S-114 · A 90-day try-out

A club plan for Password 101 Workshop

Use this as a starting point. Cross out what does not fit, add what is missing and make it your club's own.

Where this idea came from

Playbook entry
S-114 · Password 101 Workshop
Theme
Theme 5: Digital, Data & Systems · Subtheme 8: Cybersecurity & Risk
Source material
Current playbook index title and category plus an internally authored detailed-guide draft

Initiative-specific development wave

How this draft was developed

These sources support general principles for digital, data and systems, accessibility, privacy, safety, systems or responsible governance; they are not an endorsement of Password 101 Workshop, a finding that it suits any club or approval of its local design.

Primary references consulted

  • Rotary Clubs (Rotary International)
    Used for: Rotary describes club participation through service, friendship, diversity, integrity and leadership, including online participation for people affected by schedules, mobility or distance.
  • Small business cyber security guide (Australian Signals Directorate's Australian Cyber Security Centre)
    Used for: A practical security baseline includes multi-factor authentication, software updates, regular tested backups and advice suited to the organisation's actual systems and risk.
  • Chapter 11: APP 11 Security of personal information (Office of the Australian Information Commissioner)
    Used for: Entities covered by the Privacy Act must take reasonable steps to protect personal information and destroy or de-identify it when it is no longer needed, subject to lawful retention requirements.
  • Quick reference guide for responding to data breaches (Office of the Australian Information Commissioner)
    Used for: Organisations should contain, assess and respond to suspected data breaches, determine applicable notification duties and review the event to reduce recurrence.

Candidate District material

No candidate local guide was used for this version. The current initiative identity and the attributed primary references remain separate.

Theme 5 source-assurance wave

What has been checked

  • 4 current primary pages used by this guide were reopened on 9 August 2026.
  • 4 attributed source claim(s) were mapped to their bounded use in this initiative.
  • Candidate District material remains separate and does not establish this result.
See each source's scope and limit
  • Rotary Clubs
    Supports: Rotary club participation context and the value of accessible online or hybrid participation.
    Does not establish: Product configuration, legal compliance, local suitability or approval of a named initiative.
  • Small business cyber security guide
    Supports: A practical minimum cyber-security baseline for smaller organisations and volunteer-run systems.
    Does not establish: That the baseline is sufficient for a club's actual risk, system architecture, supplier arrangements or legal obligations.
  • Chapter 11: APP 11 Security of personal information
    Supports: Security, access, retention and disposal safeguards where the Privacy Act and APP 11 apply.
    Does not establish: That a club's controls are reasonable, that the Privacy Act applies or that a particular retention period is correct.
  • Quick reference guide for responding to data breaches
    Supports: A proportionate sequence for preparing for and responding to suspected personal-information breaches.
    Does not establish: Whether an incident is an eligible data breach, who must be notified or the club's legal duties in a specific event.

What still needs a person to confirm

  • Confirm which privacy, records, safeguarding and other legal duties apply to the club and this local design.
  • Confirm current ClubRunner or other platform features, permissions, licence settings and supplier instructions in the club's actual account.
  • Test accessibility and alternative participation routes with affected members rather than inferring conformance from the guide.
  • Confirm every local fact, starting point, measure, cost, owner and claim before the club decides to proceed.
  • Resolve any candidate District-source provenance and approval decision without treating the candidate as controlled authority.

The source-verification release gate remains closed.

Checks still on hold

Still an internal draft: source interpretation, local suitability, accessibility, governance and editorial approval remain open checks.

1. Is this worth trying here?

What we hope will change: Use Password 101 Workshop to protect club systems and information through simple, shared security habits and a practiced response.

2. Our 90-day try-out

What our club will do for Password 101 Workshop
StepWhat we will doWho could lead itOur dateHow we will know it is done
1Write the decision brief for Password 101 Workshop: define which accounts, devices, data and response capability the club will protect first, the starting evidence, people affected, local authority, resource limit, success signals and stop conditions.Board sponsor and information ownerWeek oneAn approved decision and boundary brief
2Identify users and non-users, map access and digital-confidence barriers, explain data use and permissions and retain an equivalent human or non-digital route where essential participation is involved. Apply this specifically to Password 101 Workshop and record which relevant experiences or users are still missing.Board sponsor and information owner with the access and privacy contactsWeeks one and twoA participant, access and information-handling plan
3Build and test a needs-led learning session with verified content, active practice and a real transfer task for Password 101 Workshop; complete the Password 101 Workshop Learning Design and Practice Sheet, rehearse the boundary wording and confirm who may decide, refer, pause, recover or close the work.System lead, privacy contact and access testerBefore the trialA tested learning design and practice sheet and delivery pack
4Use synthetic or minimised test data, least privilege, versioned configuration, accessible instructions, exception handling and a rollback; do not expose live credentials or private member information. Capture only the evidence needed to judge whether Password 101 Workshop advances practical cyber resilience.System lead, privacy contact and access testerWeeks three to eightA controlled activity and evidence record
5Compare the evidence with the starting point, validate meaning with affected participants or users, record gaps and unintended effects and prepare a completed practice artefact, observed feedback record and application commitment without overstating what the trial proves.System lead, privacy contact and access tester with an independent reviewerWithin seven days of the trialA completed practice artefact, observed feedback record and application commitment
6Make and record the authorised continue, adapt, refer, scale or stop decision for Password 101 Workshop; explain the reason, complete every action, close unnecessary records and schedule the 90-day follow-up.Service owner and independent reviewerBy day 90A published participant response, closed action register and next-step decision

