Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
The objective of this audit is to determine whether Services Australia is effectively managing privileged user access to mitigate cyber security risks.
Please direct enquiries through our contact page.
The objective of this audit is to determine whether the Australian Taxation Office (ATO) is effectively managing privileged user access to mitigate cyber security risks.
Please direct enquiries through our contact page.
The objective of this audit is to determine whether the Department of Home Affairs (DHA) is effectively managing privileged user access to mitigate cyber security risks.
Please direct enquiries through our contact page.
The audit objective was to assess selected entities’ compliance with the four mandatory ICT security strategies in the Australian Government Information Security Manual (ISM).
Please direct enquiries relating to reports through our contact page.
This edition of audit insights covers audit reports tabled in Parliament during the fourth quarter of 2017–18 with a focus on the key learnings relating to cyber resilience. Cyber security is an increasing risk across government and one that requires attention by Accountable Authorities.
Please direct enquiries through our contact page.
Section 41 of the Auditor-General Act 1997 establishes the position of the Independent Auditor. The Independent Auditor report, Review of Cyber Security, was tabled in Parliament on 4 December 2017.
Please direct enquiries through our contact page.
- In order to mitigate cyber security incidents caused by cyber threats and meet the mandatory requirements of the framework, non-corporate Commonwealth entities must prioritise the implementation and maturity level of their Essential Eight mitigation strategies to strengthen their cyber security posture and manage the evolving threat environment.
- Cyber security contract terms and conditions that associate performance measures and financial consequences for non-compliance can assist with establishing performance expectations.
- Assurance arrangements such as the Cyber Threat Assurance Program approach established by ATO to check on the implementation of mandatory PSPF cyber security requirements can assist with monitoring of compliance against cyber security contract requirements.
- Manage cyber risks systematically, including through assessments of the effectiveness of controls, security awareness training, and adopting a risk-based approach to prioritise improvements to cyber security.