Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Noting Paper 330 - UNSW Reports #330

Closed
CDR-API-Stream opened this issue Sep 27, 2023 · 1 comment
Closed

Noting Paper 330 - UNSW Reports #330

CDR-API-Stream opened this issue Sep 27, 2023 · 1 comment
Assignees
Labels
Category: InfoSec Information Security Technical Working Group Decision Proposal Category: Noting Paper A paper outlining a specific outcome or clarification that is being posted for noting

Comments

@CDR-API-Stream
Copy link
Contributor

CDR-API-Stream commented Sep 27, 2023

In 2022, the Data Standards Chair (Chair) commissioned the University of New South Wales (UNSW) to provide two reports to him about cyber security issues related to the CDR and, in particular, the Data Standards:

The scope of both papers was developed in early 2022 through consultation with Treasury, the OAIC and the ACCC.
The final Cyber Threats report was accepted and circulated to CDR agencies in October 2022; and was used extensively in consideration of the public data breaches occurring at the time, and the CDR’s cyber security posture. The final Risk report was accepted in May 2023, after minor edits. The Chair thanks the UNSW team for their expertise and work that has progressed the CDR’s understanding and mitigation of key risks.

In reading the reports, it should be noted that they were drafted based on information then publicly available in 2022. This means UNSW was not provided with Treasury’s Risk Management Framework, which is now currently being used. Additionally, UNSW’s analysis was conducted under a prior version of the Commonwealth’s Risk Management Policy.

Since undertaking this work, the Treasury has undertaken a consultation on screen scraping policy and regulatory implications which sought to compare data accessed through screen scraping with the CDR. UNSW was not asked to compare or contrast the risks of screen-scraping against the CDR and consequently, these reports should not be considered as an evaluation of the CDR; nor an assessment of respective pros or cons of either policy setting.

Noting Paper 330 UNSW Reports

@CDR-API-Stream CDR-API-Stream changed the title Noting Paper 330 - Placeholder Noting Paper 330 - UNSW Reports Feb 13, 2024
@njgilbert njgilbert self-assigned this Feb 19, 2024
@njgilbert njgilbert added Category: Noting Paper A paper outlining a specific outcome or clarification that is being posted for noting Category: InfoSec Information Security Technical Working Group Decision Proposal labels Feb 19, 2024
@ConsumerDataStandardsAustralia ConsumerDataStandardsAustralia locked as resolved and limited conversation to collaborators Feb 19, 2024
@CDR-API-Stream
Copy link
Contributor Author

The UNSW Reports have been published and can be found in the original post.

A video summarising the Reports can be found here.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Category: InfoSec Information Security Technical Working Group Decision Proposal Category: Noting Paper A paper outlining a specific outcome or clarification that is being posted for noting
Projects
None yet
Development

No branches or pull requests

2 participants