Story image

ASD will not get more powers for mass surveillance on Australians

30 Apr 18

Rumours suggesting that the Australian Signals Directorate may get more powers to spy on Australians are completely unfounded, according to the government.

Last week media agency News Corp claimed that Australian Government department heads had mentioned increasing the Australian Signals Directorate’s (ASD) ability to collect citizens’ private emails, text messages, and bank records.

However the media agency has the wrong idea and there is no such proposal,  claims a joint statement from Department of Defence secretary Greg Moriarty, Department of Home Affairs secretary Michael Pezzullo, and Australian Signals Directorate director Mike Burgess.

“There is no proposal to increase the ASD’s powers to collect intelligence on Australians or to covertly access their private data,” the statement says.

While the ASD’s cybersecurity functions are being revamped as part of the 2017 Independent Intelligence Review, this does not include the collection of intelligence on Australian citizens.

The statement says Parliament has already passed legislation that enables ASD to be an independent statutory agency within the Defence portfolio.

At the ACSC Conference last month, Burgess explained that the ASD will take over the Australian Cyber Security Centre (ACSC) from July.

As part of the changes under the Independent Intelligence Review, the ASD will be able to focus on cybersecurity risks across governments, businesses, and the community.

The ASD will also be given more abilities to combat cyber-enabled crime. This includes pure play cybercrime (hacking for criminal purposes, nation-state actors), and cyber-enabled serious crime.

“ASD’s focus on nation state actors, that is, countering cyber espionage, interference or attack will continue and will remain important,” Burgess says.

The centre’s work must lead to an improvement in the identification and management of cyber security risk for all Australians.

“The cyber security function entails protecting Australians from cyber-enabled crime and cyber-attacks, and not collecting intelligence on Australians. These are two distinct functions, technically and operationally,” the statement continues.

The officials do mention that cybersecurity requires the consideration of all options to protect Australians and the Australian economy, but that does not include mass intelligence collection.

“We would never provide advice to Government suggesting that ASD be allowed to have unchecked data collection on Australians – this can only ever occur within the law, and under very limited and controlled circumstances,” the statement concludes.

With regards to the ASD and ACSC merger, Burgess says his key priorities for the next 12 months are:

  • A national assessment of Australian cyber security, with an initial focus on critical infrastructure.
  • Collaboration with major Internet Service Providers and critical infrastructure providers to drive out known problems and identify first seen more serious threats.
  • Executing a counter cybercrime campaign, and
  • Outreach and influence to improve the identification and management of cyber security risk across the community, business and government.
How to stay safe when shopping online
Online shopping is a great way to avoid the crowds – but there are risks.
Dell EMC embeds security in latest servers
Dell EMC's 14th generation of PowerEdge servers has comprehensive management tools to provide security across hardware and firmware.
Why data backups should be a part of daily operations
"Disaster recovery needs to address complete system failure and provide a set of security policies to govern disaster incidents."
Businesses focusing on threats from within - survey
Over 50% of respondents reported that 100 days of dwell time or more was representative of their organisation.
Corelight and Exabeam partner to improve network monitoring
The combination of lateral movement and siloed usage of point security products leaves many security teams vulnerable to compromise.
SailPoint releases first identity annual report
SailPoint’s research found that many organisations are lacking maturity in their governance processes over identities.
Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
Businesses too slow on attack detection – CrowdStrike
The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 cases.