The Australian National Audit Office ANAO

Management of Cyber Security Incidents

2024 AU2024cyberIncidents — Categorised against INTOSAI ICS (GuidICS)
SCALE
  • two entities examined - the financial intelligence agency and the government's main service delivery agency; 19 recommendations, all agreed
  • about 31 per cent of the cyber security incidents reported to the signals directorate in 2022-23 came from non-corporate Commonwealth entities
  • 25 per cent of those entities self-assessed at Maturity Level Two across the eight prioritised mitigation strategies; 82 per cent reported holding an incident response plan
COMPLIANCE
  • the whole-of-government protective security policy framework, which carries the mandatory requirements for managing cyber security incidents
  • the signals directorate's cyber security guidelines and its eight prioritised mitigation strategies
  • the public governance statute under which entities must apply that framework, and the audit statute the report is made under
ECONOMY
  • the backup, logging and event-management solutions in place, and the assurance actually obtained from them
  • monitoring resources set against spending on preventive controls
  • data centres and backup media, and the protection measures documented for them
EFFICIENCY
  • timeframes for triage, escalation and reporting to stakeholders
  • centralised against decentralised event logging
  • retrieval of production and archived security event data
EFFECTIVENESS
  • readiness to maintain business continuity after a significant or reportable incident
  • testing of backup restoration and disaster recovery
  • use made of post-incident learning
  • completeness of the critical asset and data registers
1. Backups are taken daily and have never been restored as a test Business continuity Disaster recovery Testing Procedures

The audit's overall conclusion turns on this one point: 'Neither entity is well placed to ensure business continuity or disaster recovery in the event of a significant or reportable cyber security incident' (p.9). Both run backups. Neither had established that they come back. At the first entity, 'AUSTRAC performs recovery of backups as part of business area requests. It does not perform testing of restoration of backups for disaster recovery purposes. It does not have a process for extracting and analysing production and archive backup data', and it 'has not tested the recoverability of its systems and applications supporting critical business processes' (p.50). At the second, the plans 'do not include all systems and applications supporting critical business processes and it does not test the recoverability of backups' (p.9), and the gap reaches the paperwork as well: 'Services Australia does not have a policy for managing regular backups', whose recovery documentation omits backup solutions from both the security policies and the disaster recovery testing schedule (p.84). A backup that has never been restored is a belief, not a control.

  • Function: Security, IT
  • Value: Assets
  • Stakeholders: Management, Operator
  • Quality: Reliability and availability Sound risk management
2. The continuity plan left out the systems the public actually depends on Business continuity Contingency planning Business Impact Analysis (BIA) Documentation

A recovery plan can only cover what someone has listed. 'The Business Continuity Plan outlines the recovery time objectives and maximum tolerable periods of disruption for a list of business processes. Services Australia does not have business continuity or disaster recovery plans that address all systems, including the systems which support the critical recovery processes. Services Australia does not have a complete list of critical assets. As such, Services Australia is not well placed to ensure business continuity or disaster recovery in the event of a significant or reportable cyber security incident' (p.84). What was missing was not marginal: 'Services Australia has a Disaster Recovery Testing Schedule dated 31 October 2023. This schedule did not include all the systems within Services Australia. This schedule was later updated by Services Australia to include three significant financial systems, Medicare, Payment Assessment Calculation Engine (PACE) and Child Support IT system (Cuba). This schedule update was the result of issues identified during the audit of Services Australia's 2023-24 financial statements' (p.84). The national health insurance scheme entered the recovery schedule because a different audit noticed it was absent.

  • Function: Planning, Product/service delivery, IT
  • Value: Assets
  • Stakeholders: Management, Citizen, Beneficiary
  • Quality: Reliability and availability Reliable, integrated information base
3. Alerts judged not significant leave no written trace Documentation Data management Data security Monitoring Activity tracking

The entity's own plan sets the standard: its incident response plan 'states that "all information must be saved for future analysis preferably to a location not itself susceptible to [a security] incident"' (p.49). Practice stopped short of it. 'Only significant SIEM investigations are reported and logged in AUSTRAC's record-keeping repository where "significant" is defined by the security analyst. The SIEM investigation records include event logs, minutes and communications. Security alerts that have not been determined as "significant" are only reported verbally' (p.49). What was kept could not always be fetched back either: 'AUSTRAC could not provide archived SIEM data from 1 June 2022 to 31 October 2023. AUSTRAC does not have processes for extracting and retrieving cyber security events from either the production environment or archives for future analysis' (p.49). Seventeen months of the record, and the judgement of which events enter the record at all, rest on one analyst and on memory.

