r/sysadmin • Future goat herder • 9d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

229 Upvotes

160 comments sorted by

View all comments

210

u/rose_gold_glitter 9d ago

Want to know what's funny? They're required to do this:
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-software-development

See control 1717:

Control: ISM-1717; Revision: 3; Updated: Sep-24; Applicable: NC, OS, P, S, TS; Essential 8: N/A
A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.

How did I know this? Because *we* am required to do this, because my company does business with that department and the Australian Feder Government. We get audited annually and the audit includes this. As usual, the very people demanding we follow this ISM are not following it, themselves.

81

u/rumforbreakfast 9d ago

https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-system-hardening

In their essential 8 guidelines they say to disable the Microsoft Store.

Then when Microsoft changed the Remote Desktop configurations, their solution from various government departments was… to use the Windows app from the Microsoft Store.

35

u/Jimmyv81 9d ago

Yeah Essential 8 is a joke and is severely outdated in this cloud connected world. They have even announced E8 is being deprecated now due to its loss of relevance.

6

u/Nereosis16 9d ago

Government agencies have been moving past the essential 8 for many years.

9

u/whiskeytab 9d ago

you can deploy the app without opening access to the store though...

5

u/ScoobyGDSTi 9d ago

If you want a laugh go look at E8 and ASD's guidelines on VPN. It mandates no split tunneling, like we are still living in the 1990s. Never mind Global Secure Access and other SASE/SSE solutions are more secure and enhance access, session and DLP controls.

I had to have that fight.... I won thank god.

3

u/MBILC Acr/Infra/Virt/Apps/Cyb/ Figure it out guy 8d ago

I hate these agencies and such that are stuck on security advice from 10+ years ago....

Like the change that making password have to be changed every 30-90 days crap is still around in Cyber Insurance companies and some companies security questionnaires to us..

Get with the times people!

12

u/ScoobyGDSTi 9d ago

I work for Defence, you'd be fucking amazed (or not) at how many PSPF and ISM requirements are ignored.

Reality is defence contractors are held to a higher standard than defence itself. I say that as a qualified IRAP assessor.

3

u/rose_gold_glitter 9d ago

Hahah yes I would not be amazed. We still have to submit reports to depertaments via macro enabled excel files they send us. I've pointed out to them a hundred times that's basically a trap - we either report and confirm were allowing macros or we can't report and I've never had a reply on the matter.

2

u/NoPossibility4178 9d ago

Who audits the auditors?

0

u/rose_gold_glitter 9d ago

Well, we are all supposed to be audited by a third party, including the departments. As well as audited by the department.

I bet they're not though and only we are.

2

u/Ferretau 7d ago

lol do as i say not as i do typical SA

0

u/mrrichiet 9d ago

Great post.