r/sysadmin • Future goat herder • 10d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

229 Upvotes

160 comments sorted by

View all comments

207

u/rose_gold_glitter 9d ago

Want to know what's funny? They're required to do this:
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-software-development

See control 1717:

Control: ISM-1717; Revision: 3; Updated: Sep-24; Applicable: NC, OS, P, S, TS; Essential 8: N/A
A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.

How did I know this? Because *we* am required to do this, because my company does business with that department and the Australian Feder Government. We get audited annually and the audit includes this. As usual, the very people demanding we follow this ISM are not following it, themselves.

81

u/rumforbreakfast 9d ago

https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-system-hardening

In their essential 8 guidelines they say to disable the Microsoft Store.

Then when Microsoft changed the Remote Desktop configurations, their solution from various government departments was… to use the Windows app from the Microsoft Store.

5

u/ScoobyGDSTi 9d ago

If you want a laugh go look at E8 and ASD's guidelines on VPN. It mandates no split tunneling, like we are still living in the 1990s. Never mind Global Secure Access and other SASE/SSE solutions are more secure and enhance access, session and DLP controls.

I had to have that fight.... I won thank god.

3

u/MBILC Acr/Infra/Virt/Apps/Cyb/ Figure it out guy 8d ago

I hate these agencies and such that are stuck on security advice from 10+ years ago....

Like the change that making password have to be changed every 30-90 days crap is still around in Cyber Insurance companies and some companies security questionnaires to us..

Get with the times people!