Greetings from the seminar "Neither Confirm Nor Deny: National Security Secrecy and Australia's Liberal Democracy" from ANU. Emily Hitchman points out that technology has presented a challenge for national security in the past, with fax machines providing a way to breach security long before Wikileaks. This may have an effect on the AUKUS agreement with the USA and UK. One way I suggest would be the question of nuclear weapons.
ps: I am actually in a bus shelter waiting for a bus to take me to the University. I am listening to the presentation via video conference on my phone. A tip is to use "driving mode": this turns off video and the microphone, avoiding embarrassing images and noises on the conference when you are out and about (it also reduces the bandwidth required on your mobile connection).
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Wednesday, December 11, 2024
Sunday, August 11, 2019
Australia Pacific Security College
![]() |
| Hon Marise Payne, Minister for Foreign Affairs |
An APSC Design Summary is available. It is envisaged the APSC activities could include "... workshops, seminars, courses, secondments and online resources...". I suggest that this could be flipped, to make online resources the priority. The Pacific is a big place*, and the students will learn better if they spend most of their time at work, in their own country, studying online. They can keep in touch with their teachers, and peers in other countries, in online forums. There are well established processes for doing this.
![]() |
| Tom Worthington speaking on e-learning in Colombo |
* In 2005 I conducted a five day workshop
in Samoa for staff from museums around the South Pacific region, on the use of
computer and telecommunications technologies. I spent most of a day traveling to Apia, but due to the International Dateline, I arrived shortly before I left. ;-)
Monday, July 15, 2019
Qualifications of Australian Government Contractors will be Checked as Part of Security Procedures
Today I went along to a presentation at the Department of Defence about the new Defence Industry Security Program (DISP). Previously, companies and contract staff had to have a Defence contract to get a security clearance, but it was difficult to get a contract without a clearance. The new procedures allow a company to apply for DISP membership, and then tender for contracts. The company can then appoint their own Security Officer, to nominate staff for security clearances. That all makes sense, but one curious side effect is that companies will also have to check the qualifications of staff. This may require universities to improve the certification service they provide. An easily faked paper certificate will likely not be sufficient.
As well as private companies, universities can apply for DISP membership. There are four levels of membership (Entry, 1, 2, 3) and four categories (Governance, Personal Security, Physical Security, Information & Cyber Security), making a sixteen cell matrix.
As well as private companies, universities can apply for DISP membership. There are four levels of membership (Entry, 1, 2, 3) and four categories (Governance, Personal Security, Physical Security, Information & Cyber Security), making a sixteen cell matrix.
Friday, July 22, 2016
Australian Cyber Security Innovation Centre in Canberra
The Minister for Defence announced $12M from Australian Signals Directorate
(ASD) for a joint facility at ANU (23 June 2016). The height of the planned Computer
Science and Mathematics building is being increased by one floor to
accommodate joint work on for an Cyber Security Innovation Centre.
The work for the new building is already underway (I can see it out of the window of my office in the existing Computer Science and Information Technology (CIST) building, where the ANU Research School of Computer Science is located.
About a year ago I was walking past the CIST seminar room (the famous N101) on the floor below my office and noticed a group of people I did not recognize. It turned out that they were from the ASD, there to present to students on Careers at ASD, but were having difficulty getting the projector to work (a common occurrence). I helped with the projector and stayed on for the talk.
Afterwards the ASD staff commented on the difficulty they had interacting with universities. I pointed out that CSIRO had solved this problem by moving on campus. CSIRO have one wing of the CIST building at ANU, while the Research School of Computer Science has the other. Between the building's two wings is a shared staff room, to facilitate informal interaction. To meet bureaucratic requirements (and show the architect had a sense of humor), the common room was designed with two doors next to each other: one for ANU and one for CSIRO, opening into the same shared space.
ANU was building a new computer science building, so I suggested ASD could pay for an extra floor to be added. This was an off-the-cuff suggestion and I did not think much more about it. No doubt I was not the only one to suggest it.
The work for the new building is already underway (I can see it out of the window of my office in the existing Computer Science and Information Technology (CIST) building, where the ANU Research School of Computer Science is located.
About a year ago I was walking past the CIST seminar room (the famous N101) on the floor below my office and noticed a group of people I did not recognize. It turned out that they were from the ASD, there to present to students on Careers at ASD, but were having difficulty getting the projector to work (a common occurrence). I helped with the projector and stayed on for the talk.