3. Checks before we start

Things our club needs to check
QuestionWhat it means for usWho will checkDone?
Check the idea with the people affected and confirm its purpose, owner and practical limits before putting it into use.
Name the system and data owners, restrict access, provide an accessible alternative and document how errors or failures will be recovered.
Confirm venue, accessibility, safety, incident, cancellation and follow-up arrangements for the actual audience and setting.
The club proceeds with Password 101 Workshop without respecting this boundary: volunteer capability does not replace professional advice for a serious incident, compromised account, legal duty or complex configuration. — Put the boundary in the brief and participant information, give the delivery lead stop authority and move any excluded matter to its responsible process.
The system excludes members or creates a single digital path for essential participation. — Test with varied users, provide accessible instructions and retain an equivalent supported alternative.
Permissions, integrations or exports expose more personal information than the purpose requires. — Minimise fields, use least privilege, test permissions, control exports and review access after the trial.
A volunteer-built workflow becomes unowned, inaccurate or impossible to recover. — Name a service owner, document dependencies, keep tested backups and rollback steps and schedule a maintenance decision.
The current Theme 5 index controls the code and title. No unverified or close legacy Digital crosswalk was used as initiative evidence.
The connected Drive refresh returned an internal error on 9 August 2026. No unseen file was inferred or promoted; the 7 August intake, duplicate decisions, quarantines, rights boundaries and public-write permission hold remain in force and no sharing was changed.
Before local delivery, the club must approve the decision, participant choices, access arrangements, privacy and records plan, role boundaries, referral or escalation routes, resource limit and the specific control for this boundary: volunteer capability does not replace professional advice for a serious incident, compromised account, legal duty or complex configuration.

4. What changed?

What we will keep an eye on
What mattersWhere we are nowWhat we hope to seeHow we will checkWho
After 90 days, review Password 101 Workshop. Look for current access records, stronger authentication, tested recovery and incidents being contained, recorded and reviewed promptly.
Password 101 Workshop produces a completed practice artefact, observed feedback record and application commitment by the promised decision date, with evidence limitations, participation gaps and unintended effects stated.
People affected can explain the purpose, their choices, the boundary and how to raise an access, privacy, safety or governance concern.
The trial shows whether practical cyber resilience improved from the recorded starting point without shifting hidden workload, risk or exclusion elsewhere.
Every accepted action has an owner, due date and completion evidence, and the club records a reasoned continue, adapt, refer, scale or stop decision.

After 30 days

Is it reaching the right people? Is anything unsafe, unfair or harder than expected?

After 60 days

Make one useful change based on what people have told you.

After 90 days

Compare with where you started. Decide whether to change it, continue it or stop.

Made for this initiative

Tailored supporting documents

These working documents use the decisions, safeguards and evidence needs of this initiative. Complete them with the people affected and keep the agreed version with the club's project record.

01

Password 101 Workshop User Need and System Boundary Brief

Define the user problem, information flow and excluded uses.

Open supporting document
02

Password 101 Workshop Data Inventory and Purpose Map

Link every field and transfer to a necessary purpose.

Open supporting document
03

Password 101 Workshop Privacy, Consent and Notice Check

Make information handling and choices clear before collection or publication.

Open supporting document
04

Password 101 Workshop Access and Permission Matrix

Apply least privilege and accountable access reviews.

Open supporting document
05

Password 101 Workshop Accessible User Test Script

Test the real task with varied users and alternatives.

Open supporting document
06

Password 101 Workshop Configuration and Change Register

Maintain a reviewable record of settings, integrations and releases.

Open supporting document
07

Password 101 Workshop Incident, Exception and Recovery Card

Give volunteers a safe response route when the workflow fails or data is exposed.

Open supporting document
08

Password 101 Workshop Handover, Backup and Maintenance Plan

Keep the service operable beyond one volunteer.

Open supporting document
09

Password 101 Workshop Cybersecurity & Risk Delivery Check

Test whether Password 101 Workshop genuinely advances practical cyber resilience within the subtheme boundary.

Open supporting document
10

Password 101 Workshop Learning Design and Practice Sheet

Connect verified learning to practice, feedback and a real club task.

Open supporting document
11

Password 101 Workshop Evidence, Decision and Close-Out Record

Bring the evidence, limitations, participant response and final decision for Password 101 Workshop into one accountable record.

Open supporting document

Before your club says yes

Does the idea fit?

Talk with the people it is meant to serve and check that the need is real.

Who can say yes?

Name the person or group that can approve the work, spending and any safety arrangements.

Are people protected?

Check privacy, consent and safety. Collect only the information you genuinely need.

Can everyone take part?

Check the language, format, place, technology and cost for barriers.

Are the facts and permissions right?

Check names, claims, images, quotations, partner references and Rotary branding.

How will we learn?

Note where things stand now, check in at 30, 60 and 90 days, and decide what to do next.

Worksheets for your club

Open them online, print them or change them to suit the way your club works.

01

Event brief

Use this worksheet to plan who the session is for, when it will happen, how people can take part and what happens afterwards.

Open worksheet
02

Registration and follow-up log

Use this worksheet to map each step and keep only the information the club genuinely needs.

Open worksheet
03

Feedback form

Use this worksheet to hear what people experienced and decide what to change next.

Open worksheet