SlideShare a Scribd company logo
Partners in Technology
Friday 2 November 2018
Queensland Government Chief Information Office
IS18 – Policy Changes
www.qgcio.qld.gov.au
Queensland Government Chief Information Office
IS18 - Security Policy Changes
From October 1st 2018 a revised Information Security Policies (IS18) came into
effect for Queensland Government.
What are these changes, what do they mean, and what does the information
security need to look like for Queensland Government in the future.
Queensland Government Chief Information Office
Cyber security is now a strategic risk to all organisations
- No one wants to be front page news for a cyber incident
- Everyone is a potential target
- Increasingly seeing attackers exploiting weakest points in security
Never underestimate a criminal’s ability to turn
your stuff
into their money
or the damage to your reputation when that happens.
Queensland Government Chief Information Office
We have be “doing” Information Security for decades.
So what’s changed?
•Digitization
•Complexity
Expectations of the
community and
stakeholders
Sophistication & motivation
of attackers
Queensland Government Chief Information Office
IS18 History
Part of the QGEA
First established in 1993
Last major refresh of IS18 in 2009 - (5th version)
Based around
ISO/IEC 17799:2000 and ISO/IEC 27001:2006
Queensland Government Chief Information Office
Drivers for change
Not aligned to the current of the ISO 27001 standard.
Needed refreshing to match agency requirements in managing increasingly
complex ICT and business environments.
Hadn’t been particularly well adopted
Focused on controls, not the processes and outcomes
Lacked guidance on governance and assurance
Queensland Government Chief Information Office
Information Security Policy (IS18:2018)
This new policy came into effect from 1 October 2018.
Represents a move from a compliance focus
to a risk based approach
Queensland Government Chief Information Office
Policy wording
Purpose
The Queensland Government is responsible for a significant amount of
information. To ensure trust and deliver business value it is critical that
this information is protected appropriately.
This policy seeks to ensure all agencies apply a consistent, risk-based
approach, to the implementation of information security to maintain
confidentiality, integrity and availability.
Policy statement
The Queensland Government will identify and manage risks to
information, applications and technologies, through their life cycle,
using Information Security Management Systems (ISMS).
Purpose
The Queensland Government is responsible for a significant amount of
information. To ensure trust and deliver business value it is critical that
this information is protected appropriately.
This policy seeks to ensure all agencies apply a consistent, risk-based
approach, to the implementation of information security to maintain
confidentiality, integrity and availability.
Policy statement
The Queensland Government will identify and manage risks to
information, applications and technologies, through their life cycle,
using Information Security Management Systems (ISMS).
Queensland Government Chief Information Office
Policy requirement 1:
Agencies must implement an ISMS based on ISO 27001
Agencies must implement and operate an ISMS based
on the current version of ISO 27001 Information
technology - Security techniques - Information
security management systems – Requirements. The
scope of the ISMS will include the protection of all
information, application and technology assets.
Queensland Government Chief Information Office
Policy requirement 2:
Agencies must apply a systematic and repeatable
approach to risk management
Risk management is an integral part of operating an ISMS where risks must
be considered at a business level. Agencies must adopt a risk management
framework by integrating their ISMS into their corporate risk management
processes.
Queensland Government Chief Information Office
Policy requirement 3:
Agencies must meet minimum security requirements
To ensure a consistent security posture, the ISMS must meet the following requirements:
• all ICT assets that create, store, process or transmit information are assigned appropriate
controls in accordance with the Queensland Government Information Security
Classification Framework (QGISCF).
• all information transmitted over data communications networks must be secured in line
with the Network transmission security assurance framework (NTSAF)*.
• all services requiring user authentication must meet the requirements of the Queensland
Government Authentication Framework (QGAF)*.
• agencies must implement the Australian Signals Directorate (ASD) “Essential
Eight” Strategies to Mitigate Cyber Security Incidents.
* Being reviewed
Queensland Government Chief Information Office
Policy requirement 4:
Agency accountable officers must obtain assurance for systems
Every system is unique and assurance should be applied sensibly
and appropriately. Accountable officers must obtain assurance to
establish an understanding of information security protections
and adherence to information security policy.
The level of assurance applied to systems must be based on the
criticality/significance of the system, using the business impact
levels determination methodology outlined in the QGISCF.
Queensland Government Chief Information Office
Policy requirement 5:
Accountable officers must attest to the appropriateness
of agency information security
Agency accountable officers must:
• endorse the Information Security Checklist.
• certify that it is an accurate report of the agency’s information
security posture.
• endorsement must be obtained from the agency's
accountable officer through corporate audit and risk
committee.
Queensland Government Chief Information Office
Reporting requirements:
• Agencies must submit an endorsed Information Security
Compliance Checklist annually by 30 October every year to
the Queensland Government Chief Information Office.
• Endorsement must be obtained from the agency's
accountable officer through corporate audit and risk
committee.
• Communicate incident response activities and threat
intelligence to the Queensland Government Chief Information
Office.
Queensland Government Chief Information Office
Information Security Classification Framework (QGISCF)
Consistent classification of
information helps Queensland
government agencies make more
informed and timely decisions about
how they should capture, store,
maintain, transmit, process, use and
share information to best deliver
services to Queenslanders.
Queensland Government Chief Information Office
Benefits of stronger adoption of ISO 27001
• Stronger focus on the elements of governance & accountability
• Move from a compliance to a risk management based approach
• Establish sustainable process improvement
• Common language assists in aligning requirements when using cloud and
managed ICT services
• Leverage the capabilities in the market
Queensland Government Chief Information Office
Approach
Focus on establishing effective governance & accountability
Improve risk management capability
The control objectives haven’t changed significantly
Certification is not required, but may be used.
Queensland Government Chief Information Office
What does information security need to look like
Cyber Security is a Business Risk not just an IT Problem.
Integrated into enterprise risk management
Business engagement essential
Considering information security risk in all operations
Design with assurance in mind
Queensland Government Chief Information Office
Further Details
QGCIO Website
https://www.qgcio.qld.gov.au/information-on/information-security/
QGCIO email
qgcio@qgcio.qld.gov.au
Testing Within Government
Showcase
7 December 2018
QUT Gardens Point
Gardens Theatre
9am – 11am
4 Government agencies – 4 SME’s collaborating to make a difference

