Government Weak on IT Security: WA Auditor General
- 16 April, 2009 17:26
- Comments
The WA Office of the Auditor General has slammed the privacy practices of government agencies saying that in many, fundamental weaknesses in all of the key areas of information security are present.
The announcement follows the tabling in parliament of the Auditor General’s Information Systems Audit Report today.
The report consists of two parts, IS Compliance Audit, and General Computer and Application Controls Audits, both of which found serious concerns over the management of privacy and security.
Auditor General Colin Murphy said the results of the IS Compliance Audit section revealed fundamental weaknesses in all of the key areas of information security.
Specifically, the report found that three out of the five agencies lacked IT security policies, and none of the agencies consistently applied simple administrative controls such as police checks or confidentiality agreements for staff dealing with personal or sensitive information.
Also, none of the agencies had adequate controls over the transfer of personal and sensitive information to portable USB devices such as thumb drives which can be easily lost or stolen.
The results of the General Computer and Application Controls Audits section of the report, which reviewed 65 agencies and benchmarked 41 against accepted good practice for IS management, found that nearly 60 per cent of agencies failed to meet the benchmark. Some 46 per cent of agencies had not established effective controls for change management and 33 percent had not established effective controls for management of physical security. “By failing to address fundamental control weaknesses, agencies leave themselves vulnerable to computer system failures, unauthorised access to information, loss of information and fraudulent activity,” Murphy said in a statement.
“I expect agencies across government to take note of the findings and recommendations of this report.”
The report can be viewed here
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Top 5 Server Monitoring Battles—and How You Can Win Them
- CISO Guide to Next Generation Threats - Combating Advanced Malware, Zero-Day and Targeted APT Attacks
- Advanced Malware Exposed - How advanced malware, zero-day and targeted APT attacks are evading today's network defences
- Managing Trust - Data protection and compliance for financial services
- Case Study: HJ Heinz
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Social networking, ignorance, and apathy
-
China's Alibaba sees big growth with AliExpress site
-
10 Tips for Dealing with a Bully Boss
-
How to design a successful RACI project plan
-
Becoming a Social Business
As global business accelerates ever faster and companies work to quickly respond to customer demands, competitive threats and rapidly evolving trends, the richness and efficiency of social collaboration plays a key role in enabling future success. The challenge then is finding the best approach. Read on. -
Essar Group - Essar Group executives enjoy printing on the move
Essar Group’s senior management are constantly on the road. So it’s not surprising that the company has become a heavy user of mobile computing solutions to enable them to get their job done. The mobility and productivity of executives; enable them to easily print documents from any company location to any company printer using their smartphone. Read more. -
Business Process Management, Service-Oriented Architecture, and Web 2.0: Business Transformation or Train Wreck?
As a result of more and more organisations adopting new technologies and business practices surrounding BPM, SOA, and Web 2.0, fundamental changes have arisen in the way IT and business stakeholders work together. Make this into an opportunity - read on.
-
Microsoft Office
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition








Comments
Post new comment