Skip to content

Understanding system security

The Australian Cyber Security Centre (which is part of the Australian Signals Directorate) has released a series of articles around the “Essential Eight” security principles.

The following table describes how each of these principles is applied to the secure operation of MVOW.

Essential measures for data security

MeasurePurposeResponsibilityComments
Application whitelistingTo control the execution of unauthorised softwareContractorThis should be handled by your IT policies because it relates to your desktop environment.
Patching applicationsRemediate known security vulnerabilitiesContractor / PagarosYour desktop systems need to be kept up to date, as do the MVOW web servers.
Configuring MS Office macro settingsTo block untrusted macrosContractorThis should be handled by your IT policies because it relates to your desktop environment.
Application hardeningTo protect against vulnerable functionalityContractorThis should be handled by your IT policies because it relates to your desktop environment.
Restricting administrative privilegesTo limit powerful access to systemsContractor / PagarosWhile this relates to your desktop environment, MVOW allows you to restrict functionality based on user roles. See Understanding users and roles.
Patching operating systemsTo remediate known security vulnerabilitiesContractor / PagarosYour desktop systems need to be kept up to date, as do the MVOW web servers.
Multifactor authenticationTo protect against risky activitiesPagarosMVOW uses two-factor authentication to provide additional security surrounding login. See Understanding authentication.
Daily backupsTo maintain the availability of critical dataPagarosPagaros does this, retaining daily backups for a week, weekly backups for a month, monthly backups for a year, and annual backups indefinitely.
lightbulb

For more about each measure, I’d encourage you to read the strategy document to understand the why of each principle. Also see the maturity model to understand what to do in detail.