More Related Content

What's hot

Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
Digital Queensland
 
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
Digital Queensland
 
Improving Decision Making in Health & Social Care Through Quality Information...
Improving Decision Making in Health & Social Care Through Quality Information...Improving Decision Making in Health & Social Care Through Quality Information...
Improving Decision Making in Health & Social Care Through Quality Information...
The Health and Social Care Information Centre
 
Open Data at Locate15 Conference 11 march 2015
Open Data at Locate15 Conference 11 march 2015Open Data at Locate15 Conference 11 march 2015
Open Data at Locate15 Conference 11 march 2015
Open Data NZ
 
Partners in technology - DESBT ICT Priorities 2019 – 2020
Partners in technology - DESBT ICT Priorities 2019 – 2020 Partners in technology - DESBT ICT Priorities 2019 – 2020
Partners in technology - DESBT ICT Priorities 2019 – 2020
Digital Queensland
 
Appello presentation [Future Assisted Living Technology]
Appello presentation [Future Assisted Living Technology]Appello presentation [Future Assisted Living Technology]
Appello presentation [Future Assisted Living Technology]
HACThousing
 
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
Data Portal India
 
Chinese taipei ct005 1366644281
Chinese taipei ct005 1366644281Chinese taipei ct005 1366644281
Chinese taipei ct005 1366644281Nurul Yakin
 
Kate Warriner - ECO 15: Digital connectivity in healthcare
Kate Warriner - ECO 15: Digital connectivity in healthcareKate Warriner - ECO 15: Digital connectivity in healthcare
Kate Warriner - ECO 15: Digital connectivity in healthcare
Innovation Agency
 
Dr Masood Nazir - ECO 19: Care closer to home
Dr Masood Nazir - ECO 19: Care closer to homeDr Masood Nazir - ECO 19: Care closer to home
Dr Masood Nazir - ECO 19: Care closer to home
Innovation Agency
 
Open Data & Open API in US and Worldwide
Open Data & Open API in US and WorldwideOpen Data & Open API in US and Worldwide
Open Data & Open API in US and Worldwide
Data Portal India
 
NZ Health IT Cluster
NZ Health IT Cluster NZ Health IT Cluster
NZ Health IT Cluster
Health Informatics New Zealand
 
[2015 e-Government Program] Action Plan : Doha(Qatar)
[2015 e-Government Program] Action Plan : Doha(Qatar)[2015 e-Government Program] Action Plan : Doha(Qatar)
[2015 e-Government Program] Action Plan : Doha(Qatar)
shrdcinfo
 
Janet King - ECO 15: Digital connectivity in healthcare
Janet King - ECO 15: Digital connectivity in healthcareJanet King - ECO 15: Digital connectivity in healthcare
Janet King - ECO 15: Digital connectivity in healthcare
Innovation Agency
 
