Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home International Customs

Customs merger made Immigration’s cyber compliance a problem

byCT Report
05/05/2017
in International Customs
Share on FacebookShare on Twitter

CANBERRA: The highly complex IT environment that spawned from the merger of the federal Immigration and Customs agencies is to blame for the combined agency failing a cyber security compliance audit, Immigration has said. The agency also argued the ATO and Human Services – the other two big agencies to be audited by the national audit office earlier this year – had a head start over Immigration in their cyber security transformation efforts. The Australian National Audit Office (ANAO) audit found that Human Services was the only one of the three agencies to be “cyber resilient” and compliant with all four of the ASD’s top cyber mitigation strategies. Immigration and the ATO had failed to properly implement application whitelisting; patch operating systems and applications; and were not effectively managing their IT supplier contacts, the ANAO found. All three are currently subject to a follow-up inquiry by parliament’s joint committee of public accounts, intended to keep the heat on the agencies to improve compliance.

In a submission to that inquiry, Immigration said it agreed with the findings of the report and would implement the recommendations, but laid out its case as to why it had failed to meet the cyber security obligations. Its July 2015 merger with Customs left it with a highly complex IT environment as a result of the two agencies having made opposite decisions on basically every technology procurement choice. Former Customs CIO Randall Brugeaud told last year’s Gartner Symposium/ITxpo conference that the combined environment prior to integration had more than 500 business and supporting systems, over 850 systems interfaces and services, around 750 databases, 20,000 desktops, 3500 mobile devices, thousands of servers and multiple data centres. The combined agency also had something from just about every major technology player on its books.  It has made much headway on slimming down its IT environment, but the agency pointed out in its submission to the inquiry that this complexity had an impact on its cyber security compliance. For example, of its 279 business critical applications, 70 percent are bespoke, the agency said, and its application set is supported by infrastructure spanning 84 regional and 51 offshore locations. The agency also argued that Human Services and the ATO were further along in their cyber security investments than Immigration.

You might also like

lamic banking assets reach Rs14.47 trillion, sector share rises to 23%

07/03/2026

Shippers see temporary lull in exports

05/02/2020

Immigration said it was only in its second year of a number of multi-year programs covering security, identity and access management, end user computing, and consolidation – whereas Human Services and ATO’s efforts had began as much as five years ago. “[These programs] will significantly enhance the department’s cyber security capability,” it said. Part of its security program stream is dedicated solely to becoming compliant with the ASD’s top four cyber mitigation strategies, it said. It pledged to be compliant with the application whitelisting component across all desktops by July this year after deploying a “strengthened application whitelisting solution” to its Windows 7 desktops. It is currently upgrading to Windows 10. Servers will be compliant with application whitelisting by July 2018.

A proof-of-concept for multifactor authentication for privileged accounts will be completed this year, and its end user computing consolidation program – due for completion in June 2020 – will introduce a “single departmental end user ICT environment [called] BorderNet” covering single desktop, printing service, email and file systems. It has also elevated its CISO to a first assistant secretary role and put in place accredited secure gateways, the agency said. However, the regular patching requirement is a more challenging one. “It is acknowledged that security patching of ICT systems is one of the department’s core BAU [business as usual] activities that must be undertaken to protect ICT infrastructure and information from disruption or theft from external advanced persistent threats” despite the complexities involved in supporting a myriad of different systems, Immigration said. It said it was currently developing a business case to increase patching frequency. Earlier this week the ATO revealed its highly-publicised SAN outages had played a significant role in its ability to meet its cyber security obligations.

Tags: Customs merger made Immigration's cyber compliance a problem

Related Stories

lamic banking assets reach Rs14.47 trillion, sector share rises to 23%

byCT Report
07/03/2026

KARACHI: Pakistan’s Islamic banking sector expanded during 2025, increasing its share in the country’s financial system with assets reaching nearly...

Shippers see temporary lull in exports

byadmin
05/02/2020

Shippers expect the coronavirus outbreak to have the greatest effect on farm product exports, notably fresh fruits and vegetables, with...

Toyota Motor Corp. employees work on the Crown vehicle production line at the company's Motomachi plant in Toyota City, Aichi, Japan, on Thursday, July 26, 2018. Toyota may stop importing some models into the U.S. if President Donald Trump raises vehicle tariffs, while other cars and trucks in showrooms will get more expensive, according to the automaker’s North American chief. Photographer: Shiho Fukada/Bloomberg

Toyota SA to invest over R4 billion in car assembly and parts

byadmin
05/02/2020

Toyota SA Motors (TSAM) has announced a R4.28bn investment in local vehicle assembly and parts supply. Speaking at the company’s...

Over 80 Kilos Cocaine Found On Dutch Plane In Argentina; Three Dutch Arrested

byadmin
05/02/2020

More than 80 kilograms of cocaine was found on a Martinair Cargo plane in Argentina. Seven men, three of whom...

Next Post

Thailand's Q2 exports up 5%: shippers' council

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.