Skip to content

Menu

Managing cyber security risks

Report 3: 2019–20. Tabled date: 2019-10-01. 17 recommendations published as HTML.

All audit reports

Tabled Report 3: 2019–20

Tabled date
2019-10-01
Report year
2019-20

Information technology Whole of government

Entities audited

Not identified in the published HTML audit scope.

Recommendations

  1. QAO's text Addressed to: all entities self-assess against the findings of this report, and where relevant

    develop a framework for managing cyber security risks consistent with the Information security policy (IS18:2018) (Chapter 2)

    They should also have information security standards to ensure the framework is consistently applied throughout the entity at an operational level.

    Queensland Audit Office (QAO) insight statement 1 in Chapter 2 provides more guidance on this.

  2. QAO's text Addressed to: develop and implement policies and procedures to identify and classify information assets, so they can effectively manage all their information assets that are at risk. This

    develop and implement policies and procedures to identify and classify information assets, so they can effectively manage all their information assets that are at risk. This should include policies and procedures for:

    • identifying and maintaining an inventory of information assets
    • classifying information assets as per the 2018 Queensland Government Information Security Classification Framework (Chapter 2)
  3. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This should include:

    • developing a risk assessment process for cyber security that integrates with their enterprise risk management framework
    • developing risk appetite statements for cyber security
    • identifying and assessing cyber security risks to their key information assets (Chapter 2)

    QAO insight statement 3 in Chapter 2 provides more guidance on this.

  4. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    review how they manage their ICT assets by:

    • reviewing their list of ICT assets and checking if they are assigned to employees who no longer work there and, if necessary, recovering any ICT assets that have not been returned
    • reviewing their employee separation process to ensure it includes updating the ICT asset register whenever an employee’s employment ends (Chapter 2)

    QAO insight statement 2 in Chapter 2 provides more guidance on this.

  5. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    assess the adequacy of their physical security to protect their ICT assets from unauthorised access (Chapter 4)

  6. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    design and implement an application whitelisting strategy (Chapter 3)

    QAO insight statement 4 in Chapter 3 provides more guidance on this.

  7. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    design and implement a patch management strategy to cover the patching of vulnerabilities in operating systems, applications, drivers, and hardware devices (Chapter 3)

    QAO insight statement 5 in Chapter 3 provides more guidance on this.

  8. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    ensure they effectively minimise and restrict administrative privileges (Chapter 3)

    QAO insight statement 6 in Chapter 3 provides more guidance on this.

  9. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    implement risk management practices for their use of third parties to deliver information technology services (Chapter 3)

    QAO insight statement 7 in Chapter 3 provides more guidance on this.

  10. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    undertake a risk assessment to determine the most effective password policy and implement it as a priority (Chapter 4)

    Controls may include:

    • blacklisting commonly breached passwords, dictionary words, and words about the context of the work environment (for example, entity name, services, and units)
    • preventing the use of repetitive and sequential characters.

    Better practice guidance that may help entities includes:

    • National Institute of Standards and Technology (NIST) Special Publication 800-63B Digital Identity Guidelines
    • Australian Cyber Security Centre Information Security Manual
    • Queensland Government Enterprise Architecture Guideline: Reducing password frustration for Queensland public servants
  11. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    implement multi-factor authentication as a minimum on external services that allow login with their domain accounts, and for sensitive internal systems (Chapter 4)

  12. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    review all subdomains and consider whether they provide an indication of the entity’s underlying technology or services, and modify existing subdomains to obscure exposing information (Chapter 4)

  13. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    implement encryption on online services that communicate via an unencrypted channel (Chapter 4)

  14. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    segregate workstations located in publicly accessible areas from their corporate network (Chapter 4)

  15. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    develop cyber security training and deliver it to all staff, with more targeted training to users who have access to sensitive data (Chapter 3)

    QAO insight statement 8 in Chapter 3 provides more guidance on this.

  16. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    ensure security and awareness training includes:

    • discouraging the use of corporate email addresses on external services
    • education on the risks of posting information on social media that provides information on an entities’ technology services
    • education on phishing attacks
    • education on the risk of physically ‘tailgating’ people into public sector buildings and offices (Chapter 4)
  17. QAO's text Addressed to: develop and implement a methodology for identifying and assessing cyber security risks to their information assets. This

    introduce and configure end user device logging.

    This should include configuring security logs and rules on end user devices (for example, computer desktops and laptops) for detecting malicious and anomalous behaviour and events. (Chapter 4)

Authoritative report — Queensland Audit Office

Report PDF on QAO

Source: Queensland Audit Office, CC BY 4.0

Catalogue snapshot 2026-10-09

© The State of Queensland (Queensland Audit Office) 2026

Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.

Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.

No endorsement by the State of Queensland or Queensland Audit Office is implied.

CC BY 4.0 · QAO copyright and exceptions