Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Feds, Microsoft sign whole of govt security deal

The Australian federal government has signed a whole-of-government agreement with Microsoft to exchange information on security issues ranging from cyberterrorism and general security bulletins.

As part of the arrangement, Microsoft will provide the Australian federal government with a monthly security bulletin and in return Microsoft will have closer contact with government agencies to learn how Microsoft products are being used and operating.

The alliance, dubbed the Security Cooperation Program (SCP), is the first whole-of-government agreement for Microsoft.

Announcing the agreement, Attorney General Phillip Ruddock said the SCP is one way to remain ahead of hackers and criminals "who seek to exploit information technology systems for their own benefit or to inflict harm on our community".

"The SCP would help defend government systems against terrorists who may be planning to break into computer systems to shut down markets, or disrupt water or electricity services."

All federal government agencies are immediately part of the agreement. State and territory governments can also sign up to the SCP.

Peter Watson, Microsoft Australia's chief security advisor, confirmed its participation in the SCP will not supersede any existing government agencies such as AusCert or the DSD. The DSD will be a key part of the program due to existing ties with the Critical Infrastructure Protection Branch.

Watson said in regards to this agreement, (Australia is just one of 14 different countries participating in the SCP), the standard program has been tweaked to ensure the DSD is a central point of contact for the SCP to deal with the government.

"The focus is around our security product set; we do not ask what other (non Microsoft) products are used, but we are interested in seeing broad characteristics to help with trending analysis and what we develop in terms of products and guidance," Watson said.

"What we do is provide a monthly set of consolidated information of what we are seeing of security issues around the world, such as virus infections [through] to things where people might be exploiting known vulnerabilities that we (Microsoft) are doing investigations on.

"Information from all 14 nations is made anonymous then provided to the SCP, because what we are trying to do is share information about vulnerabilities [without] disclosing where they came from."

Hydrasight analyst Michael Warrilow said if the arrangement involves anything more than exchanging information, he has serious concerns. Warrilow said the way it looks at the moment is just a feel-good approach with very little actual merit.

"The Attorney General has already invested in AusCert for Australia and the region as well as the critical infrastructure group whereas the government overall has invested in the Defense Signals Directorate (DSD)," Warrilow said.

"In my opinion these agencies represent a far better means of protecting the government and Australian society."

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: AusCert, Defense Signals Directorate, Microsoft

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Botnets: The dark side of cloud computing
    Botnets pose a serious threat to your network, your business, your partners and customers. Botnets rival the power of today’s most powerful cloud computing platforms. These “dark” clouds, controlled by cybercriminals, are designed to silently infect your network. Left undetected, botnets borrow your network to serve malicious business interests. This paper details how you can protect against the risk of botnet infection using security gateways that offer comprehensive unified threat management (UTM).
    Learn more »
  • IBM zEnterprise System Brings Hybrid Computing Capabilities to Midsize Organisations
    This paper focuses on the IBM z114 cross-tier solution, which brings IBM AIX Unix and Linux workloads into the mix, with Microsoft Windows support to follow in the future. This blended approach to computing allows workloads running on any of those operating systems to communicate more quickly and effectively with the System z, producing business benefits from the orchestration, or coordination, of management for all of the workloads running across all of the linked platforms.
    Learn more »
  • Enterprise Buyers Guide for Cloud Storage
    Customer interest in public cloud storage is increasing, driven by the promise of affordable, elastic storage for archiving, backup/recovery, and disaster purposes. To understand the types of offerings available and to assist buyers with purchasing decisions Computerworld has prepared a public cloud storage buyers guide.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments