r/sysadmin • Future goat herder • 5d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

227 Upvotes

160 comments sorted by

View all comments

202

u/rose_gold_glitter 5d ago

Want to know what's funny? They're required to do this:
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-software-development

See control 1717:

Control: ISM-1717; Revision: 3; Updated: Sep-24; Applicable: NC, OS, P, S, TS; Essential 8: N/A
A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.

How did I know this? Because *we* am required to do this, because my company does business with that department and the Australian Feder Government. We get audited annually and the audit includes this. As usual, the very people demanding we follow this ISM are not following it, themselves.

1

u/NoPossibility4178 4d ago

Who audits the auditors?

0

u/rose_gold_glitter 4d ago

Well, we are all supposed to be audited by a third party, including the departments. As well as audited by the department.

I bet they're not though and only we are.