governmentnews.com.au

Wikileaks forces governments to reconsider IT security

Published on Fri, 03/12/2010, 11:18:24

|

By Lilia Guan
 
The publication of more than 250,000 sensitive documents from the US Embassy has raised concerns about government IT security.
 
Non-profit whistle blowing agency, Wikileaks, released confidentail documents, giving the public an insight into the US Government’s foreign activities.
 
A spokesperson from the Attorney-General’s Department confirmed with Government News the leak was currently being  being investigated by US authorities. The documents leaked are US-classified material. 
 
“The sort of offences that could be relevant may include offences relating to the unauthorised use or disclosure of classified information,” he said.
 
In Australia the protection of Government information systems was one of the three key objectives of the Government’s Cyber Security Strategy, the spokesperson said.
 
“The Government relies heavily on information and communication technology to deliver its services and agencies must actively manage security risks associated with electronic data transmission, aggregation and storage,” he said.
 
However as indicated in the Cyber Security Strategy, the Government was reviewing its protective security policy to ensure that its information security policies and standards continue to reflect international best practice.
 
The spokesperson said in June this year, the Australian Government released a new Protective Security Policy Framework.
 
The Framework aimed to create "an appropriate security culture amongst government agencies, setting out the mandatory protective security, including information security, requirements expected by Government".
 
“The Government was progressively reviewing the information security policies and procedures which support this framework,” the spokesperson said.
 
“The work began some months ago and the lessons of this most recent incident will be an important input into this process.”

 However no organisation should feel 100 percent confident that this won’t happen to them, According to the CIO of South Australia, Andrew Mills.
“It’s worrying when something like this happens,” he said.
 
“I don’t think any of us should be confident that this won’t happen [within own organisation]. This happened to two of the most secure [government] organisations in the world.”
 
Mr Mills said organisations implement technology based on risk and the IT department has to balance that risk with their budget.
 
“I don’t think you’ll ever be able to get rid of the human aspect [within security].”
 
According to Mr Mills IT departments had to ensure useability, without locking down the system to tightly.
 
“There’re balances that need to be checked with whatever technology you put in,” he said.
 
Data secuirty vendor Imperva's data security expert, Robert Rachwald, said the Wikileaks could happen to any government around the world.
 
“What happened was there was too much trust put in the hands of single low level military personnel,” he said.
 
“[Within a six month period] he was able to download privileged information and recognised the value of what he had.”
 
Mr Rachwald said too much IT “privilege” was given to a single user and there were “no checks and balances” in place to stop him from being able access corporate data.

1,472


Your Vote

What are your procurement priorities for 2012?

IT implementations

Infrastructure

Green implementations

Security for property

Ugrading fleets



CONFERENCES & EVENTS

SPLASH! Pool & Spa Trade Show

25-26 July 2012, Jupiter’s Casino & Hotel

Read More »

AHPM Congress

13-14 August 2012 Doltone House, Sydney www.ahpmcongress.com.au

Read More »
COURSES & TRAINING

Contract Governance Education Programs

CPLi is a specialist provider of professional contract governance education programs and consulting services.

Read More »

Government funded business and management qualifications.

ITCC has a range of business and management qualifications, some of which are government funded. If eligible, Federal Government funding will cover the total cost of some of the below qualifications for you or your staff.

Read More »

Take the Pain out of Managing your Training

Partner with mytraining.net we help take the headache out of multi-quotation requirements & streamline training reservations

Read More »
SECURITY PROFILE

ADT Security Solutions

ADT Security can provide Government Security solutions such as Grade A1 monitoring, Type 1 certified installation and monitoring.

Read More »
GREEN PROCUREMENT

Zero emissions sweeper

The Green Machines 500ze is a Lithium-ion powered vacuum street sweeper, heralds a significant step in the drive for reduced carbon emissions and improved air quality.

Read More »
NEW PRODUCTS

Fujitsu General launches AIRSTAGE VR-II heat recovery system

Bringing its expertise to life at ARBS, global air conditioning specialist Fujitsu General has launched its AIRSTAGE VR-II heat recovery system.

Read More »

New Cat M Series

Now factory-fitted with AccuGrade-ready components – at no extra cost.

Read More »

Isuzu - The One For Low Emissions

Scratch the surface and it's easy to see that not all truck manufacturers are created equal in terms of exhaust emissions.

Read More »