ACT Govt repels over one million intrusions

 

Auditor-General commends 'robust' security.

The ACT auditor-general has credited the territory government’s ‘robust’ ICT security regime for defending against more than one million attacks in the nine months to 31 March.

An audit report, released Friday, found ACT’s Shared Services ICT security “overall satisfactory” in protecting a network of 18,000 public servants, 37,500 students, 5000 teachers, and Canberra Institute of Technology students (pdf).

But not all directorates and agencies relied on the state’s Shared Services ICT offerings, despite it being the government’s preferred supplier.

ACT auditor-general Maxine Cooper noted that externally hosted agency websites were not as secure, with at least one documented compromise in the nine-month period.

She reported that such breaches could be minimised if all directorate and agency websites were hosted on the ACT Government network or by a government-endorsed suppliers.

Cooper found administrative structures and processes that supported whole-of-government ICT policies and procedures “satisfactory”, but there were shortcomings in security governance and mobile security plans.

Use of handheld devices, or “portable platforms” that could access the ACT Government’s networks and the internet was growing, but it was unclear who owned data on a device provided to an employee.

Despite a “well-structured and wide ranging” Shared Services ICT security template, only five percent of the government’s 1025 information management systems had a system security plan, and 2.24 percent had undergone threat and risk assessments.

“It is not clear to Audit why there are so few security plans or threat and risk assessments,” Cooper wrote.

“This may be a problem related to communication between Shared Services ICT and directorates and agencies, who own the data in the systems.

“There is great scope for expanding the use of system security plans and threat and risk assessments given how few have been prepared.”

“Whole-of-government information security roles and responsibilities and communication processes are not overall well defined and documented; this hinders communication,” Cooper noted.

Shared Services ICT agreed to prepare roles and responsibilities documents and seek to establish mandatory website hosting requirements by 1 January next year.

A spokesperson for the unit reported that it would complete a “significant body of work on policy, protocols and procedures for mobile technology” by 1 October 2012.

Shared Services ICT also agreed to evaluate whole-of-government electronic records management options to improve record keeping, security and collaboration between directorates.

Copyright © iTnews.com.au . All rights reserved.


ACT Govt repels over one million intrusions
eye on systems
 
 
 
 
Top Stories
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
Review: Sydney's Opal smartcard
It's no Oyster card.
 
Rackspace puts price premium on Aussie public cloud
At least 17 percent more compared to US instances.
 
 
eye on systems
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  64%
 
No
  36%
TOTAL VOTES: 61

Vote