  • Function: Security, IT
  • Value: Domain knowledge
  • Stakeholders: Operator, Staff, Oversight
  • Quality: Reliable, integrated information base Functioning oversight and governance
4. Monitoring coverage stayed below the standard because the effort went to prevention Monitoring Activity tracking Guidance Procedures Coordination

Detection was built on an arrangement nobody designed. 'The decentralised event logging approach was a result of historical management arrangements, where IT environments were managed by different AUSTRAC business areas and it has not been implemented in the recommended way. A centralised logging approach offers better control, efficiency and standardisation as recommended by the ASD's Guidelines for System Monitoring' (p.48). The reason given for leaving it there is the finding worth carrying: 'AUSTRAC has not implemented ASD's recommendation for appropriate SIEM coverage or documented a strategy for prioritising its event monitoring resources due to a "focus on implementing preventative controls to mitigate cyber security incidents"' (p.48). The summary states the consequence plainly - the 'coverage of event logs is not in accordance with ASD's Cyber Security Guidelines' and the entity 'does not have an event logging policy' (p.9). Spending on keeping attacks out is not a substitute for being able to see one that gets in.

  • Function: Security, IT, Organizational structure
  • Value: Regulatory system, Assets
  • Stakeholders: Management, Policy setter
  • Quality: Streamlined, standardized processes Sound risk management
5. A response process with no clock on any of its steps Procedures Incident management Incident response Monitoring Reporting

Both entities have the steps written down and neither has said how fast they must happen. For the first: it 'does not document cyber security incident meetings, nor has it defined timeframes for reporting to relevant stakeholders' (p.10), and it 'has not defined timeframes for analysing cyber security events, nor does it perform any analysis on the timeliness or completeness of triaging and escalation processes' (p.49). For the second: it 'has not established a timeframe for triage and escalation activities nor a process for analysing archived SIEM data' and 'has not defined an approach for cyber security investigations' (pp.9-10), and it 'has not defined the timeframes for reporting to relevant stakeholders' (p.11). The audit put a recommendation on each of these, and both entities agreed. In incident management the clock is the control: without a defined time to triage, escalate and report, there is nothing to measure performance against and nothing a reviewer can test.

  • Function: Security, Governance
  • Value: Regulatory system
  • Stakeholders: Management, Operator, Oversight
  • Quality: Clear objectives and goal-setting Streamlined, standardized processes Functioning oversight and governance
6. A real breach came and went without a lessons-learned review Feedback Root Cause Analysis (RCA) Incident management Documentation Procedures

The learning is produced and then goes nowhere. At the first entity, 'AUSTRAC's incident reports include post-incident learning and post-remediation analysis. AUSTRAC undertook a root-cause analysis of the cyber security issue in 2023 which identified some systematic improvements. AUSTRAC does not use these incident reports to design and implement a security maturity monitoring plan or update its framework of procedures for cyber security incident management or share learnings internally and externally, where appropriate' (p.56). At the second the omission attaches to a named event: 'Any lessons learned from that experience, including support received from Services Australia's legal function, have not been used to review or update Services Australia's framework of procedures for cyber security incident management. Services Australia has not undertaken a post-incident review or a lessons-learned exercise following a large-scale data breach involving HWL Ebsworth Lawyers' (p.86). The audit's own message to every other entity is that post-incident learning 'greatly improves business continuity and recovery prospects' (p.17).

  • Function: Security, Governance
  • Value: Domain knowledge
  • Stakeholders: Management, Oversight, Staff
  • Quality: Sound risk management Functioning oversight and governance
7. The person empowered to decide has no written responsibilities Responsibility Accountability Documentation Guidance Procedures

Authority was granted and never described. The first entity 'has established management structures and responsibilities for managing cyber security incidents. However, it has not documented the assigned responsibilities for its CISO although the CISO is empowered to make decisions' (p.10), and the audit recommended it develop 'policies that define the responsibilities of the Chief Information Security Officer in accordance with the Protective Security Policy Framework requirements' (p.12). At the second the gap is one level higher: it 'does not have a policy covering the management of cyber security incidents' (p.9), and 'In January 2024, Services Australia advised the ANAO that it would commence developing the Cyber Security Incident Management and Response Policy from March 2024' (p.86) - that is, after the audit had begun. The report draws the general lesson for everyone else: entities should document policies and procedures, 'which is important for managing staff turnover', particularly where an organisation depends critically on a few key security advisors (p.17).

