惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
博客园 - 司徒正美
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
The Cloudflare Blog
月光博客
月光博客
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
罗磊的独立博客
雷峰网
雷峰网
博客园 - 叶小钗
量子位
IT之家
IT之家

Government

Australia’s proposed digital duty of care bill “a global reckoning coming for big tech,” says minister If you build it… Tasmania sets the state’s expectations for data centres and AI infrastructure Digital platforms to be targeted as part of NSW crackdown on organised crime operations Forget about it: Data erasure rights a key feature of new draft privacy laws Australians to gain greater control over compromised identity documents with new IDLock scheme Australia & Thailand to strengthen cooperation on fighting cybercrime Hack on! Private US companies given Presidential go-ahead to target cyber criminals Artificial intelligence: South Australian Premier announces Royal Commission into AI Artificial intelligence a key area of Australia’s 2026 Defence Innovation, Science and Technology Strategy Australia’s eSafety Commissioner sues Telegram over terror content AI and cyber security key talking points at recent talks between Singapore & Australia Always watching: Vic state government targets spying bosses and online bullies Qld government announces new digital project governance bodies Child protection advocates call for faster action on digital duty of care laws Cyber resilience a key plank of new Nakamal Agreement between Vanuatu and Australia ACMA targets SMS scams, emergency services, and telco protections in 2026–27 compliance agenda Exclusive: Pauline Hanson’s One Nation party quietly deletes Labor hacking claims Privacy Commissioner rules Medmate and Monash IVF breached privacy law through tracking pixels Australian government, Microsoft sign agreement strengthening cyber security Tony Burke announces ‘new program of work’ under Horizon 2 of the Australian Cyber Security Strategy AFCA to become Australia’s central scams complaints body under new prevention framework Pentagon’s new Department of Defense Cyber Defense Command could be a good model for Australia Be counted: Australia’s next census faces cyber security shortcomings Aussie government proposes automatic reimbursement for scam losses below $3,000 Op-Ed: Australia’s cyber law is stuck in the past – the Slay Review is our chance to fix it ACCC welcomes another year of funding for the National Anti-Scam Centre Budget 2026: Expectations around AI, SMB resilience, and national defence Australia strengthens cyber defence in multinational operation New Zealand announces new sanctions against Russian cyber actors, online support platforms Op-Ed: Australia’s next budget must treat cyber resilience as essential infrastructure
Australia’s Department of Parliamentary Services has only...
David Hollingworth · 2026-06-15 · via Government

DPS says it will “address critical cyber, information security and operational resilience risks” in wake of ANAO review.

Australia’s Department of Parliamentary Services has only “partly effective” cyber security stature, audit finds

The Department of Parliamentary Services has said it agrees with all the findings of and recommendations made following a recent cyber security audit by the Australian National Audit Office.

According to the ANAO, previous audits had found gaps in identity management, and the office felt an ongoing assessment was necessary given emerging risks.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

What this audit found was more than a little alarming. The ANAO found that despite DPS managing more than 10,000 end-user devices used by almost 5,000 users, seven strategies out of the Essential Eight were “Implemented below the standard required”.

“The Essential Eight cyber security strategies were not fully implemented in accordance with the requirements of the Protective Security Policy Framework,” the ANAO said in its findings, which were published on June 11.

“The department was relying on compensating controls without adequate coverage of all systems and risk management of identified vulnerabilities.”

Despite the department establishing proper governance processes, the effectiveness of the DPS’s risk assessment, acceptance and communication was found to be lacking.

Similarly, the ANAO found an outdated policy framework and a limited ability to adequately “apply controls and governance for some of the users it supports”.

Part of the issue, the ANAO said, was the DPS’s varied user base, which includes Parliamentarians, their staff, and other entities.

“The differing business and security requirements of these user groups were not reflected in the department’s IT environment. DPS experienced significant turnover in ICT staff in the previous 18 months,” the ANAO said.

“Some technology platforms supporting key business functions require risk-managed operation due to lifecycle constraints, and inventories of key information, assets and risks were outdated.”

The ANAO recommended that the DPS review its governance and risk assessment processes and develop a risk-based program to uplift its security posture to achieve compliance with the government’s Protective Security Policy Framework.

The DPS has agreed to all recommendations.

“DPS is committed to working collaboratively with partners across the Parliament and government to strengthen cyber security practices through a program of continuous improvement,” Jaala Hunchcliffe, Secretary of the DPS, said in a letter of response to the audit.

“This will further support strengthening of systems and processes in alignment with Australian Government standards through embedding Information Security Manual controls and progressing actions to increase our maturity level with the Australian Signals Directorate’s Essential Eight Security Model.”

You can read the full results of the audit here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.