WA Parliamentary Question on Notice regarding penetration testing of government agencies' network systems and websites since March 2017. Reveals which agencies conducted tests, by whom, and on what systems.

AnsweredQoN 3800Legislative Assembly
Asked
14 August 2018
Portfolio
Tourism; Racing and Gaming; Small Business; Defence Issues; Citizenship and Multicultural Interests

QuestionView source ↗

For all departments, agencies, government trading enterprises or boards within the Minister’s portfolio responsibilities, I ask since 11 March 2017: (a) Have any independent consultants or companies been engaged to run penetration or 'White Hat' tests on any internal or external network systems: (i) If so, what consultant or company was engaged and on what date; (ii) If so, did it include any social engineering or phishing tests; and (iii) If not, why not; and (b) Have any independent consultants or companies been engaged to run penetration or 'White Hat' tests on any websites: (i) If so, what consultant or company was engaged and on what date; and (ii) If so, what website (domain only) was tested?

AnswerView source ↗

Answered
18 September 2018
Responded by
Minister for Tourism; Racing and Gaming; Small Business; Defence Issues; Citizenship and Multicultural Interests
Response time
9 days
Tourism Portfolio
Tourism Western Australia
Please refer to Legislative Assembly Question on Notice 3789
Rottnest Island Authority
Please refer to Legislative Assembly Question on Notice 3792
Racing and Gaming Portfolio
For the Racing, Gaming and Liquor Division of the Department of Local Government, Sport and Cultural Industries please refer to Legislative Assembly Question on Notice 3796
Racing and Wagering Western Australia (RWWA)
a)      Yes
(i)         Asterisk Information Security, August 2017
(ii)       No
(iii)     Phishing testing is conducted using a third party service
b)      Yes
(i)     Asterisk Information Security, August 2017
(ii)    rwwa.com.au, tabtouch.com.au, tabtouch.mobi, ozchase.com.au
Western Australian Greyhound Racing Association (WAGRA)
a)      No
(i)         Not applicable
(ii)       Not applicable
(iii)     Not required
b)      No
(i)     Not applicable
(ii)    Not applicable
Burswood Park Board (BPB)
a)      No
(i)         Not applicable
(ii)       Not applicable
(iii)     Not required
b)      No
(i)     Not applicable
(ii)    Not applicable
Small Business Portfolio
Small Business Development Corporation
(a) Yes
(i)  Asterisk Information Systems Pty Ltd; 24 May 2017.
(ii) No
(iii) The focus of the penetration tests was the effectiveness of the firewall and system   security.
(b) Yes
(i) Asterisk Information Systems Pty Ltd; 24 May 2017.
(ii) mail.smallbusiness.wa.gov.au
Defence Issues Portfolio
11 March 2017- 30 June 2017
Please refer to Legislative Assembly Question on Notice 3801
July 2017 - Current
Please refer to Legislative Assembly Question on Notice 3789
Citizenship and Multicultural Interests Portfolio
Please refer to Legislative Assembly Question on Notice 3796

Explore WA Government Data

Search the full archive in the free dashboard, or query programmatically via API.

Explore more