Afterwards the ASD staff commented on the difficulty they had interacting with universities. I pointed out that CSIRO had solved this problem by moving on campus. CSIRO have one wing of the CIST building at ANU, while the Research School of Computer Science has the other. Between the building's two wings is a shared staff room, to facilitate informal interaction. To meet bureaucratic requirements (and show the architect had a sense of humor), the common room was designed with two doors next to each other: one for ANU and one for CSIRO, opening into the same shared space.
ANU was building a new computer science building, so I suggested ASD could pay for an extra floor to be added. This was an off-the-cuff suggestion and I did not think much more about it. No doubt I was not the only one to suggest it.
Monday, July 4, 2016
Digital Indonesia Conference in Canberra
The Digital Indonesia: Challenges and Opportunities of the Digital Revolution Conference will be at the Australian National University in Canberra, 16 and 17 September 2016. This is free to attend, but registration is required. The Draft program includes:
- Digital economy: opportunities, Mari Pangestu, The University of Indonesia
- Mobile telephony, Emma Baulch, Queensland University of Technology
- The digital economy: challenges, Bede Moore, Digital entrepreneur
- Internet and overcoming ‘the digital divide’, Onno W Purbo, Surya University
- Hacking culture: between art, technology and science, Edwin Jurriens, The University of Melbourne
- ‘Disruptive’ technologies and labour: the Go-Jek debate, Michele Ford, The University of Sydney
- Social media and Islamic practice online/offline, Martin Slama, Austrian Academy of Sciences
- Using ‘Big data’, Diastika Rahwidiati and Jonggun Lee, UN Pulse Lab Jakarta
- Digitalising knowledge: education, libraries, archives, Kathleen Azali, Institute of Southeast Asian Studies
- State crackdown online, Usman Hamid, The Australian National University
- Online counter-terrorism, Nava Nuraniyah, Institute for Policy Analysis of Conflict
Monday, June 27, 2016
Australian Cyber Security Courses
The Australian Government has committed $3.5M over four years for an Academic Centres of Cyber Security Excellence program. Already there are a number of cyber security programs offered by Australian universities. But before looking at courses, how do these fit with professional requirements?
Edith Cowan University offer a ECU Master of Cyber Security. This includes units general computer units, plus security related ones, including: Computer Security, Network Security Fundamentals, Wireless Security, Introductory Computer Forensics, Information Security, and most interestingly, Ethical Hacking and Defence. There is also a ECU Graduate Diploma of Cyber Security, and ECU Graduate Certificate of Cyber Security, Bachelor of Science (Cyber Security).
Swinburne University offer a cybersecurity major in Computer Science and Engineering bachelor degrees, with courses in eForensic Fundamentals, Information Systems Risk and Security, IT Security and Network Security & Resilience. There is also a cybersecurity Master of Information and Communication Technologies (Research). Some of the programs include work placements.
UNSW Canberra, at the Defence Force Academy, is offering a new Master's Degree in Cyber Security, Strategy and Diplomacy, as well as a Master of Cyber Security and Master of Cyber Security Operations. UNSW Canberra also offers an extensive range of security courses including: Critical Infrastructure Cyber Security, Cyber Adversary Tradecraft, Intrusion Analysis and Response, Cyber Security Boot Camp, Introduction to Pen Testing, Executive Security Awareness, Computer Network Operation / Network Security Operations, Wireless Security, Reverse Engineering of Malware
Murdoch University offers a Cyber Forensics and Information SecurityBachelor of Science.
Macquarie University offers a Bachelor of Security Studies, and a Master of Information Technology with a specialisation in Internetworking and Cyber Security.
The Australian National University offers courses in Cyber-security and Cybercrime, Cyber Warfare Law and Statecraft and national security in cyberspace.
University of South Australia offers a Master of Science (Cyber Security and Forensic Computing).
University of Woolongong offer a BSc with a Major in Cyber Security, with course in System Security, Corporate Network Security, Cryptography and Secure Applications and Ethical Hacking.
Deakin University offer a Bachelor of Cyber Security.
Box Hill Institute offer a Certificate IV in Information Technology (Specialising in Cyber Security).
Victoria Polytechnic offer an Advanced Diploma of Network Security (ICT60215).
One point to note is that vocational programs are standardized across Australia, so the same cyber security qualifications offered by Box Hill and Victoria Polytechnic could be offered by other TAFEs and by private Registered Training Organizations. These qualifications could also be offered by training units within government agencies and companies, for their own staff. In contrast, the content of university degrees are not standardized in Australia, so degrees at the same level with similar "cyber security" titles, could have very different content.
