The Australian Taxation Office (ATO) has set a governance framework that supports ongoing management of its Tax Agent and Business Portals, while its strategic and business planning activities offer clear direction and guidance for their future development.
But the Australian National Audit Office (ANAO) believes the ATO could do better on documenting the roles and responsibilities of the Portals' business owners and key internal stakeholders, and on improving its performance measurement framework.
Acting Auditor-General Steve Chapman recommended the ATO clearly articulate roles and responsibilities in the interests of achieving a more coordinated approach to managing the Portals.
"Developing specific performance measures for the Portals will better inform management decision making, particularly regarding future investment in the Portals," he said in a new audit report, Tax Agent and Business Portals.
The Tax Agent and Business Portals give tax agents and businesses a gateway to online services like access to tax information and the ability to complete a range of online transactions in a secure environment 24 hours a day, seven days a week.
The latest audit report finds the ATO has been responsive to the need to improve information access for tax agents and expended a considerable effort in quickly developing the Tax Agent Portal. Overall, survey results have shown tax agents' satisfaction with and use of the Portal is high and increasing, and tax agents have experienced savings from using the Portal.
But it finds the ATO needs to go further in introducing measures to reduce risk.
"The ATO in introducing the Tax Agent Portal aimed to achieve a balance between uptake of the Portal and IT security (i.e. secure online access to taxpayer information). Access to business systems data via the Internet exposes the ATO to an increased level of risk. The ANAO considers that although the ATO has introduced a range of IT security and user access controls, these controls need to be strengthened in several areas to better protect the integrity of the ATO's business systems," the report said.
The ANAO is also urging the ATO to adopt a more systematic, directed, and comprehensive approach to IT security planning. It says the ATO should define the roles and responsibilities of system owners and other key stakeholders to support a coordinated approach to future Portals IT security planning.
And it concludes while the ATO has implemented appropriate internal application security controls for Portals users, which restrict user access to functionality within the application, the ATO does not maintain security baselines for all key system security components. The ATO has issued security baseline guidelines for some components, but has not established a formal process for monitoring compliance with the guidelines.
"The ANAO considers that, without formalised security baselines for all key system security components and ongoing compliance and security enforcement measures, the ATO, through operation of its Portals, may be exposed to a higher level of IT security risk than is considered acceptable," the report says.
It also wants the ATO to improve its practices supporting the administrator function, user access. It notes the ATO's own reviews have also identified a lack of sufficient mechanisms to ensure consistency in the process for the authorization and revocation of Portals user access, and the monitoring and review of internal user access.
The ATO needs to be able to produce a clear and meaningful end-to-end view of a user's actions within the Portals to enable the reconstruction of events and to provide an adequate audit trail of user transactions. The report says this is particularly important when reviewing transactions performed to detect possible security breaches. The ATO is undertaking a project to establish processes that will enable a complete view of a user's actions within its systems, including the Portals.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Solve Exchange Mailbox Storage Issues Once and for All
Email Archiving 101—Customer Case Study
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Everything you need to know about email and web security (but were afraid to ask)
Gaining Competitive Advantage Through Enterprise Planning
Best Practice in Building an Integrated Information Management Strategy
Enterprise Wireless WLAN Security
Delivering the Power of Choice with Microsoft Dynamics CRM
- White PaperWhat you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
- White PaperLearn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
SOA What? Why You Need SOA Governance Framework 04 December, 2008 08:32:00
Adopting services oriented architecture (SOA) in your enterprise without thinking through IT governance can cause something like the Gold Rush in the 1800s; extreme rates of growth and minimal law and order which produce unexpected outcomes. - +
The Myth of Cloud Computing 04 December, 2008 08:25:00
Why the rapid spread of virtual technology is becoming a security riskWhy the rapid spread of virtual technology is becoming a security risk. - +
Who Pushed Vendors Toward Better Security? 04 December, 2008 09:38:00
Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann DavidsonHint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson. - +
CPO & CISO: A Comprehensive Approach to Information 04 December, 2008 08:42:00
GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets. - +
Virtually every Windows PC at risk, says Secunia 04 December, 2008 08:00:00
Almost all PCs scanned by patch tool have an unpatched app; 46% have 11-plus.More than 98% of Windows computers harbor at least one unpatched application, and nearly half contain 11 or more programs at risk from attack, a Danish security company said Wednesday.
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 05 December, 2008 13:00:00
International researchers gather in Sydney to preview the clever web 05 December, 2008 09:48:00
Borderless corporate networks to shift focus to secure content management in Australia in 2009 04 December, 2008 16:06:00
IDC Says Asia/Pacific Excluding Japan IT Market Will Remain The Bright Spot... 04 December, 2008 15:04:00
MySpot SOS "Panic Button" Smartphone Application could save lone worker lives 04 December, 2008 13:34:00
|
||
|
||
|
|
||
|
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
IT executives face the need to improve service delivery with limited resource increases. Two common strategies for achieving this are network and systems management tools and datacenter consolidation. Read on to disocover how you can make a strong business case for IT Consolidation.
















