Government information and services can be high-value targets for malicious and statesponsored threat actors. Cyber incidents can threaten the information held by the Government, public trust in our institutions, and the various digital functions that governments provide. For this reason, the Government has a vital role in setting best practice cyber security standards – a role recognised by nearly all stakeholders during consultation. Industry has clearly voiced an expectation that Government improves its own cyber security, in addition to imposing higher standards on other organisations. Australia urgently needs a new approach to government cyber security. Enduring and low levels of cyber maturity across many Australian Government entities have revealed major gaps in our security posture. We have significant cyber skills shortages in the APS, and many government systems do not yet meet the ASD’s Essential Eight strategies for mitigating cyber security incidents. To uplift our collective cyber security, the Government must itself adopt cyber best practices – including driving accountability for cyber security across its own departments and agencies. How the Government will take action Deliver a plan to uplift Commonwealth cyber security to position the Australian Government as a world-class trusted digital government. Under this initiative, the Government will: 1. Strengthen the cyber maturity of government departments and agencies The Cyber Coordinator will be enabled to lead whole-of-government cyber security uplift. As part of their role, the Coordinator will oversee the implementation and reporting of cyber maturity across Commonwealth departments and agencies. The Coordinator will also work collaboratively with state, territory and local governments to promote investment that will drive a meaningful shift in government cyber maturity. To protect the Australian Government’s data and digital estate, we will build on the best practice principles established within ASD’s Essential Eight. We will also draw on internationallyrecognised approaches to zero trust, aiming to develop a whole-of-government zero trust culture. We will implement defined controls across our networks that will be consolidated into the Australian Government Information Security Manual, and enabled through the Protective Security Policy Framework. To provide ongoing accountability, we will develop an internal cyber security program and assurance function. We will scale up support to government entities uplifting their maturity against the Essential Eight. We will also conduct regular reviews of the cyber maturity of Commonwealth entities as part of the Investment Oversight Framework led by the Digital Transformation Agency. These reviews will inform further evolution of our security frameworks and help government entities meet changes in the evolving threat landscape. 2023–2030 Australian Cyber Security Strategy 43

Select target paragraph3