iTnews
  • Home
  • News
  • Technology
  • Security

Auditor-General slams Vic Govt data security flaws

By Ben Grubb
Nov 26 2009 9:57AM
Follow google news

No CIO + no security policy = huge risks.

The Victorian Auditor-General has observed “fundamental flaws” within the Victorian Government’s handling of IT security.

In a report entitled Maintaining the Integrity and Confidentiality of Personal Information, the Auditor-General said information from within three Victorian Government departments, including the Premier's, had been stored on portable storage devices, CDs and DVDs that were vulnerable to loss and in easily-read formats.

Personal information was also exchanged via personal email accounts, some of which were "particularly vulnerable" to unauthorised access, the Auditor General said.

“While we examined only three departments, the ability to penetrate databases, the consistency of our findings and the lack of effective oversight and coordination of information security practices strongly indicate that this phenomenon is widespread,” the Auditor-General said in the report.

“Extracts or whole copies of personal information from the selected databases were stored in unsecured shared drives on departmental networks accessible by unauthorised staff.”

Auditor-General slams Vic Govt data security flaws

Poor password management, poor physical security of servers (one had been stored behind a front reception desk), no mandatory use of antivirus software for remote access and 'protected' data held off-site in a home office had all contributted to the security failings.

The report concluded that the confidentiality of personal information collected and used by the public sector could be, and had been, "easily compromised".

It said that the issues had arisen partly because information security policy, standards and guidance for the sector were incomplete and "too narrowly focused on ICT security".

"Neither the Department of Treasury and Finance nor the Department of Premier and Cabinet have addressed all aspects of information security following the disbanding of the Office of the Chief Information Officer and its supporting committees in 2006," it said.

"In the absence of strong and consistent central leadership and effective oversight, the importance of protecting personal information has not been properly understood by the sector."

Victorian Premier, John Brumby, said the report sent a "very strong signal" to all departmental and agency heads about the "importance" of the issue.

"The Auditor-General has highlighted these concerns, and we are acting on them," he said.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
auditorgeneraldataflawsgovernmentsecurityslamsvictorian

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.