Australian Government Technical Interoperability Framework
Appendix A - Security considerations
Amongst others, the following list of security issues will have to be considered and addressed as part of implementing an interoperability framework:
- The overall management processes/control mechanisms required that address the "big picture" issues of interoperability. For example:
- addressing the different standards and levels of security of the different stakeholders (Australian Government, State and Local Governments, private industry and community sectors)
- defining and managing the relationships/levels of interoperability between the three tiers of government, industry and the community
- the level and any restrictions on the classification/sensitivity of the information traversing the framework
- defining and managing how the Interoperability Technical Framework fits into and supports other frameworks and identification and management of security issues associated with this
- the security, business impact and cost implications of changing the standards/specifications and evolving/updating or changing the framework
- defining and allocating responsibility for security
- change control
- legacy systems
- proprietary issues
- control and knowledge of who is authorised, and who is connecting to which resources (accountability/auditability)
- the impact of changes made by one stakeholder on the whole
- other security issues such as the weakest link in the chain" potential security flaws
- Identification and management of the risks and threats associated with implementing the interoperability framework
- Identification and implementation of a minimum set of security controls required to ensure availability, confidentiality, integrity, authenticity and non‑repudiation of information traversing the framework is maintained and consistent with its classification/sensitivity. From the government perspective, this should be in line with government policies/requirements (e.g. PSM, ACS133, DSD advice).
Contact for information on this page: interoperability@finance.gov.au