Charles Stury University (CSU) offer a free Network Security Administrator Certification short course to help prepare for certification as an EC-Council Network Security Administrator (ENSA)
At the introductory level the Open University run a MOOC on "Introduction to Cyber Security". Also there is a more traditional on-line course "An introduction to information security".
ps: Having a background in defence, my teaching occasionally touches on cyber security. Last semester I was teaching IT ethics using a hypothetical about Cyberwarfare Over the South China Sea.
Cyber Security Skills
The Skills Framework for the Information Age (SFIA) is used by the Australian Computer Society to identify the skills IT professionals should have and to accredit suitable university courses. SFIA Version 6 has security related skills definitions:- Information security SCTY
- Information assurance INAS
- Security administration SCAD
- Penetration testing PENT
- Incident management USUP
Australian Cyber Security Programs
Edith Cowan University offer a ECU Master of Cyber Security. This includes units general computer units, plus security related ones, including: Computer Security, Network Security Fundamentals, Wireless Security, Introductory Computer Forensics, Information Security, and most interestingly, Ethical Hacking and Defence. There is also a ECU Graduate Diploma of Cyber Security, and ECU Graduate Certificate of Cyber Security, Bachelor of Science (Cyber Security).
Swinburne University offer a cybersecurity major in Computer Science and Engineering bachelor degrees, with courses in eForensic Fundamentals, Information Systems Risk and Security, IT Security and Network Security & Resilience. There is also a cybersecurity Master of Information and Communication Technologies (Research). Some of the programs include work placements.
UNSW Canberra, at the Defence Force Academy, is offering a new Master's Degree in Cyber Security, Strategy and Diplomacy, as well as a Master of Cyber Security and Master of Cyber Security Operations. UNSW Canberra also offers an extensive range of security courses including: Critical Infrastructure Cyber Security, Cyber Adversary Tradecraft, Intrusion Analysis and Response, Cyber Security Boot Camp, Introduction to Pen Testing, Executive Security Awareness, Computer Network Operation / Network Security Operations, Wireless Security, Reverse Engineering of Malware
Murdoch University offers a Cyber Forensics and Information SecurityBachelor of Science.
Macquarie University offers a Bachelor of Security Studies, and a Master of Information Technology with a specialisation in Internetworking and Cyber Security.
The University of Canberra offers a Graduate Certificate in Cyber Law and Policy, with courses in Cybercrime Investigations, Cyber Security Law, Digital Evidence and Intelligence Management.
The Australian National University offers courses in Cyber-security and Cybercrime, Cyber Warfare Law and Statecraft and national security in cyberspace.
University of South Australia offers a Master of Science (Cyber Security and Forensic Computing).
University of Woolongong offer a BSc with a Major in Cyber Security, with course in System Security, Corporate Network Security, Cryptography and Secure Applications and Ethical Hacking.
Deakin University offer a Bachelor of Cyber Security.
Sub-degree Programs
Box Hill Institute offer a Certificate IV in Information Technology (Specialising in Cyber Security).
Victoria Polytechnic offer an Advanced Diploma of Network Security (ICT60215).
One point to note is that vocational programs are standardized across Australia, so the same cyber security qualifications offered by Box Hill and Victoria Polytechnic could be offered by other TAFEs and by private Registered Training Organizations. These qualifications could also be offered by training units within government agencies and companies, for their own staff. In contrast, the content of university degrees are not standardized in Australia, so degrees at the same level with similar "cyber security" titles, could have very different content.
Open, Online and "Free" Courses
In addition to programs and courses offered directly, Australian universities offer education on cyber security though Open Universities Australia. These include Macquarie University Bachelor of Security Studies, and the Australian Computer Society formation Security Course.Charles Stury University (CSU) offer a free Network Security Administrator Certification short course to help prepare for certification as an EC-Council Network Security Administrator (ENSA)
At the introductory level the Open University run a MOOC on "Introduction to Cyber Security". Also there is a more traditional on-line course "An introduction to information security".
ps: Having a background in defence, my teaching occasionally touches on cyber security. Last semester I was teaching IT ethics using a hypothetical about Cyberwarfare Over the South China Sea.
Friday, February 26, 2016
Training Police On-line
Helen M Lynch will speak on the "Distributed Content Environment" developed for the CSU School of Policing Studies, at the Australian Computer Society e-Learning Special Interest Group in Canberra, 5pm 11 May 2916.
