Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
- In establishing specific risk management frameworks for cyber security, the three audited government business enterprises and corporate Commonwealth entities adopted mitigation strategies and controls from the Australian Government Information Security Manual, despite not being mandated to do so. The Reserve Bank and Australia Post went further and adopted aspects of recognised national and international cyber security frameworks applicable to their industry or regulatory environments.
- Cyber resilience requires more than entities being compliant with relevant risk management frameworks and controls. The Reserve Bank has embedded behaviours and practices within its organisation that contribute to a strong cyber resilience culture. ASC has demonstrated a positive attitude to managing cyber risks and an open approach to continuous improvements to cyber security processes and practices.
The ANAO could continue the ANAO’s series of audits on cyber security. The scope would include assessing selected entities’ cyber security frameworks and controls against the controls required under the Protective Security Policy Framework and the Australian Signals Directorate’s Essential Eight Maturity Model.
Please direct enquiries through our contact page.
- Independent timely reporting on the implementation of the cyber policy framework supports public accountability by providing an evidence base for the Parliament to hold the executive government and individual entities to account. The extent of public reporting should be appropriately balanced with the need to manage cyber security risks where adversaries could use published information about cyber vulnerabilities to more effectively target malicious activities. Strong accountability arrangements within government are required in the absence of public accountability through the Parliament.
- Where controls required within a cyber security framework are not being met, entities such as the Reserve Bank and ASC have undertaken a risk assessment to develop mitigating controls, which have proven effective in meeting the intent of the specified controls. Entities can draw on expertise in the Australian Government (such as the Australian Cyber Security Centre) and the private sector for assistance in strengthening cyber security controls.
- Self-assess the Top Four cyber security risk mitigation strategies of the Protective Security Policy Framework using a controls-based approach. If the self-assessment is non-compliance, make the necessary investments and changes to become compliant.
- The effective implementation of cyber security mitigation strategies is underpinned by the identification of assets and risk assessments to identify the level of protection required from cyber threats.
The ANAO could assess the implementation of REDSPICE to expand the range and sophistication of the Australian Signals Directorate’s intelligence and cyber capabilities. The 2024 National Defence Strategy highlighted that space and cyber capabilities play a significant role in safeguarding national security and listed the continued investment in the Australian Signals Directorate through REDSPICE as a capability investment priority. The REDSPICE program was announced in 2022 with $9.9 billion in funding over ten years. The REDSPICE program includes growing the workforce with 1900 new roles, a three-fold increase in offensive cyber capability, improved foundational technologies (including artificial intelligence) and an increased national and international footprint. The ANAO could examine the objectives of the program and the extent to which those objectives have been achieved.
Please direct enquiries through our contact page.
- To meet the mandatory PSPF requirements of mitigating common and emerging cyber threats, it is important for entities to have effective risk management practices for cyber security. This includes conducting assessments of the effectiveness of security controls, security awareness training, and adopting a risk-based approach to prioritise improvements to cyber security.
The objective of the audit was to assess the effectiveness of Australian Government agencies' management and implementation of measures to protect and secure their electronic information, in accordance with Australian Government protective security requirements.