A new broadband network for the Health and Social Care sector
A new broadband network for the Health and Social Care sectorA new broadband network for the Health and Social Care sector
A new broadband network for the Health and Social Care sector
HIMSS UK
 
Leapfrog Strategies for Thailand
Leapfrog Strategies for ThailandLeapfrog Strategies for Thailand
Leapfrog Strategies for Thailand
Randeep Sudan
 
Improving Wellbeing Through Information and Technology
Improving Wellbeing Through Information and TechnologyImproving Wellbeing Through Information and Technology
Improving Wellbeing Through Information and Technology
The Health and Social Care Information Centre
 
Internet Governance and Economic Development
Internet Governance and Economic DevelopmentInternet Governance and Economic Development
Internet Governance and Economic Development
RIPE NCC
 
Digital Continuity Strategy Consultation
Digital Continuity Strategy ConsultationDigital Continuity Strategy Consultation
Digital Continuity Strategy ConsultationStephenClarke
 

What's hot (20)

Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
Partners in Technology (PiT) - Public Safety Business Agency - 23 October 2015
 
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
Partners in Technology (PiT) - Queensland Digital Industry Survey 2014 - 21 J...
 
Improving Decision Making in Health & Social Care Through Quality Information...
Improving Decision Making in Health & Social Care Through Quality Information...Improving Decision Making in Health & Social Care Through Quality Information...
Improving Decision Making in Health & Social Care Through Quality Information...
 
Open Data at Locate15 Conference 11 march 2015
Open Data at Locate15 Conference 11 march 2015Open Data at Locate15 Conference 11 march 2015
Open Data at Locate15 Conference 11 march 2015
 
Partners in technology - DESBT ICT Priorities 2019 – 2020
Partners in technology - DESBT ICT Priorities 2019 – 2020 Partners in technology - DESBT ICT Priorities 2019 – 2020
Partners in technology - DESBT ICT Priorities 2019 – 2020
 
Appello presentation [Future Assisted Living Technology]
Appello presentation [Future Assisted Living Technology]Appello presentation [Future Assisted Living Technology]
Appello presentation [Future Assisted Living Technology]
 
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
National Data Sharing and Accessibility Policy [ NDSAP 2012 ]
 
Chinese taipei ct005 1366644281
Chinese taipei ct005 1366644281Chinese taipei ct005 1366644281
Chinese taipei ct005 1366644281
 
Kate Warriner - ECO 15: Digital connectivity in healthcare
Kate Warriner - ECO 15: Digital connectivity in healthcareKate Warriner - ECO 15: Digital connectivity in healthcare
Kate Warriner - ECO 15: Digital connectivity in healthcare
 
Kenya's open data journey ce dem14
Kenya's open data journey   ce dem14Kenya's open data journey   ce dem14
Kenya's open data journey ce dem14
 
Dr Masood Nazir - ECO 19: Care closer to home
Dr Masood Nazir - ECO 19: Care closer to homeDr Masood Nazir - ECO 19: Care closer to home
Dr Masood Nazir - ECO 19: Care closer to home
 
Open Data & Open API in US and Worldwide
Open Data & Open API in US and WorldwideOpen Data & Open API in US and Worldwide
Open Data & Open API in US and Worldwide
 
NZ Health IT Cluster
NZ Health IT Cluster NZ Health IT Cluster
NZ Health IT Cluster
 
[2015 e-Government Program] Action Plan : Doha(Qatar)
[2015 e-Government Program] Action Plan : Doha(Qatar)[2015 e-Government Program] Action Plan : Doha(Qatar)
[2015 e-Government Program] Action Plan : Doha(Qatar)
 
Janet King - ECO 15: Digital connectivity in healthcare
Janet King - ECO 15: Digital connectivity in healthcareJanet King - ECO 15: Digital connectivity in healthcare
Janet King - ECO 15: Digital connectivity in healthcare
 
A new broadband network for the Health and Social Care sector
A new broadband network for the Health and Social Care sectorA new broadband network for the Health and Social Care sector
A new broadband network for the Health and Social Care sector
 
Leapfrog Strategies for Thailand
Leapfrog Strategies for ThailandLeapfrog Strategies for Thailand
Leapfrog Strategies for Thailand
 
Improving Wellbeing Through Information and Technology
Improving Wellbeing Through Information and TechnologyImproving Wellbeing Through Information and Technology
Improving Wellbeing Through Information and Technology
 
Internet Governance and Economic Development
Internet Governance and Economic DevelopmentInternet Governance and Economic Development
Internet Governance and Economic Development
 
