news The Australian Signals Directorate appears to have released a guide to hardening Microsoft’s Windows 8 operating system, three years after the software was released for use by corporate customers, and as Microsoft is slated to release its next upgrade, Windows 10.
The Australian Signals Directorate, which has the motto Reveal Their Secrets — Protect Our Own, is one of the key Federal Government agencies responsible for protecting the security of public sector IT systems. It publishes its Information Security Manual — the key document which consists of a standard governing the security of government IT systems — as well as a list of approved devices for use in Government, and manuals for hardening IT platforms so they can be securely used in Government.
However, the agency is known for being substantially behind the times when it comes to approving modern technology to be upgraded.
For example, ASD only approved Apple iPhone and iPad devices for use within the Federal Government in April 2012, almost four years after the iPhone first launched in Australia, and at a stage where Apple’s iOS platform was considered suitable for secure corporate deployments. The iPad, which runs the same iOS platform, launched in April 2010. Demand was so great for the Apple platforms within the Federal Government that a number of politicians and public servants bought their own personal device and were carrying two units — an official Government model, often a BlackBerry, and a personal Apple iPhone.
Similarly, ASD only reportedly started certifing the Android platform for Government use in May 2013, after the point where Android started to dominate global marketshare for smartphone shipments. At that stage, only Samsung units were supported by ASD.
Currently, ASD’s official Evaluated Products List appears to contain only Apple and BlackBerry mobile devices, despite the fact that the BlackBerry handset platform is regarded as legacy by corporations and governments globally, having been largely superceded by platforms from Apple, Android (often Samsung) and Microsoft (with its Nokia acquisition). It is not clear why only the two Apple and BlackBerry platforms appear to be supported.
According to the ASD’s website, it appears to be similarly behind when it comes to desktop platforms.
As first noted by Computerworld, this month the agency published hardening guides to the Microsoft Windows 7 Service Pack 1, Windows 8.1, and Office 2013 platforms, as well as content management systems. Windows 7 Service Pack 1 was released in February 2011, while Windows 8 was released to manufacturing in August 2012 — three years ago — with the updated Windows 8.1 eing released ot manufacturing oin August 2013. Office 2013 was released to manufacturing in October 2012.
The news comes as Microsoft is releasing newer versions of its software. The company released Windows 10 to manufacturers on July 15 this year, and Office 2016 is slated to be released later this year.
To be honest, I’m not sure entirely what we’re seeing here. The Australian Signals Directorate isn’t the most transparent of organisations at the best of times, and things often get a little confusing when you’re trying to assess what it’s up to.
However, what I think we’re seeing is that the organisation currently only officially supports Apple and BlackBerry on its mobile devices Evaluated Products List, and that it has only just released hardening guides for a bunch of other Microsoft software which is several years old.
In one sense this is fairly normal and expected behaviour. Many corporates and government organisations tend to lag a few releases behind new software upgrades — they tend to focus on long-term, stable releases. In this vein, we’ve seen a lot of organisations stick with the stable Windows XP platform, not upgrading until it became Windows 7 was as stable and much more updated in terms of the features it offered. In comparison, Windows Vista and Windows 8 have not been as widely adopted.
However, on the other hand, it does feel like the ASD is getting woefully out of date here. I would expect that Office 2013 had been adopted by quite a few government organisations already, and the same for Windows 7 Service Pack 1. When you lag behind even government agencies, you know you’re quite a bit out of date when it comes to technology. How long will it take ASD to release a hardening guide for Windows 10? And will it ever start to get serious about Android? I thought that was already wrapped up, but I can’t find much about it on ASD’s website.
Perhaps I’m wrong on all these matters. I’d welcome comment from anyone in the public sector as to what’s happening here — happy to be corrected and to correct the record.
Image credit: Microsoft