Security of critical water infrastructure
Report 19: 2016–17. Tabled date: 2017-06-27. 4 recommendations published as HTML.
Tabled Report 19: 2016–17
- Tabled date
- 2017-06-27
- Report year
- 2016-17
Entities audited
Not identified in the published HTML audit scope.
Recommendations
QAO's text Addressed to: the Department of Energy and Water Supply
integrate information technology risks and cyber threats into the existing risk management framework for drinking water services and in the Queensland water and sewage service provider performance reports. (Chapter 2)
QAO's text Addressed to: the Department of Energy and Water Supply
facilitate information sharing about adopting standards for securing information technology amongst entities that manage water control systems. (Chapter 2)
QAO's text Addressed to: improve oversight, identification and monitoring of information technology risks and cyber threats to water control systems. (Chapter 2) This
improve oversight, identification and monitoring of information technology risks and cyber threats to water control systems. (Chapter 2)
This should include:
- clearly articulating and assigning roles and responsibilities for all parties, including any external service providers in securing the systems
- maintaining a complete and up-to-date list of assets for water control systems and assessing the risk exposure of each asset
- developing and implementing a security plan for water control systems based on risk assessments
- implementing appropriate user access and authentication policies
- using a phased approach to implementing the Australian Government's ’essential eight’ security controls based on each entity's risk assessment
- establishing performance indicators for security and periodically testing these controls to monitor the maturity and strength of defences built into the information technology control environment
- improving understanding of how to manage information technology risks and how they relate to other forms of operational risks.
QAO's text Addressed to: establish enterprise-wide incident response plans, business continuity, and disaster recovery processes for information technology. (Chapter 3) This
establish enterprise-wide incident response plans, business continuity, and disaster recovery processes for information technology. (Chapter 3)
This should include:
- testing the capability to respond to wide-scale information technology security incidents either through scenario testing or through desktop exercises
- training staff to identify, assess, and have a coordinated response to information technology security breaches
- adopting appropriate business continuity plans that include processes for reporting incidents to stakeholders and building on lessons learned
- updating and testing information technology disaster recovery and business continuity plans to include processes to recover from a wide-scale information technology security breach
- considering the impact of multiple system failures on business continuity planning and how entities can operate water and wastewater plants manually, if required.
Authoritative report — Queensland Audit Office
Source: Queensland Audit Office, CC BY 4.0
Catalogue snapshot 2026-10-09
© The State of Queensland (Queensland Audit Office) 2026
Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.
Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.
No endorsement by the State of Queensland or Queensland Audit Office is implied.