Digital Continuity Strategy Consultation
Digital Continuity Strategy ConsultationDigital Continuity Strategy Consultation
Digital Continuity Strategy Consultation
 

Similar to Partners in technology information security policy changes

NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
NQA
 
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...Taiye Lambo
 
MCGlobalTech Service Presentation
MCGlobalTech Service PresentationMCGlobalTech Service Presentation
MCGlobalTech Service Presentation
William McBorrough
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
IT Governance Ltd
 
Qatar's NIA Policy Program
Qatar's NIA Policy ProgramQatar's NIA Policy Program
Qatar's NIA Policy ProgramSamir Pawaskar
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service Presentation
William McBorrough
 
Why ISO 27001 for an Organisation
Why ISO 27001 for an OrganisationWhy ISO 27001 for an Organisation
Why ISO 27001 for an Organisation
Syed Azher
 
Enterprise security strategic_plan
Enterprise security strategic_planEnterprise security strategic_plan
Enterprise security strategic_plan
wardell henley
 
Using cloud services: Compliance with the Security Requirements of the Spanis...
Using cloud services: Compliance with the Security Requirements of the Spanis...Using cloud services: Compliance with the Security Requirements of the Spanis...
Using cloud services: Compliance with the Security Requirements of the Spanis...
Miguel A. Amutio
 
2015-ISBS-Technical-Report-blue-digital
2015-ISBS-Technical-Report-blue-digital2015-ISBS-Technical-Report-blue-digital
2015-ISBS-Technical-Report-blue-digitalJames Fisher
 
The Security Circle- Services Offered
The Security Circle- Services OfferedThe Security Circle- Services Offered
The Security Circle- Services OfferedRachel Anne Carter
 
Cyber Security Strategy for Pakistan.docx
Cyber Security Strategy for Pakistan.docxCyber Security Strategy for Pakistan.docx
Cyber Security Strategy for Pakistan.docx
falknoor56
 
The Present and the Future ISAC in Taiwan
The Present and the Future ISAC in TaiwanThe Present and the Future ISAC in Taiwan
The Present and the Future ISAC in Taiwan
APNIC
 
National Cyber Security Strategy 2020 DSCI submission.pdf
National Cyber Security Strategy 2020 DSCI submission.pdfNational Cyber Security Strategy 2020 DSCI submission.pdf
National Cyber Security Strategy 2020 DSCI submission.pdf
sri_ias
 
Singapore's National Cyber Security Strategy
Singapore's National Cyber Security StrategySingapore's National Cyber Security Strategy
Singapore's National Cyber Security Strategy
Benjamin Ang
 
Pindad iso27000 2016 smki
Pindad   iso27000 2016 smkiPindad   iso27000 2016 smki
9 September 2014: Cyber Security Model
9 September 2014: Cyber Security Model 9 September 2014: Cyber Security Model
9 September 2014: Cyber Security Model
Defence and Security Accelerator
 
NQA - Information security best practice guide
NQA - Information security best practice guideNQA - Information security best practice guide
NQA - Information security best practice guide
NA Putra
 
Information Security Continuous Monitoring within a Risk Management Framework
Information Security Continuous Monitoring within a Risk Management FrameworkInformation Security Continuous Monitoring within a Risk Management Framework
Information Security Continuous Monitoring within a Risk Management Framework
William McBorrough
 
Iso 27001 2005- by netpeckers consulting
Iso 27001 2005- by netpeckers consultingIso 27001 2005- by netpeckers consulting
Iso 27001 2005- by netpeckers consulting
Iskcon Ahmedabad
 

Similar to Partners in technology information security policy changes (20)

NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
 
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
 
MCGlobalTech Service Presentation
MCGlobalTech Service PresentationMCGlobalTech Service Presentation
MCGlobalTech Service Presentation
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
 
Qatar's NIA Policy Program
Qatar's NIA Policy ProgramQatar's NIA Policy Program
Qatar's NIA Policy Program
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service Presentation
 
Why ISO 27001 for an Organisation
Why ISO 27001 for an OrganisationWhy ISO 27001 for an Organisation
Why ISO 27001 for an Organisation
 
Enterprise security strategic_plan
Enterprise security strategic_planEnterprise security strategic_plan
Enterprise security strategic_plan
 
Using cloud services: Compliance with the Security Requirements of the Spanis...
Using cloud services: Compliance with the Security Requirements of the Spanis...Using cloud services: Compliance with the Security Requirements of the Spanis...
Using cloud services: Compliance with the Security Requirements of the Spanis...
 
