Data integrity
Data Integrity Policy.
This Policy establishes the Open Access Publishing Association (OAPA) framework that protects the confidentiality, integrity, and availability of information assets.
Policy position
All controls in this Policy are applied proportionally to OAPA’s size, risk profile, and resource capacity.
Where a control is delegated to a hosting provider or external service, OAPA verifies that equivalent safeguards are in place.
1. Purpose
- 1.1 This Policy establishes the Open Access Publishing Association (OAPA) framework that protects the confidentiality, integrity, and availability of information assets.
- 1.2 The Policy aligns with the principles of ISO/IEC 27001 and addresses the specific requirements of academic publishing, including secure manuscript handling, double-blind peer review, and management of submissions from editors and staff.
- 1.3 OAPA maintains a publicly available Privacy Statement on its website describing how personal and organisational data are collected, used, stored, and protected in compliance with the Australian Privacy Principles. This statement complements the Data Integrity Policy and applies to all OAPA-managed services.
- 1.4 All controls in this Policy are applied proportionally to OAPA’s size, risk profile, and resource capacity. Where a control is delegated to a hosting provider or external service, OAPA verifies that equivalent safeguards are in place.
2. Scope
- 2.1 This Policy:
- applies to all OAPA staff, contractors, volunteers, editors, and peer reviewers.
- covers all information systems managed by OAPA, including the Open Journal Systems (OJS) platform, associated databases, and supporting infrastructure.
- extends to all manuscripts, reviews, editorial records, author details, and communications processed by OAPA.
3. Principles
- 3.1 Confidentiality requires that author identities, reviewer reports, and editorial deliberations remain protected in line with double-blind peer review protocols, unless otherwise stated in publishing policy (e.g., open review and group review processes).
- 3.2 Integrity requires safeguarding manuscripts and editorial records against unauthorised alteration or deletion.
- 3.3 Availability requires OAPA to maintain platforms, submission systems, and archives in a manner that ensures timely access.
- 3.4 Accountability requires all users to act responsibly and in compliance with this policy.
- 3.5 Impartiality requires that submissions from OAPA editors or board members be managed transparently and without conflicts of interest.
4. Roles and Responsibilities
- 4.1 The OAPA Board of Directors approves and reviews this policy annually.
- 4.2 The Editor-in-Chief and Managing Editors ensure that peer review processes of the publishing instance they are accountable for remain compliant with the OAPA Publishing Policy overseeing security of editorial workflows.
- 4.3 The Technology Committee implements and maintains essential controls, including multi-factor authentication, software patching, and backups.
- 4.4 Authors and reviewers are responsible for maintaining confidentiality and complying with journal policy compliant with OAPA Publishing Policy.
- 4.5 All staff, editors, contractors, and volunteers with access to OAPA systems or data must sign a Confidentiality and Acceptable Use Agreement prior to gaining system access. Breaches of these agreements are handled by the Technology Committee.
5. Access Control
- 5.1 Access to OAPA systems is limited to authorised personnel and follows the principle of least privilege.
- 5.2 Two-factor authentication is mandatory for all accounts with administrative privileges.
- 5.3 Reviewer identities are anonymised within the submission system, and unauthorised disclosure is prohibited.
- 5.4 System logs are retained to provide monitoring and auditing capabilities.
6. Peer Review Integrity
- 6.1 OAPA maintains peer review processes in line with the OAPA Publishing Policy to protect both author and reviewer identities. Manuscripts are ordinarily assigned to reviewers without disclosure of author identity, and review reports are stored securely with access limited to the assigned editor and authorised administrators.
- 6.2 When an editor submits as an author, the submission is reassigned to an independent editor with no conflict of interest.
- 6.3 The submitting editor has no access to peer review records or decision workflows.
- 6.4 The process is monitored by the OAPA Publishing Lead and reported annually to the Board.
7. Information Security Controls
- 7.1 Technical measures include firewall protection, regular patching of OJS and server software, daily automated backups, and encrypted transmission using TLS/SSL.
- 7.2 All OAPA-managed email domains implement Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) records to prevent spoofing and forged messages. Email transmission is enforced using TLS 1.2 or higher.
- 7.3 Organisational measures include annual security and privacy awareness updates for all staff, editors, and contractors, incident-response procedures, and annual risk assessments.
- 7.4 All software or configuration changes to OAPA platforms follow secure-development practices using version control and peer review. VentraIP’s managed hosting services and OAPA’s administrative systems employ active anti-malware protection with automatic signature updates.
