On Monday, 2 March 2020 the Australian Signals Directorate (ASD) and the Digital Transformation Agency (DTA) announced the results of the review of the Cloud Services Certification Program (CSCP) and Information Security Registered Assessors Program (IRAP). The review made the following recommendations:
- Close the CSCP and create new co-designed cloud security guidelines with industry
- Grow and enhance IRAP
- Establish Government and Industry Consultative Forums for cyber security
- Update incentives in Procurement and Administrative Instructions and Guidance to reflect the cessation of the CSCP
As of March 2, 2020, the ASD is no longer be the Certification Authority and has ceased all certification activities, including re-certification activities. All ASD certifications and re-certification letters will be void from July 27, 2020 and the Australian government Information Security Manual (ISM) has been updated to remove the requirement to select cloud services from the Certified Cloud Services List (CCSL).
Under the Australian government Secure Cloud Strategy, Commonwealth agencies are able to self assess cloud services using practices already used to assess ICT systems.
What now:
On July 27, 2020, the Australian Cyber Security Centre (ACSC) and the Digital Transformation Agency (DTA) released new Cloud Security Guidance co-designed with industry to support the secure adoption of cloud services across government and industry. AWS continues to undertake IRAP assessments to maintain currency of the assessment and to onboard new services. Commonwealth entities will continue to be responsible for their own assurance and risk management activities. In accordance with the Australian government Secure Cloud Strategy, Commonwealth entities are able to self-assess cloud services using practices already used to assess ICT systems. ASD will enhance existing cloud security guidance through the development of co-designed guidelines with industry. These guidelines will further aid Commonwealth entities and Australian businesses to increase their cyber security and resilience.
To date, ASD has developed a number of useful guides for organisations to undertake the appropriate security assessments in relation to cloud services. It is recommended that any assessment clearly addresses the security controls in the ISM, and ASD cloud security guidance, including:
The DTA continues to encourage Commonwealth agencies to use the Australian government Secure Cloud Strategy to support their adoption of cloud services.