Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
The objective of the audit was to assess the effectiveness of the management of risks arising from the use of PSDs in selected Australian Government agencies. The PSDs included within the scope of this audit were: USB flash drives; CDs and DVDs; external hard drives; laptop computers and smartphones.
- As Australia’s cyber security regulatory landscape evolves and reforms, it is important for an entity to consider how their legal function will support their governance committees during the external reporting process to manage increasing scrutiny and liability risks following a significant or reportable cyber security incident.
The audit objective was to assess the effectiveness of the Therapeutic Goods Administration’s (TGA) application of the Code of Good Manufacturing Practice (Code of GMP) for prescription medicines.
Please direct enquiries relating to reports through our contact page.
The audit objective was to assess the effectiveness of physical security arrangements in selected Australian Government agencies, including whether applicable Australian Government requirements are being met.
Please direct enquiries relating to reports through our contact page.
This first e-newsletter of the Commonwealth Auditors General Group was produced by Sir Amyas Morse, UK Comptroller and Auditor General as guest editor, along with the editorial team of the Auditors General of Australia, Fiji, Jamaica and Tanzania. Cybersecurity is the theme for this newsletter, with articles from the Supreme Audit Institutions (SAIs) of Australia, Malta and the UK.
One of the main purposes of the e-newsletter is to share experiences and establish a dialogue based on the discussions that were started at the 23rd Conference of Commonwealth Auditors General in Delhi. For this edition the conversation is around ‘leveraging technology in public audit’, and it draws on international peers experiences and learnings from conducting cybersecurity audits.
If you have any thoughts on future technical content which you would like to propose, please contact international@nao.gsi.gov.uk
The audit objective was to re-assess the three entities' compliance with the 'Top Four' mandatory strategies in the Australian Government Information Security Manual (ISM). The audit also aims to examine the typical challenges faced by entities to achieve and maintain their desired ICT security posture.
Please direct enquiries relating to reports through our contact page.
- Entities should seek their own assurance over the effectiveness of key cyber security controls. This assurance should consider appropriate sources of evidence that can demonstrate a control is functioning as intended.
- Entities should ensure that the cyber security controls they rely on adequately address the scope of identified risks (or that other mitigating controls address gaps in coverage) and are regularly reassessed to determine their continued effectiveness against current and emerging threats.
Mr Mr Ian McPhee, AO PSM - Auditor-General for Australia, presented an Australian Country Paper at the 6th ASOSAI Symposium in Kuala Lumpur, Malaysia
- Good privacy practices are essential to ensure citizens trust the government to collect and use their personal information appropriately. In an environment of increasing data breaches, cyber threats and malicious actors, entities should regularly assess privacy risks to inform reviews of their privacy management plans and implementation of governance, policies, ICT controls, training, audit and assurance arrangements.