2015-ISBS-Technical-Report-blue-digital
2015-ISBS-Technical-Report-blue-digital2015-ISBS-Technical-Report-blue-digital
2015-ISBS-Technical-Report-blue-digital
 
The Security Circle- Services Offered
The Security Circle- Services OfferedThe Security Circle- Services Offered
The Security Circle- Services Offered
 
Cyber Security Strategy for Pakistan.docx
Cyber Security Strategy for Pakistan.docxCyber Security Strategy for Pakistan.docx
Cyber Security Strategy for Pakistan.docx
 
The Present and the Future ISAC in Taiwan
The Present and the Future ISAC in TaiwanThe Present and the Future ISAC in Taiwan
The Present and the Future ISAC in Taiwan
 
National Cyber Security Strategy 2020 DSCI submission.pdf
National Cyber Security Strategy 2020 DSCI submission.pdfNational Cyber Security Strategy 2020 DSCI submission.pdf
National Cyber Security Strategy 2020 DSCI submission.pdf
 
Singapore's National Cyber Security Strategy
Singapore's National Cyber Security StrategySingapore's National Cyber Security Strategy
Singapore's National Cyber Security Strategy
 
Pindad iso27000 2016 smki
Pindad   iso27000 2016 smkiPindad   iso27000 2016 smki
Pindad iso27000 2016 smki
 
9 September 2014: Cyber Security Model
9 September 2014: Cyber Security Model 9 September 2014: Cyber Security Model
9 September 2014: Cyber Security Model
 
NQA - Information security best practice guide
NQA - Information security best practice guideNQA - Information security best practice guide
NQA - Information security best practice guide
 
Information Security Continuous Monitoring within a Risk Management Framework
Information Security Continuous Monitoring within a Risk Management FrameworkInformation Security Continuous Monitoring within a Risk Management Framework
Information Security Continuous Monitoring within a Risk Management Framework
 
Iso 27001 2005- by netpeckers consulting
Iso 27001 2005- by netpeckers consultingIso 27001 2005- by netpeckers consulting
Iso 27001 2005- by netpeckers consulting
 

More from Digital Queensland

Partners in Technology 15 March 2024
Partners in Technology 15 March 2024Partners in Technology 15 March 2024
Partners in Technology 15 March 2024
Digital Queensland
 
Partners in Technology 10 February 2023
Partners in Technology 10 February 2023Partners in Technology 10 February 2023
Partners in Technology 10 February 2023
Digital Queensland
 
Partners in Technology 1 July 2020
Partners in Technology 1 July 2020Partners in Technology 1 July 2020
Partners in Technology 1 July 2020
Digital Queensland
 
Partners in Technology 4 June 2020
Partners in Technology 4 June 2020Partners in Technology 4 June 2020
Partners in Technology 4 June 2020
Digital Queensland
 
Partners in Technology 4 June 2020
Partners in Technology 4 June 2020Partners in Technology 4 June 2020
Partners in Technology 4 June 2020
Digital Queensland
 
Partners in Technology 21 May 2020
Partners in Technology 21 May 2020Partners in Technology 21 May 2020
Partners in Technology 21 May 2020
Digital Queensland
 
Partners in Technology 7 May 2020
Partners in Technology 7 May 2020Partners in Technology 7 May 2020
Partners in Technology 7 May 2020
Digital Queensland
 
Partners in Technology 7 May 2020
Partners in Technology 7 May 2020Partners in Technology 7 May 2020
Partners in Technology 7 May 2020
Digital Queensland
 
Partners in Technology 23 April 2020
Partners in Technology 23 April 2020Partners in Technology 23 April 2020
Partners in Technology 23 April 2020
Digital Queensland
 
Partners in Technology 9 April 2020
Partners in Technology  9 April 2020Partners in Technology  9 April 2020
Partners in Technology 9 April 2020
Digital Queensland
 
Partners in Technology 9 April 2020
Partners in Technology  9 April 2020Partners in Technology  9 April 2020
Partners in Technology 9 April 2020
Digital Queensland
 
Partners in Technology 27 March 2020
Partners in Technology 27 March 2020Partners in Technology 27 March 2020
Partners in Technology 27 March 2020
Digital Queensland
 
Partners in Technology - the digital future of DES
Partners in Technology - the digital future of DESPartners in Technology - the digital future of DES
Partners in Technology - the digital future of DES
Digital Queensland
 
Partners in Technology - the Queensland digital licence
Partners in Technology - the Queensland digital licencePartners in Technology - the Queensland digital licence
Partners in Technology - the Queensland digital licence
Digital Queensland
 
