iTnews

WA govt taking weeks to remove system access for ex-staff: audit

By Justin Hendry on Aug 5, 2021 4:31PM
WA govt taking weeks to remove system access for ex-staff: audit

Failings in access management uncovered.

Access management practices have been exposed within the WA government, with three departments found to be taking weeks – and even months – to off-board staff from IT systems.

In a staff exit controls audit, the WA auditor found the departments had failed to minimise information security risks as staff access to systems was not always cancelled in a “timely” fashion.

“It took between two and 161 days to deactivate or withdraw access to information systems after staff left the entity,” the report [pdf] released on Thursday said.

“This increases the risk of unauthorised access and can compromise the confidentiality, integrity and availability of the entities’ information.”

The audit sampled 83 staff and contractors who had left the departments of Planning, Lands and Heritage (DPJH); Finance; and Local Government, Sport and Cultural Industries (DLGSC).

Of the three departments, DLGSC was the worst offender, recording “insufficient information to determine when access to IT systems was cancelled for all 30 people in [its] sample”.

“System logs showing the dates of when this occurred were not recorded,” the report said, adding that it was able to determine only one person had accessed the system four days after their exit.

DPLH took between one and 124 days to cancel system access after an individual had left, where information was available.

For the most part, however, the department “did not routinely record specific dates when IT access [was] cancelled”.

“For 10 of our sample, there was no information to determine when access was cancelled,” the report said.

Meanwhile, Finance took an average of seven days to cancel access to systems, though in one case – which related to a secondment where the employee continued to perform work – it took 161 days.

The audit office was unable to determine when another 10 people – representing 38 percent of the people in the sample – had their access cancelled due to “insufficient information”.

Finance policy currently asks that IT access for terminated staff be disabled on the last day of employment, which the audit found was not always the most appropriate target.

“In some cases, this may mean people continue to have access while clearing their remaining leave when they should have no need to access systems,” the report said.

“This increases the risk of unauthorised access and weakens controls over inappropriate use.”

The audit was also unable to verify whether staff had returned all IT assets to the three departments upon their departure due to “insufficient records”.

At the DPLH, 15 people – or more half the 27 staff sampled – had “left with no evidence of laptop return or what was issued”, while at DLGSC there was only evidence for six of the 30 staff sampled.

Finance was able to “demonstrate that 19 of 26 staff in [the] selected sample returned their IT equipment”, though seven did not have adequate documentation.

The auditor has recommended that all three departments ensure access to IT systems is removed or disable immediately when staff leave and clearly record this.

It has also asked that departments maintain a register of all assets issued to staff and ensure assets are returned upon exit.

All three departments have agreed.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
access controlsauditgovernmentitsecuritystate governmentstrategywawa government

Partner Content

Don't miss Australia’s premiere IoT Conference on 9th June
Promoted Content Don't miss Australia’s premiere IoT Conference on 9th June
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Justin Hendry
Aug 5 2021
4:31PM
0 Comments

Related Articles

  • WA registry system flaws force auditor to delay findings by 18 months
  • NSW gov cyber security progress "insufficient", audit finds
  • WA Education forced to restart schools system overhaul
  • WA gov gives digital capability fund $400m top-up
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

Kmart Australia re-platforms ecommerce site to AWS

Kmart Australia re-platforms ecommerce site to AWS

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

Digital Nation

COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.