Tuesday | 7 July, 2009
CSO
PwC review lauds ATO's security practices
Tax office a bastion of secure information, review finds.
Howard Dahdah (Computerworld) 08/05/2008 13:08:01

The Australian Taxation Office is on top of its game when it comes to information security, an independent investigation has found.

PricewaterhouseCoopers was commissioned last December to do a comprehensive four-month long review of the security practices at the Tax Office.

In his summary notes, PwC partner Mark Ridley, said that as an organisation, "the Tax Office is highly conscious of information security and considers the security of the information with which it is entrusted as a serious business issue."

Furthermore, "the Tax Office compares favourably with other organisations - particularly with regard to security culture - and a strong sense of responsibility for security exists amongst Tax Officers."

The ATO undertook the review as a preventative measure after high profile cases overseas such as in the US and UK that resulted in the loss or disclosure of sensitive information.

"It was clear during the course of this review with meetings with Senior Executives and Management from across the organisation, that the Tax Office generally has a lower appetite for risk in relation to stewardship of client information than many other organizations which we see," the report reads.

"While this evidently stems from the large volumes of personal and corporate sensitive information which the Tax Office processes on a daily basis, the Tax Office appears more security conscious when compared to other organisations with large customer and financial databases."

The ATO came up trumps in many areas. The investigation, titled Information Security Practices Review, also found the ATO's information security governance structures are "generally sound"; it has a clear corporate stance on security matters; has effective education and awareness programs; has a well defined security classification framework; has a range of effective security monitoring mechanisms; and has incident response mechanisms in place.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content Syndicate content
 
Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Sponsored Links