Partners in Technology - future of customer and digital delivery in Queenslan...
Partners in Technology - future of customer and digital delivery in Queenslan...Partners in Technology - future of customer and digital delivery in Queenslan...
Partners in Technology - future of customer and digital delivery in Queenslan...
Digital Queensland
 
Partners in Technology - Establish and prove foundational ICT capability
Partners in Technology - Establish and prove foundational ICT capabilityPartners in Technology - Establish and prove foundational ICT capability
Partners in Technology - Establish and prove foundational ICT capability
Digital Queensland
 
Partners in Technology - Bringing digital ideas to life
Partners in Technology - Bringing digital ideas to lifePartners in Technology - Bringing digital ideas to life
Partners in Technology - Bringing digital ideas to life
Digital Queensland
 
Partners in Technology - Opportunities for delivering better ICT services
Partners in Technology - Opportunities for delivering better ICT services Partners in Technology - Opportunities for delivering better ICT services
Partners in Technology - Opportunities for delivering better ICT services
Digital Queensland
 
Partners in Technology - Department of Transport and Main Roads
Partners in Technology - Department of Transport and Main RoadsPartners in Technology - Department of Transport and Main Roads
Partners in Technology - Department of Transport and Main Roads
Digital Queensland
 
Partners in Technology (PiT) - Be a Responsive Government
Partners in Technology (PiT) - Be a Responsive GovernmentPartners in Technology (PiT) - Be a Responsive Government
Partners in Technology (PiT) - Be a Responsive Government
Digital Queensland
 

More from Digital Queensland (20)

Partners in Technology 15 March 2024
Partners in Technology 15 March 2024Partners in Technology 15 March 2024
Partners in Technology 15 March 2024
 
Partners in Technology 10 February 2023
Partners in Technology 10 February 2023Partners in Technology 10 February 2023
Partners in Technology 10 February 2023
 
Partners in Technology 1 July 2020
Partners in Technology 1 July 2020Partners in Technology 1 July 2020
Partners in Technology 1 July 2020
 
Partners in Technology 4 June 2020
Partners in Technology 4 June 2020Partners in Technology 4 June 2020
Partners in Technology 4 June 2020
 
Partners in Technology 4 June 2020
Partners in Technology 4 June 2020Partners in Technology 4 June 2020
Partners in Technology 4 June 2020
 
Partners in Technology 21 May 2020
Partners in Technology 21 May 2020Partners in Technology 21 May 2020
Partners in Technology 21 May 2020
 
Partners in Technology 7 May 2020
Partners in Technology 7 May 2020Partners in Technology 7 May 2020
Partners in Technology 7 May 2020
 
Partners in Technology 7 May 2020
Partners in Technology 7 May 2020Partners in Technology 7 May 2020
Partners in Technology 7 May 2020
 
Partners in Technology 23 April 2020
Partners in Technology 23 April 2020Partners in Technology 23 April 2020
Partners in Technology 23 April 2020
 
Partners in Technology 9 April 2020
Partners in Technology  9 April 2020Partners in Technology  9 April 2020
Partners in Technology 9 April 2020
 
Partners in Technology 9 April 2020
Partners in Technology  9 April 2020Partners in Technology  9 April 2020
Partners in Technology 9 April 2020
 
Partners in Technology 27 March 2020
Partners in Technology 27 March 2020Partners in Technology 27 March 2020
Partners in Technology 27 March 2020
 
Partners in Technology - the digital future of DES
Partners in Technology - the digital future of DESPartners in Technology - the digital future of DES
Partners in Technology - the digital future of DES
 
Partners in Technology - the Queensland digital licence
Partners in Technology - the Queensland digital licencePartners in Technology - the Queensland digital licence
Partners in Technology - the Queensland digital licence
 
Partners in Technology - future of customer and digital delivery in Queenslan...
Partners in Technology - future of customer and digital delivery in Queenslan...Partners in Technology - future of customer and digital delivery in Queenslan...
Partners in Technology - future of customer and digital delivery in Queenslan...
 
