iTnews
  • Home
  • News
  • Business
  • Strategy

Gov readies cyber hub expansion, stops certifying internet gateways

By Justin Hendry on Nov 2, 2021 12:05PM
Gov readies cyber hub expansion, stops certifying internet gateways

Makes change to strengthen network defences.

Australia’s cyber spies will stop certifying secure internet gateway (SIG) services in preparation for the centralisation of federal government networks through a series of cyber hubs.

The Australian Signals Directorate and Digital Transformation Agency revealed the policy change on Monday, paving the way for an expansion of the hub model from as early as July next year.

Cyber hubs were first flagged in the government’s cyber security strategy last year to reduce the number of target networks and allow it to focus investment on a smaller network footprint.

They are seen as critical to uplifting the cyber security of public sector networks, complementing work to implement the Essential Eight controls which has proved difficult for agencies of all sizes.

Since July, the government has been piloting three cyber hubs in Defence, Home Affairs and Services Australia to inform a future whole-of-government operating model by testing core services.

But even as the 12-month pilot continues at the three agencies, the government’s SIG policy has now been “modernised” to ensure it is “consistent with and supports the implementation of cyber hubs”.

“It is envisioned that the future cyber hubs operating model… will see cyber hubs providing a range of cyber security services, including SIG services, to non-corporate Commonwealth entities,” ASD and the DTA said in a statement.

“As such, consideration is being given to how SIG services should integrate with a future cyber hubs model.

“DTA will provide timely advice to Commonwealth entities, cyber hub providers and industry during the government’s development of cyber hubs subject to government approval.”

With the hubs expected to “centralise the management and operations of Commonwealth entities for cyber monitoring, detection and response capabilities”, ASD “will no longer progress re-certification activities” for commercial or government SIGs.

Existing certified gateway providers – Emantra, Macquarie Telecom, NTT, Optus, Sliced Tech, Telstra and Verizon – will remain certified until ASD’s role as certification authority ceases on 1 July 2022.

The two agencies said the changes would better enable and encourage agencies using existing SIGs to the adopt “emerging cyber security technologies and capabilities” 

“Entities will be empowered to adopt a new risk-based authorisation model, consistent with the consideration of other cyber architecture such as the adoption of cloud environments,” they said.

“Security guidance, co-designed by the Australian Cyber Security Centre with government and industry from key stakeholder groups, will be developed through consultative forums to support the policy enhancements.” 

The agencies said the model aligned with the approach they had adopted for cloud services since ditching the cloud services certification program in early 2020 to remove bottlenecks.

Changes to ASD’s role as the SIG certification authority comes two-and-a-half years after the DTA last reviewed the government's shared gateway scheme to give agencies more flexibility.

The then policy mandated a core internet gateway reduction program for all agencies, but  granted them the freedom to deploy services that best served their cyber security posture.

The DTA is now expected to work with the Attorney-General’s Department and the Australian Cyber Security Centre to ensure the new SIG policy aligns with the protective security policy framework.

“In the interim, entities will continue to meet their SIG requirements in line with the PSPF obligations, and existing industry partners will continue to provider services in line with current arrangements,” ASD and the DTA said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
acscasdcyberdtafederal governmentgatewaygovernmentitsecuritystrategy

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Why rethinking your CMS is crucial for customer retention
Promoted Content Why rethinking your CMS is crucial for customer retention
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • Micro Focus Information Management & Governance (IM&G) Forum 2022
  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
  • Forrester Technology & Innovation Asia Pacific 2022
By Justin Hendry
Nov 2 2021
12:05PM
0 Comments

Related Articles

  • Sovereign push for gov cyber hubs ahead of expansion
  • Defence cancels SkyGuardian drones to fund REDSPICE cyber plan
  • Cyber basics still beyond fed gov as Essential Eight mandate looms
  • Oracle accredited 'certified strategic' gov cloud provider
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

NBN Co taking orders for 'non-premises' connections

NBN Co taking orders for 'non-premises' connections

Australian scientists build world's first quantum computer IC

Australian scientists build world's first quantum computer IC

Digital Nation

IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
The security threat of quantum computing
The security threat of quantum computing
COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.