Six Australian government agencies have come under fire from the Australian National Audit Office (ANAO) for their lax security.
The report on a 2005 audit of security management was released yesterday and is called Internet Security in Australian Government Agencies. The Australian National Audit Office (ANAO) found 31 specific risks - as defined by the Defence Signals Directorate (DSD) - in agency Web servers.
Three percent of risks were high level, 32 percent were medium level and 65 percent of risks were low-level risks. The ANAO made 51 suggestions for improvements.
Alarmingly, the ANAO report also concluded the current level of Internet security in six government agencies was insufficient, and that none of the agencies fully complied with the Protective Security Manual (PSM) and ACSI 33.
The PSM is a list of common standards for protective security for all Australian Government agencies and contractors with eight points including security policy and personnel security. ACSI 33, part of the PSM, breaks down risk management into five simple steps - context, identifying, analyzing, assessing and developing a plan and is mandatory for all commonwealth agencies.
The audited agencies were Australian Customs Service, Australian Federal Police (AFP), Australian Radiation Protection and Nuclear Safety Agency, Department of Education and Workplace Relations, Department of Industry, Tourism and Resources and Medicare Australia.
None of the agencies had ICT security documentation that complied with the PSM and ACSI 33, and lacked a systematic and coordinated program for ongoing management of ICT security-related risk assessments. Security policies and system security plans were not linked to ICT risk assessments and plans, and the agencies lacked system security plans.
The ANAO report stated agencies had only limited business continuity plans, if at all.
"While several of the six agencies had initiated development of business continuity and disaster recovery plans for Internet services, only one had sound plans in place," the report stated.
"Two agencies largely depended upon the knowledge of key staff and had few documented procedures. Documents were found in draft form and some plans had not been regularly reviewed.
"A majority of the agencies audited had implemented standard operating desktop procedures that did not comply with ACSI 33. Non compliance was found in inappropriate password management, user account privileges inappropriately administered, no documented procedures for incident detection and response and management of hardware and the use of remote access was not adequately secured."
E-mail filtering in all agencies was found to be inadequate. Only one of the agencies had sound disaster recovery plans in place. Two agencies were found to depend on the knowledge of key staff and few agencies had documented procedures, some documents were left in draft form and some plans had not been regularly reviewed.
The report also recommended the Department of Industry, Tourism and Resources document the coverage of Internet services within business continuity and disaster recovery plans in 2006-07, introduce requirements for documenting benefits versus risk before purchasing new technologies and review e-mail blocking tools with a view to "improving the blocking of malicious e-mails".
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Strategies for Eliminating .PST Files
Security Inside Out
Email Archiving Implementation: Five Costly Mistakes to Avoid
Discover the advantages of an open architecture multi-vendor network solution
Taking On Demand CRM Integration to the Next Level
CRM your salespeople will love
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Cutting printer costs
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Vignette Announces 2008 Excellence Awards 2008-11-21 10:50:00+11
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
Understanding Email Marketing: A Guide for SMBs
Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.









