I propose to take Questions Nos. 1273 and 1274 together.
My Department's Managed Desktop services are provided by the Office of the Government Chief Information Officer (OGCIO). The OGCIO implements an extensive Information Security Management System (ISMS) comprising of security policies and controls aligned and certified to the industry security standard ISO 27001:2022 to address risks from cyber security attacks.
The ISO 27001: 2022 standards underpin a strategic approach to managing and mitigating cyber risks. Core capabilities such as threat analysis, vulnerability management, and cyber infrastructure support are delivered through an appropriate combination of resources and skillsets. In addition, the standard governs the assessment and treatment of supplier related risks. It requires a systematic approach to identifying, assessing, and mitigating risks associated with supply chain and vulnerability management. All third-party services are subject to appropriate due diligence, contractual and security requirements, and ongoing oversight to ensure that cybersecurity risks are effectively identified and managed.
For operational and security reasons, the National Cyber Security Centre has advised that details of systems, processes and staff resources, which could in any way compromise cyber security measures in place, should not be disclosed. I am satisfied that, working with the OCGIO, my Department has appropriate policies, systems, and measures in place to effectively manage the risk of cyber security threats.