Partners in Technology - Establish and prove foundational ICT capability
Partners in Technology - Establish and prove foundational ICT capabilityPartners in Technology - Establish and prove foundational ICT capability
Partners in Technology - Establish and prove foundational ICT capability
 
Partners in Technology - Bringing digital ideas to life
Partners in Technology - Bringing digital ideas to lifePartners in Technology - Bringing digital ideas to life
Partners in Technology - Bringing digital ideas to life
 
Partners in Technology - Opportunities for delivering better ICT services
Partners in Technology - Opportunities for delivering better ICT services Partners in Technology - Opportunities for delivering better ICT services
Partners in Technology - Opportunities for delivering better ICT services
 
Partners in Technology - Department of Transport and Main Roads
Partners in Technology - Department of Transport and Main RoadsPartners in Technology - Department of Transport and Main Roads
Partners in Technology - Department of Transport and Main Roads
 
Partners in Technology (PiT) - Be a Responsive Government
Partners in Technology (PiT) - Be a Responsive GovernmentPartners in Technology (PiT) - Be a Responsive Government
Partners in Technology (PiT) - Be a Responsive Government
 

Recently uploaded

ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
Saeed Al Dhaheri
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
JSchaus & Associates
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
ARCResearch
 
PACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdfPACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdf
Mohammed325561
 
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
ehbuaw
 
PPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
PPT Item # 9 - 2024 Street Maintenance Program(SMP) AmendmentPPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
PPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
ahcitycouncil
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
850fcj96
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
ehbuaw
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
JSchaus & Associates
 
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
RIDPRO11
 
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
ehbuaw
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
Get Government Grants
 
Many ways to support street children.pptx
Many ways to support street children.pptxMany ways to support street children.pptx
Many ways to support street children.pptx
SERUDS INDIA
 
PPT Item # 5 - 5330 Broadway ARB Case # 930F
PPT Item # 5 - 5330 Broadway ARB Case # 930FPPT Item # 5 - 5330 Broadway ARB Case # 930F
PPT Item # 5 - 5330 Broadway ARB Case # 930F
ahcitycouncil
 
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
ehbuaw
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
oklahomajudicialproc1
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
Antti Rautiainen
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Congressional Budget Office
 
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
ukyewh
 
PPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way StopPPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way Stop
ahcitycouncil
 

Recently uploaded (20)

ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
 
PACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdfPACT launching workshop presentation-Final.pdf
PACT launching workshop presentation-Final.pdf
 
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
一比一原版(UQ毕业证)昆士兰大学毕业证成绩单
 
PPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
PPT Item # 9 - 2024 Street Maintenance Program(SMP) AmendmentPPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
PPT Item # 9 - 2024 Street Maintenance Program(SMP) Amendment
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
 
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
 
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
一比一原版(ANU毕业证)澳大利亚国立大学毕业证成绩单
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
 
Many ways to support street children.pptx
Many ways to support street children.pptxMany ways to support street children.pptx
Many ways to support street children.pptx
 
PPT Item # 5 - 5330 Broadway ARB Case # 930F
PPT Item # 5 - 5330 Broadway ARB Case # 930FPPT Item # 5 - 5330 Broadway ARB Case # 930F
PPT Item # 5 - 5330 Broadway ARB Case # 930F
 
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
一比一原版(UOW毕业证)伍伦贡大学毕业证成绩单
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
 
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
一比一原版(QUT毕业证)昆士兰科技大学毕业证成绩单
 
PPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way StopPPT Item # 8 - Tuxedo Columbine 3way Stop
PPT Item # 8 - Tuxedo Columbine 3way Stop
 

