262 Items found
Due to table: April 2027
Open for contribution

The objective of this audit is to determine whether Services Australia is effectively managing privileged user access to mitigate cyber security risks.

Entity
Services Australia
Contact

Please direct enquiries through our contact page.

Due to table: April 2027
Open for contribution

The objective of this audit is to determine whether the Australian Taxation Office (ATO) is effectively managing privileged user access to mitigate cyber security risks.

Entity
Australian Taxation Office
Contact

Please direct enquiries through our contact page.

Due to table: April 2027
Open for contribution

The objective of this audit is to determine whether the Department of Home Affairs (DHA) is effectively managing privileged user access to mitigate cyber security risks.

Entity
Department of Home Affairs
Contact

Please direct enquiries through our contact page.

Published: Thursday 5 May 2016
Published

The audit objective was to assess selected entities’ compliance with the four mandatory ICT security strategies in the Australian Government Information Security Manual (ISM).

Entity
Australian Federal Police (AFP); Australian Transaction Reports and Analysis Centre (AUSTRAC); Department of Agriculture and Water Resources; Department of Industry, Innovation and Science
Contact

Please direct enquiries relating to reports through our contact page.

Published: Friday 20 July 2018
Published

This edition of audit insights covers audit reports tabled in Parliament during the fourth quarter of 2017–18 with a focus on the key learnings relating to cyber resilience. Cyber security is an increasing risk across government and one that requires attention by Accountable Authorities.

Contact

Please direct enquiries through our contact page.

Updated: Friday 22 July 2022
Updated

Section 41 of the Auditor-General Act 1997 establishes the position of the Independent Auditor. The Independent Auditor report, Review of Cyber Security, was tabled in Parliament on 4 December 2017.

Contact

Please direct enquiries through our contact page.

  • In order to mitigate cyber security incidents caused by cyber threats and meet the mandatory requirements of the framework, non-corporate Commonwealth entities must prioritise the implementation and maturity level of their Essential Eight mitigation strategies to strengthen their cyber security posture and manage the evolving threat environment.
  • Cyber security contract terms and conditions that associate performance measures and financial consequences for non-compliance can assist with establishing performance expectations.
  • Assurance arrangements such as the Cyber Threat Assurance Program approach established by ATO to check on the implementation of mandatory PSPF cyber security requirements can assist with monitoring of compliance against cyber security contract requirements.
  • Manage cyber risks systematically, including through assessments of the effectiveness of controls, security awareness training, and adopting a risk-based approach to prioritise improvements to cyber security.