Government information and services can be high-value targets for malicious and statesponsored threat actors. Cyber incidents can threaten the information held by the Government,
public trust in our institutions, and the various digital functions that governments provide. For this
reason, the Government has a vital role in setting best practice cyber security standards – a role
recognised by nearly all stakeholders during consultation. Industry has clearly voiced an
expectation that Government improves its own cyber security, in addition to imposing higher
standards on other organisations.
Australia urgently needs a new approach to government cyber security. Enduring and low
levels of cyber maturity across many Australian Government entities have revealed major
gaps in our security posture. We have significant cyber skills shortages in the APS, and many
government systems do not yet meet the ASD’s Essential Eight strategies for mitigating cyber
security incidents. To uplift our collective cyber security, the Government must itself adopt
cyber best practices – including driving accountability for cyber security across its own
departments and agencies.
How the Government will take action
Deliver a plan to uplift Commonwealth cyber security to position the Australian Government as a
world-class trusted digital government.
Under this initiative, the Government will:
1. Strengthen the cyber maturity of government departments and agencies
The Cyber Coordinator will be enabled to lead whole-of-government cyber security uplift.
As part of their role, the Coordinator will oversee the implementation and reporting of cyber
maturity across Commonwealth departments and agencies. The Coordinator will also work
collaboratively with state, territory and local governments to promote investment that will drive
a meaningful shift in government cyber maturity.
To protect the Australian Government’s data and digital estate, we will build on the best
practice principles established within ASD’s Essential Eight. We will also draw on internationallyrecognised approaches to zero trust, aiming to develop a whole-of-government zero trust
culture. We will implement defined controls across our networks that will be consolidated into
the Australian Government Information Security Manual, and enabled through the Protective
Security Policy Framework.
To provide ongoing accountability, we will develop an internal cyber security program and
assurance function. We will scale up support to government entities uplifting their maturity
against the Essential Eight. We will also conduct regular reviews of the cyber maturity of
Commonwealth entities as part of the Investment Oversight Framework led by the Digital
Transformation Agency. These reviews will inform further evolution of our security frameworks
and help government entities meet changes in the evolving threat landscape.
2023–2030 Australian Cyber Security Strategy
43