. Your obligations depend on your industry, your contracts and your data. Have a qualified adviser review anything high stakes. See the full disclaimer.