In conducting our audit we took precautions against inadvertently compromising information held on
Agencies internal computer systems and the risk that our attacks could seriously impede performance
We also worked closely with the Police Technology Crime Investigation Team. This team handles
Investigation and response when a potential cyber attack (unauthorised use) is reported. Unauthorised use of computer systems is a criminal offence under the Criminal Code.
Prior to commencing the audit at agencies we reviewed their policies and procedures for identifying and responding to cyber threats. This included reviewing information security policies, incident response plans, staff induction processes, and security awareness training.
We performed external and internal attacks to test the vulnerabilities of agency computer systems.