"The distributed content environment (DCE) is a system developed and implemented for the School of Policing Studies, CSU, to customise, reuse, update and deliver teaching and learning resources in mobile ready formats to students, teachers and classroom. The DCE has wide application as it enables a truly “digital“ classroom and supports the use of mobile devices by teachers and students in and outside of the classroom. DCE enables the distribution of teaching and learning resources by harnessing a range of educational technologies that are common to most universities and TAFE institutions in Australia today.
The core technologies of the DCE are the digital object repositories and the online learning environment e.g. Moodle and Equella, as well as content authoring tools which when harnessed together create a seamless distribution of teaching and learning resources to a range of audiences.This session explains the DCE and how it can be applied to a range of teaching and learning situations."
Friday, January 24, 2014
Free Online Short Courses to Prepare for Certification
Charles Sturt University (CSU) are offering a Free Short Course: Network Security Administrator Certification. This is run on-line over 5 weeks, with live webinars (and optional recordings) and students expected to do 10-12
hours of study. Several aspects make this different to Massive open Online Courses (MOOCs) being offered by other institutions. Fist of all there is a live component to the course, not just recordings. Also the course is intended to prepare the student for an external certification (ENSA). It is also significant that this is described as a "short course" with no mention of "MOOC", or the hype surrounding them. As I said at the Inaugural
Student Experience Conference, in Sydney, I expect to see the MOOC Bubble burst, with
most MOOCs abandoned by the end of 2014.
CSU point out that the short course is based on their Master of Information Systems Security. Clearly the short free course is being used to promote the full for-fee degree program. This would appear to be a viable business model for free courses. A student who completes the short course would be predisposed to enrolling in the degree program.
However, students who undertake the free course to prepare for external certification may not realise the large commitment of time and effort required. Last year I completed two certificates in education, one through regular courses (partly in the classroom and partly on-line) and one by Recognition of Prior Learning (RPL). In theory the RPL should have been easier, as it just required me to collate and present evidence of what I had done previously. But this turned out to be harder than going through a structured course, where you get guidance on what to do and where there are many small milestones on the way to completion.
However, students who undertake the free course to prepare for external certification may not realise the large commitment of time and effort required. Last year I completed two certificates in education, one through regular courses (partly in the classroom and partly on-line) and one by Recognition of Prior Learning (RPL). In theory the RPL should have been easier, as it just required me to collate and present evidence of what I had done previously. But this turned out to be harder than going through a structured course, where you get guidance on what to do and where there are many small milestones on the way to completion.
Also, using a free short course to promote longer for-fee programs might backfire on some universities, presenting a false impression of their programs. Some MOOCs appear to be provided by universities which don' generally offer on-line courses (not the case with CSU who are a leader in on-line education). Also the MOOCs are at a far lower academic standard than regular courses. It will not do a university much good to attract students with one type of course at one level, sign up and pay for a degree program, only to find it is not offered on-line and is far harder.
Friday, November 8, 2013
Formulating National Security in Cyberspace
Greetings from the Australian National University in Canberra, where an international research project on "Political Strategic Ecology in Cyberspace" is being launched. This research uses techniques of complex systems and natural ecology. The researchers are asking for input from the community and will reach out via blogs and other on-line forms.
Professor Paul Cornish from University of Exeter UK, argued that cyberspace should be treated as a strategic space. Professor Roger Bradbury, National Security College at ANU expressed concern about the Internet being balkanized with countries such s China separating their national systems from the global network.
One of the audience members commented that the Internet was built by engineers and and that might cause an impediment to security. I found this discussion of balkanization and engineers acting without reference to the public interest troubling. The term "internet" refers to a "Network of Networks", with "The Internet" as the global example of this. Those designing the Internet did not so in isolation from issues of governance, that was key to the system.
I suggest researchers need to first look at how the Internet was created and is now governed. Professor Fred Cate , Director of the Center for Applied Cybersecurity Research at Indiana University, pointed out that most of the Internet is run by non-government organizations. He argued that the law and governance was lagging actual use of the Internet. However, this is not my experience.
When advocating the use of the Internet in Australia in the 1990s, myself and others considered the governance and legal implications. In my day job I had to devise policies for the use of the Internet and the world Wide web by the Department of Defence. This turned out to be relativity easy, identifying existing polices, laws and guidelines and interpreting these where necessary. The general assumption which many people in government and academia made, that public utilities are administered primarily by government turned out not to be true. In practice, most public services are provided by non-government entities following guidelines and standards written by non-government bodies. This approach-was extended to the Internet and proved resilient.
