Bulletin Board - Review and Comment
Step 1 of 4: Comment on Document
How to make a comment?
1. Use this
to open a comment box for your chosen Section, Part, Heading or clause.
2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.
3. Do not open more than one comment box at the same time.
4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.
Important Information
During the comment process you are connected to a database. The session that connects you to the database may time-out due to inactivity. The following tips will help you to avoid losing your comments or corrupting your entries:
- Do not jump between web pages/applications while logging comments.
- Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
- Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
- Do not exit the process until you have completed all three stages.
(1) This Procedure states how Victoria University (VU) will manage critical incidents as part of its Business Resilience Framework. It establishes the governance, escalation, response and recovery arrangements used to manage critical incidents that may impact the University's people, operations, assets, reputation or community. (2) This Procedure applies to all University staff; students; contractors, consultants and volunteers engaged by the University; visitors to University campuses; University-controlled entities, offshore operations and partner-delivered activities, where applicable; and any person with responsibilities under this Procedure. (3) This Procedure applies to critical incidents occurring: (4) This Procedure does not replace local emergency response arrangements, specialised operational procedures or business continuity plans. Where required, those arrangements will be activated and implemented in conjunction with this Procedure. (5) Business Resilience Policy (6) To support effective critical incident management, staff with responsibilities under this Procedure must understand their roles and responsibilities and participate in relevant training, exercising and preparedness activities in accordance with University critical incident management guidance and processes. (7) The University may develop incident-specific response plans, playbooks or guidance materials to support preparedness and response for identified critical incident scenarios. (8) Potential members of the CIMT will be trained for their roles and responsibilities. (9) Actual or suspected critical incidents must be reported to the Office of the DVC Enterprise and Digital (DVC E&D). (10) The Deputy Vice-Chancellor Enterprise and Digital, as CIML, will assess the incident and determine the severity classification of the incident and whether activation ofe a Critical Incident Response is required. The following definitions broadly categorises the 4 severity classifications. Major and Critical incidents will generally require activation of this Procedure. (11) Table 1: Incident Severity Classifications (12) The CIML has delegated authority to declare a critical incident and to determine the level of response required to support the University’s response and recovery actions. (13) All incidents that present an immediately threat to people, operations or the environment must be reported immediately to the University's Security Services or emergency services, as appropriate, who will coordinate the emergency response. (14) Any incident that meets the MAJOR category must be reported to the Office of the CRO for consolidated reporting to the ARC and Council. (15) The CIMLU may delegate some or all management functions of incident control - planning, intelligence/public information, operations, logistics and finance as the incident or critical incidents escalate in size or complexity. (16) At a minimum, the CIMT will comprise: (17) Together, this core team will determine the additional members and subject matter experts required to respond to the specific circumstances of the critical incident. (18) Each core role must have at least one trained alternate. (19) The Subject Matter Experts may be engaged from within or external to the University to: (20) Where a critical incident involves students, the Student Crisis Response Procedure must also be activated to ensure appropriate student welfare, support and recovery actions are undertaken. (21) The CIML will review the information known about the incident and the impact it has on VU’s operations. Using the Business Impact Assessment (BIA) data, it will prioritise response and recovery efforts to the critical functions impacted first. (22) Where the special Crisis Delegations are not enough for the CIML to take appropriate action, the CIML will first go to the Vice-Chancellor to seek approval. If the VC’s delegations are not sufficient, the Critical Incident Council Delegation Group (CICDG) will be convened. (23) The CIMT will ensure that: (24) Each nominated key decision-making member of the CIMT must have delegated powers for operational decisions made within the scope of their specific role. Such decisions must always place primary importance on the impact on the VU community. These decisions must also be consistent with the purpose, values and objectives of the University. (25) The University will allocate appropriate resources to respond to a critical incident. The CIML may activate the Crisis Operations Centre as required, convene regular briefings of the CIMT for key senior officers and key subject matter experts as required. (26) Upon activation of a critical incident response, the following internal communication and escalation protocols will be enacted: (27) Internal and external communications arising from a critical incident must be managed in accordance with the Media Policy, Media Protocol and any critical incident communication plan approved for the incident. (28) The CIML will ensure