Select Page

Audit: ANAO finds Services Australia lacking in cyber and cost aspects of WPIT | ZDNet

Audit: ANAO finds Services Australia lacking in cyber and cost aspects of WPIT | ZDNet

Australian Audit Report September 25 2020

ANAO finds Services Australia lacking in cyber and cost aspects of WPIT

Services Australia did not apply an appropriate framework to manage cyber security risk.

ANAO Services Australia Audit Report: System Redevelopment — Managing Risks While Planning Transition
Reported in: ANAO finds Services Australia lacking in cyber and cost aspects of WPIT | ZDNet
More reports from ZDNet.

Key InfoSec Finding: “Services Australia had largely appropriate arrangements to manage risks to operating the welfare payment system. Services Australia established and maintained a risk management framework at the entity and group levels that applied to various elements of the welfare payment system. Payment correctness and system availability risks were managed. Services Australia did not apply an appropriate framework to manage cyber security risk, and did not monitor the cost of operating the system.”

Australian National Audit Office (ANAO) on Thursday handed down its examination of the Services Australia Welfare Payment Infrastructure Transformation (WPIT) program, finding the agency had “largely appropriate arrangements” in many areas, but was lacking on the cyber and cost monitoring fronts.

Kicked off in 2015, WPIT was originally slated to cost around AU$1.5 billion and run from 2015 to 2022, with one of the core reasons for the program being to replace the then-30-year-old Income Security Integrated System (ISIS).

On the cyber front, the report found there were no cybersecurity plans specific to each element of the system.

“However, Services Australia self-assessed that it ‘has measures in place for the underpinning components including monitoring of vulnerabilities and appropriate patching, monitoring of system administrative and privileged access, and penetration testing of outward facing systems’,” the ANAO wrote.

About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More Australian News

Weekly Australian News and Monthly Incident Review Emails

No advertisements, marketing, sales, or unsolicited emails. Your email address is ONLY used to send the publications listed above.

* indicates required


Shares
Share This