  • Function: Governance, Security, Organizational structure
  • Value: Human capital, Regulatory system
  • Stakeholders: Management, Policy setter, Staff
  • Quality: Clear objectives and goal-setting Adequate resources and competences
8. Incident response that never brings in the lawyers Coordination Incident response Documentation Responsibility

A serious incident is a legal event as much as a technical one, and neither response process treats it that way. At the first entity the reporting processes 'do not include the engagement of relevant expertise in other business areas, such as legal advisors, and do not ensure the integrity of evidence supporting cyber security investigations' (p.41). At the second, the programme built to catch the insider threat was assembled without that advice: its 'trusted insider program has not considered input from other business areas, such as its legal function' (p.60), and the same is true of the external reporting process, where the audit found no 'consideration of engaging other relevant expertise, such as legal advisors, during reporting processes' (p.60). The audit raises this to a message for all entities: as the regulatory landscape reforms, an entity should consider how its legal function 'will support their governance committees during the external reporting process to manage increasing scrutiny and liability risks' (p.17). Evidence that will not stand up is evidence collected for nothing.

  • Function: Governance, Security, Regulations
  • Value: Regulatory system, Domain knowledge
  • Stakeholders: Management, Oversight, Policy setter
  • Quality: Sound risk management Adequate resources and competences
Control focus
ICS phaseControl functionCases
Organic elements of a processBusiness continuity1. Backups are taken daily and have never been restored as a test<br/>2. The continuity plan left out the systems the public actually depends on
Data management3. Alerts judged not significant leave no written trace
Business continuityDisaster recovery1. Backups are taken daily and have never been restored as a test
Contingency planning2. The continuity plan left out the systems the public actually depends on
Business Impact Analysis (BIA)2. The continuity plan left out the systems the public actually depends on
Incident response5. A response process with no clock on any of its steps<br/>8. Incident response that never brings in the lawyers
Work processesTesting1. Backups are taken daily and have never been restored as a test
Procedures1. Backups are taken daily and have never been restored as a test<br/>4. Monitoring coverage stayed below the standard because the effort went to prevention<br/>5. A response process with no clock on any of its steps<br/>6. A real breach came and went without a lessons-learned review<br/>7. The person empowered to decide has no written responsibilities
Monitoring3. Alerts judged not significant leave no written trace<br/>4. Monitoring coverage stayed below the standard because the effort went to prevention<br/>5. A response process with no clock on any of its steps
Incident management5. A response process with no clock on any of its steps<br/>6. A real breach came and went without a lessons-learned review
Functions applied to all stagesDocumentation2. The continuity plan left out the systems the public actually depends on<br/>3. Alerts judged not significant leave no written trace<br/>6. A real breach came and went without a lessons-learned review<br/>7. The person empowered to decide has no written responsibilities<br/>8. Incident response that never brings in the lawyers
Coordination4. Monitoring coverage stayed below the standard because the effort went to prevention<br/>8. Incident response that never brings in the lawyers
Reporting5. A response process with no clock on any of its steps
Data managementData security3. Alerts judged not significant leave no written trace
MonitoringActivity tracking3. Alerts judged not significant leave no written trace<br/>4. Monitoring coverage stayed below the standard because the effort went to prevention
Initial phaseGuidance4. Monitoring coverage stayed below the standard because the effort went to prevention<br/>7. The person empowered to decide has no written responsibilities
Responsibility7. The person empowered to decide has no written responsibilities<br/>8. Incident response that never brings in the lawyers
CommunicationFeedback6. A real breach came and went without a lessons-learned review
Incident managementRoot Cause Analysis (RCA)6. A real breach came and went without a lessons-learned review
ResponsibilityAccountability7. The person empowered to decide has no written responsibilities
Evidential weight 364 — 3rd of 52 ranked. depth 8 · breadth 62 · rarity 17.57 · recency 0.84. What this measures, and what it does not.
This page is part of CUBE, a knowledge-sharing initiative of the EUROSAI IT Working Group. Its purpose is to make what supreme audit institutions find easier to search, compare and reuse — by auditors, and by the wider public who rarely reach these reports in their original form. It presents an analysis prepared, with AI assistance, by NIK — Najwyższa Izba Kontroli, Poland (initiation, coordination) on the basis of the publicly available report of The Australian National Audit Office, categorised against the internal-control terminology of INTOSAI's Guidance on Auditing Internal Control (ICS), drafted by the Internal Control Standards Subcommittee, which NIK (Poland) chairs. The categorisation and the case selection are ours, not the audit institution's, and so is any error in them. Readers are warmly encouraged to go to the original report, linked above; this page is a way in, never a substitute. Underlying data.