that appropriate communications resources are engaged to support the response and recovery activities associated with the critical incident. (29) Critical incident management and business continuity form part of the University's broader Business Resilience Framework. Where a critical incident impacts, or is likely to impact, the University's critical functions, relevant Business Continuity Plans may be activated to support response and recovery activities. (30) Not all critical Incidents will require the activation of Business Continuity Plans (Response Plans and/or Recovery Plans). (31) Implementation of an appropriate business continuity response is the responsibility of the relevant delegated officer/s. The most senior officer responsible for the affected area will liaise with the CIML regarding response and recovery activities, as required. (32) Following resolution of the critical incident, the CIML or nominee will coordinate a post-incident operational debrief (within 10 University business days) to: (33) A Post Incident Report will be prepared. Where appropriate, the report may be provided to the Vice-Chancellor, Audit and Risk Committee, the Council or other relevant governance body as determined by the CIML. (34) The CIML or delegated person will ensure records are maintained for each critical incident, including key decisions, actions, and communications undertaken during the University’s response. (35) Members of the CIMT are responsible for maintaining appropriate records relating to decisions and actions taken within their respective portfolios. (36) Records created under this Procedure must be managed in accordance with the Records Management Policy, Information Security Policy and relevant associated procedures. (37) Information relating to a critical incident must be protected from unauthorised access, use, disclosure, alteration or loss and handled in accordance with applicable privacy, information management and legal requirements. (38) HESF: Standard 2.3 Wellbeing and Safety; 6.2.1 Corporate Monitoring and Accountability; 7.3.3 Information Management. (39) Outcome Standards for NVR Registered Training Organisations Instrument 2025: Standard 2.6 Wellbeing. Compliance Standards for NVR Registered Training Organisations and FPP Requirements 2025: Standard 20 Compliance with Laws. (40) ESOS National Code of Practice 2018: Standard 5 Younger overseas students, 6 Overseas student support services. (41) Business Continuity: The capability of the University to continue delivering critical services and functions at acceptable levels during and following a disruption, through the use of planned strategies, processes, resources, and recovery arrangements (42) Business Reliance: The University's ability to anticipate, prepare for, respond to, adapt to, and recover from disruptive events while continuing to achieve its objectives. (43) Crisis or Critical Incident: An event that has the potential to cause significant harm to people, disrupt critical University operations, impact the University's reputation, or require a coordinated response involving senior leadership and multiple functions. (44) Critical Incident Management Team: A designated group of senior leaders and subject matter experts responsible for providing strategic oversight, decision-making, coordination, and direction during a critical incident or crisis response. (45) Crisis Operations Centre: A designated physical or virtual coordination environment established to support the management of a crisis by enabling information sharing, situational awareness, decision-making, resource coordination, and communication between response teams (46) Incident: An event, situation, or occurrence that has caused, or has the potential to cause, disruption, harm, loss, or adverse impacts to University operations, people, assets, or reputation. (47) Incident Classification: The process of assessing and categorising an incident based on factors such as severity, impact, complexity, urgency, and potential consequences to determine the appropriate level of response and escalation. (48) Critical Incident Management Plan: A documented framework that defines the University's approach to preparing for, responding to, managing, and recovering from critical incidents. It outlines governance structures, roles and responsibilities, escalation processes, communication arrangements, and response procedures. Business Resilience - Critical Incident Management Procedure
Section 1 - Summary
Section 2 - Scope
Section 3 - Policy/Regulation
Section 4 - Procedures
Part A - Summary of Roles and Responsibilities
Top of PageSection 5 - Procedures
Pre-Crisis
Alert and Assess
Severity
Definition
Typical Characteristics
Typical Response
Minor
A localised incident with limited impact that can be managed by the affected faculty, school, or business unit using normal operational procedures
Moderate
An incident with measurable operational impacts that affects multiple areas or requires coordinated management beyond the local business unit, but where operational procedures still respond.
Major
An incident that disrupts targeted operations, poses risks to people or assets, or requires executive oversight and cross-functional coordination.
Relevant Executive VCG leadership directs the response with coordinated internal and external communications.
Activation of relevant business continuity arrangements may be required.
Critical
An incident that threatens life, the University's ability to operate, or its reputation, requiring immediate executive
Critical Incident Management Team (CIMT) activated. Business continuity and recovery arrangements activated as required.
Activate and Respond
Escalation
Statements to the media or public
Business Continuity
Post-Incident
Records
Section 6 - HESF/ASQA/ESOS Alignment
Section 7 - Definitions