- 7.5 Physical measures are provided through secure hosting infrastructure located in Australian data centres managed by VentraIP. VentraIP maintains ISO 27001-aligned data-centre controls. OAPA relies on VentraIP’s physical and network security certifications in place of separate OAPA controls.
- 7.6 Open Journals System. OJS is maintained in a patched and updated state, with security updates applied promptly. User roles are managed to ensure least-privilege access. Peer review workflows in OJS are configured to maintain double-blind confidentiality.
- 7.7 Moodle. Moodle is configured with secure authentication, encrypted communications, and regular patching. User data is limited to necessary information for training participation. Course content and participation data are protected in accordance with this policy.
- 7.8 Third-Party Data Sharing. OAPA engages with third parties such as DOI registration agencies, indexing services, and plagiarism detection providers. Data transferred is limited to that which is strictly necessary for service delivery, and agreements with third parties require compliance with confidentiality and security obligations. Personal data is not shared with unauthorised parties or used for purposes beyond publication and training.
- 7.9 Backups and recovery are managed through an Acronis backup that is performed every 6 hours via VentraIP for covered services. Backups are verified at least annually through a restore test.
8. Incident Response
- 8.1 All suspected data breaches, security incidents, or breaches of peer review confidentiality must be reported immediately to the Managing Editor.
- 8.2 Each incident will be logged, investigated, and remediated, with findings reviewed by the Board.
- 8.3 Where legally required, affected authors, reviewers, or regulators will be notified promptly.
- 8.4 OAPA welcomes responsible disclosure of potential security vulnerabilities. Reports may be sent to tech@open-publishing.org, which is monitored by the Technology Committee for logging, triage, and investigation.
9. Risk Management
- 9.1 OAPA maintains a risk register to document potential threats such as phishing, unauthorised access, or manuscript manipulation.
- 9.2 Risks are assessed annually for likelihood and impact, and mitigating actions are recorded.
- 9.3 OAPA commissions external or internal vulnerability reviews when significant system changes occur or at least every two years.
- 9.4 Host-level vulnerability scans are performed annually across all production systems, with results reviewed by the Technology Committee and remediation tracked to completion.
- 9.5 OAPA maintains an Asset Register listing all servers, software, privileged accounts, and endpoint devices used to deliver its services. The register is reviewed at least annually.
- 9.6 OAPA follows the Plan–Do–Check–Act cycle to ensure continuous improvement in its information security management.
- 9.7 OAPA conducts an annual security review to confirm adherence to this Policy. The review may be completed through a meeting of the Technology Committee and documented in meeting minutes. All major platform updates (e.g., OJS, Moodle) are noted in a simple Change Log recording the change, approver, and date.
10. Compliance and Enforcement
- 10.1 Compliance with this policy is mandatory for all staff, editors, and reviewers.
- 10.2 OAPA complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in the collection, storage, and processing of personal information. All data handling practices are reviewed annually to ensure alignment with applicable Australian and international privacy regulations.
- 10.3 Breaches of confidentiality, failures to uphold peer review integrity, or non-adherence to security practices may result in disciplinary action, removal from editorial roles, termination of contracts, or referral to academic or legal authorities.
11. Data Collected, Stored, and Processed
- 11.1 Author and Reviewer Information. OAPA collects and processes personal information necessary to manage manuscript submission and peer review, including first name, last name, institutional affiliation, email address, ORCID identifier, and relevant academic or professional details.
- 11.2 Manuscript and Editorial Data. OJS stores submitted manuscripts, supplementary files, metadata (title, abstract, keywords), editorial decisions, and peer review reports, all of which are confidential and accessed only by authorised editors, reviewers, and administrators.
- 11.3 System and Usage Data. OAPA systems may log technical information including IP address, browser type, login timestamps, and access records for the purposes of security monitoring, troubleshooting, and audit.
- 11.4 Training and Learning Management Data. Moodle is used for reviewer, author, and editor training and collects participant registration details, course enrolments, activity logs, and training records limited to what is necessary for participation and course administration.
- 11.5 Third-Party Transfers. Data may be transferred to external parties only where necessary for scholarly publishing operations, including DOI registration with Crossref, indexing services, and plagiarism detection providers, and such transfers are limited to the minimum required information.
- 11.6 Email and Communications Data. OAPA systems process email addresses, correspondence content, and notification preferences to support journal operations and training communications, and email traffic is encrypted in transit using TLS.
- 11.7 Data Integrity and Security. All collected data is subject to the confidentiality, integrity, and availability requirements of this policy, and Acronis backups are taken every six hours through VentraIP and tested at least annually to ensure recovery capability.
Policy information
Version 1.0 Approved by the OAPA Board on 30 October 2025.
Review date: 30 October 2026.