Select Page

Audit: Cyber basics still beyond fed gov as Essential Eight mandate looms | iTnews

Audit: Cyber basics still beyond fed gov as Essential Eight mandate looms | iTnews

Australian National Audit Office Report June 10 2022

Cyber basics still beyond fed gov as Essential Eight mandate looms

Audit finds most controls “still significantly below” requirement.

Australian National Audit Office Report: The Auditor-General Auditor-General Report No.32 2021–22 Financial Statements Audit
Reported in: Cyber basics still beyond fed gov as Essential Eight mandate looms | iTnews
Read more Audit Reports

Federal government agencies are continuing to struggle to implement the ‘Essential Eight’ cyber security controls, with only two of 19 agencies recently examined by the national auditor making the required grade.

A total of 36 IT control environment findings were reported to the entities comprising no significant, 10 moderate, 26 minor. the majority of the findings are related to the management of user terminations, logging and monitoring of privileged users, and password management.

Reported compliance with the PSPF Policy 10 requirements

IT Control Environment 0

10 26
IT Security 0

9 21
IT Change Management 0

1 4
Disaster Recovery Arrangements 0

0 1

 
ANAO E8 yearly trend

The ANAO noted that a parliamentary inquiry last year had recommended the need for greater accountability of the cyber security requirements, including over the self-assessment process.

“While entities’ compliance with PSPF cyber security requirements remains low, there continues to be the risk of compromise to information,” it said.

From July 2022, non-corporate Commonwealth entities will be expected to implement Essential Eight maturity level two mitigations to achieve a managing maturity rating under Policy 10 part of the protective security policy framework (PSPF).

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Exclusive: New Zealand Sotheby’s International Realty investigating cyber security incident

Prolific hacker 2019 claims hack of a luxury Kiwi real estate firm, but the company says the hacker is overstating the extent of the breach. • Mon, 24 … [...]

Public backlash over police AI surveillance trial | A Current Affair

An Australian-first trial of live facial recognition technology in WA has led to 18 arrests in just seven days, but privacy experts are sounding the alarm. (Broadcast AUGUST 15, 2026) [...]

Origin energy data breach update | Slump in Inghams’ annual profit

An update on last month's Origin Energy data breach, which impacted around 900 thousand customers. The company says 60 full bank account numbers and 100 identity document numbers were accessed, [...]

The industry speaks: Scam Awareness Week 2026

The theme for this year’s Scam Awareness Week – which runs from 24 to 28 August – is “No one’s just a number”, and that’s certainly true of the … [...]

Have I Been Pwned: Oz Hair and Beauty Data Breach

Have I Been Pwned In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently … [...]

Dozens of Origin Energy customers' full bank details, ID numbers accessed in July breach

Origin Energy says as many as 60 customers had their full bank account numbers accessed by a hacker in July. Last month, Origin confirmed a major … [...]

Exclusive: Ransomware newcomers list South Australia’s Ramsey Bros as hacking victim

The Storm ransomware group claims to have hacked an Australian farm machinery supplier and has allegedly published customer data and vehicle … [...]

Oz Hair and Beauty confirms cyber incident to customers

Aussie hair and beauty business Oz Hair and Beauty has disclosed to customers that it has suffered a cyber incident. • Thu, 20 Aug 2026 • … [...]

NSW drivers licence photos could be part of national database under new laws

The New South Wales government is planning to join a national facial recognition service, aimed at preventing identity fraud, as part of a wider bill … [...]

Quest Apartment Hotels customers' personal data exposed in security breach

Quest Apartment Hotels says it is investigating a security breach that has affected customers' personal data. In an email to customers, seen by ABC … [...]

Fake ABC News articles are promoting scams. The money leads to an international fraud network

Hooked up to a drip and awaiting surgery, Rodger was running out of options. "You guys have all of my money tied up," he texted his broker. "I need … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading