10.07.2015 Views

Appendices - Department of Business - Northern Territory Government

Appendices - Department of Business - Northern Territory Government

Appendices - Department of Business - Northern Territory Government

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

appendicesAPPENDIX IIAudit Audit Outcome or Recommendation Summary ActionmyHR Web Application Security AssessmentAlthough the tests conducted in this assignmentdid not prove that information within myHR couldbe easily breached, a number <strong>of</strong> opportunitieswere identified to improve security controls over themyHR application:• production data used in development and testenvironments• information in myHR has not been classifiedaccording to government requirements• general security observations – special charactersare accepted in scripts• lack <strong>of</strong> myHR data encryption• excessive user logon attempts are possible via theweb (http) logon process• myHR server house-keeping is required.All required actions have been completed.It was noted that the security vulnerability andpenetration testing <strong>of</strong> myHR did not succeed inbreaching myHR controls:• system controls for training and test environments<strong>of</strong> PIPS and myHR implemented and scheduledfor review quarterly• no action is required –myHR is a user interfacefor the Nomad system (PIPS) and only displaysinformation that is part <strong>of</strong> this system. RecordsManagement Standards are applied to allpersonnel files• finding is incorrect as myHR does not allowprogram commands using special characters• myHR sits behind the WAN and is protectedby security protocols used for all governmentapplications. Consideration <strong>of</strong> suggestedencryption will be included in any modification<strong>of</strong> myHR• third party password application is no longerrequired due to migration <strong>of</strong> myHR to a singleWindows 2003 server• myHR is fully hosted by Data Centre Servicesand subject to standard housekeeping forhosted servers.<strong>Department</strong> <strong>of</strong> <strong>Business</strong> and Employment Annual Report 2009–10185

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!