Partners in technology information security policy changes

  • 1. Partners in Technology Friday 2 November 2018 Queensland Government Chief Information Office
  • 2. IS18 – Policy Changes www.qgcio.qld.gov.au
  • 3. Queensland Government Chief Information Office IS18 - Security Policy Changes From October 1st 2018 a revised Information Security Policies (IS18) came into effect for Queensland Government. What are these changes, what do they mean, and what does the information security need to look like for Queensland Government in the future.
  • 4. Queensland Government Chief Information Office Cyber security is now a strategic risk to all organisations - No one wants to be front page news for a cyber incident - Everyone is a potential target - Increasingly seeing attackers exploiting weakest points in security Never underestimate a criminal’s ability to turn your stuff into their money or the damage to your reputation when that happens.
  • 5. Queensland Government Chief Information Office We have be “doing” Information Security for decades. So what’s changed? •Digitization •Complexity Expectations of the community and stakeholders Sophistication & motivation of attackers
  • 6. Queensland Government Chief Information Office IS18 History Part of the QGEA First established in 1993 Last major refresh of IS18 in 2009 - (5th version) Based around ISO/IEC 17799:2000 and ISO/IEC 27001:2006
  • 7. Queensland Government Chief Information Office Drivers for change Not aligned to the current of the ISO 27001 standard. Needed refreshing to match agency requirements in managing increasingly complex ICT and business environments. Hadn’t been particularly well adopted Focused on controls, not the processes and outcomes Lacked guidance on governance and assurance
  • 8. Queensland Government Chief Information Office Information Security Policy (IS18:2018) This new policy came into effect from 1 October 2018. Represents a move from a compliance focus to a risk based approach
  • 9. Queensland Government Chief Information Office Policy wording Purpose The Queensland Government is responsible for a significant amount of information. To ensure trust and deliver business value it is critical that this information is protected appropriately. This policy seeks to ensure all agencies apply a consistent, risk-based approach, to the implementation of information security to maintain confidentiality, integrity and availability. Policy statement The Queensland Government will identify and manage risks to information, applications and technologies, through their life cycle, using Information Security Management Systems (ISMS). Purpose The Queensland Government is responsible for a significant amount of information. To ensure trust and deliver business value it is critical that this information is protected appropriately. This policy seeks to ensure all agencies apply a consistent, risk-based approach, to the implementation of information security to maintain confidentiality, integrity and availability. Policy statement The Queensland Government will identify and manage risks to information, applications and technologies, through their life cycle, using Information Security Management Systems (ISMS).
  • 10. Queensland Government Chief Information Office Policy requirement 1: Agencies must implement an ISMS based on ISO 27001 Agencies must implement and operate an ISMS based on the current version of ISO 27001 Information technology - Security techniques - Information security management systems – Requirements. The scope of the ISMS will include the protection of all information, application and technology assets.
  • 11. Queensland Government Chief Information Office Policy requirement 2: Agencies must apply a systematic and repeatable approach to risk management Risk management is an integral part of operating an ISMS where risks must be considered at a business level. Agencies must adopt a risk management framework by integrating their ISMS into their corporate risk management processes.
  • 12. Queensland Government Chief Information Office Policy requirement 3: Agencies must meet minimum security requirements To ensure a consistent security posture, the ISMS must meet the following requirements: • all ICT assets that create, store, process or transmit information are assigned appropriate controls in accordance with the Queensland Government Information Security Classification Framework (QGISCF). • all information transmitted over data communications networks must be secured in line with the Network transmission security assurance framework (NTSAF)*. • all services requiring user authentication must meet the requirements of the Queensland Government Authentication Framework (QGAF)*. • agencies must implement the Australian Signals Directorate (ASD) “Essential Eight” Strategies to Mitigate Cyber Security Incidents. * Being reviewed
  • 13. Queensland Government Chief Information Office Policy requirement 4: Agency accountable officers must obtain assurance for systems Every system is unique and assurance should be applied sensibly and appropriately. Accountable officers must obtain assurance to establish an understanding of information security protections and adherence to information security policy. The level of assurance applied to systems must be based on the criticality/significance of the system, using the business impact levels determination methodology outlined in the QGISCF.
  • 14. Queensland Government Chief Information Office Policy requirement 5: Accountable officers must attest to the appropriateness of agency information security Agency accountable officers must: • endorse the Information Security Checklist. • certify that it is an accurate report of the agency’s information security posture. • endorsement must be obtained from the agency's accountable officer through corporate audit and risk committee.
  • 15. Queensland Government Chief Information Office Reporting requirements: • Agencies must submit an endorsed Information Security Compliance Checklist annually by 30 October every year to the Queensland Government Chief Information Office. • Endorsement must be obtained from the agency's accountable officer through corporate audit and risk committee. • Communicate incident response activities and threat intelligence to the Queensland Government Chief Information Office.
  • 16. Queensland Government Chief Information Office Information Security Classification Framework (QGISCF) Consistent classification of information helps Queensland government agencies make more informed and timely decisions about how they should capture, store, maintain, transmit, process, use and share information to best deliver services to Queenslanders.
  • 17. Queensland Government Chief Information Office Benefits of stronger adoption of ISO 27001 • Stronger focus on the elements of governance & accountability • Move from a compliance to a risk management based approach • Establish sustainable process improvement • Common language assists in aligning requirements when using cloud and managed ICT services • Leverage the capabilities in the market
  • 18. Queensland Government Chief Information Office Approach Focus on establishing effective governance & accountability Improve risk management capability The control objectives haven’t changed significantly Certification is not required, but may be used.
  • 19. Queensland Government Chief Information Office What does information security need to look like Cyber Security is a Business Risk not just an IT Problem. Integrated into enterprise risk management Business engagement essential Considering information security risk in all operations Design with assurance in mind
  • 20. Queensland Government Chief Information Office Further Details QGCIO Website https://www.qgcio.qld.gov.au/information-on/information-security/ QGCIO email qgcio@qgcio.qld.gov.au
  • 21. Testing Within Government Showcase 7 December 2018 QUT Gardens Point Gardens Theatre 9am – 11am 4 Government agencies – 4 SME’s collaborating to make a difference