Governments and researchers who want to impose top-down government control of the Internet in order to protect democracy are missing the point.
One student in the audience asked an interesting question about cyber-war, outer-space and conventional warfare in developing nations. One of the panel responded that cyber-war would be an adjunct to use of conventional forces and may make conflicts harder to mange.
I asked the panel how we could get the results of their research to policy makers and practitioners quickly. In the 1990s we used the ANU fellow bar as a forum for formulating public policy, but perhaps something more systematic is needed.
Professor Paul Cornish from University of Exeter UK, argued that cyberspace should be treated as a strategic space. Professor Roger Bradbury, National Security College at ANU expressed concern about the Internet being balkanized with countries such s China separating their national systems from the global network.
One of the audience members commented that the Internet was built by engineers and and that might cause an impediment to security. I found this discussion of balkanization and engineers acting without reference to the public interest troubling. The term "internet" refers to a "Network of Networks", with "The Internet" as the global example of this. Those designing the Internet did not so in isolation from issues of governance, that was key to the system.
I suggest researchers need to first look at how the Internet was created and is now governed. Professor Fred Cate , Director of the Center for Applied Cybersecurity Research at Indiana University, pointed out that most of the Internet is run by non-government organizations. He argued that the law and governance was lagging actual use of the Internet. However, this is not my experience.
When advocating the use of the Internet in Australia in the 1990s, myself and others considered the governance and legal implications. In my day job I had to devise policies for the use of the Internet and the world Wide web by the Department of Defence. This turned out to be relativity easy, identifying existing polices, laws and guidelines and interpreting these where necessary. The general assumption which many people in government and academia made, that public utilities are administered primarily by government turned out not to be true. In practice, most public services are provided by non-government entities following guidelines and standards written by non-government bodies. This approach-was extended to the Internet and proved resilient.
Governments and researchers who want to impose top-down government control of the Internet in order to protect democracy are missing the point.
One student in the audience asked an interesting question about cyber-war, outer-space and conventional warfare in developing nations. One of the panel responded that cyber-war would be an adjunct to use of conventional forces and may make conflicts harder to mange.
I asked the panel how we could get the results of their research to policy makers and practitioners quickly. In the 1990s we used the ANU fellow bar as a forum for formulating public policy, but perhaps something more systematic is needed.
Strategy and Statecraft in Cyberspace
Join us for a panel discussion and open forum to explore the complexities of cyberspace from a national security perspective – a domain in which states and non-state actors interact with each other in an increasingly contested environment.
This event has been organized by the ANU National Security College (NSC) as it finalises priorities for its new research program on Strategy and Statecraft in Cyberspace. The NSC has brought together leading researchers from Australia, the United States and the United Kingdom for this event which will be facilitated by the ABC’s Michael Brissenden:
Like the traditional domains of land, sea, air and space, states and non-state actors are using the cyberspace domain to pursue their objectives in an increasingly complex world. The panel will discuss the rise of cyberspace, which has created a number of ‘wicked’ policy problems for global security including:
- Professor Roger Bradbury is a complex systems scientist with experience in international cyber issues, and is with the National Security College at ANU.
Professor Fred Cate specialises in information privacy and security law issues, and is Director of the Center for Applied Cybersecurity Research at Indiana University, USA.
Professor Paul Cornish is an expert in cyber security and cyber war, and Professor of Strategic Studies at the Strategy and Security Institute at the University of Exeter, UK.
- Dr Jon Lindsay is an expert in international relations at the University of California Institute on Global Conflict and Cooperation at UC San Diego, USA.
the proliferation of cyber weapons to state and non-state actors the systemic vulnerabilities in the infrastructure of globalisation and military power the friction between private sector actors who manage the Internet and the public sector actors who are supposed to defend them the mismatch between the pace of policy formation and the pace of technological change the failure to coordinate among government agencies responsible for national security, law enforcement and industrial policy major disagreements about how the Internet should be managed domestically and internationally.
Some authors foresee grave new risks of a ‘digital Pearl Harbor’, while their critics dismiss these warnings as inflating the threat. Technological complexity has amplified political complexity, which in turn has complicated political analysis. Our panel will endeavor to unpick these issues from the perspectives of social policy, security policy and the future of technology. We look forward to welcoming you at this important event focusing on an issue of critical significance.
Subscribe to:
Posts (Atom)




