The Australian Cyber Security Centre announced new mandatory security controls in the Information Security Manual to enhance software protection during its development and deployment phases. All public sector agencies can apply the framework, which encompasses traditional, mobile, web, and artificial intelligence applications. In March and June 2025, the revisions directly address the escalating threats from cyber supply chain vulnerabilities, harmful code, and unsafe data handling practices.
Agencies must obtain authoritative sources for software, maintain separation between development and production environments, conduct vulnerability scans on third-party components, and adhere to secure-by-design principles under the newly implemented measures. These controls enhance privacy, uphold data governance, and guarantee robust protections for data collection, sharing, collaboration, cloud storage, and the use of emerging technologies. Australia’s recent updates play a crucial role in enhancing cybersecurity and advancing digital government initiatives. They focus on embedding resilience throughout the software development lifecycle and safeguarding the integrity of public sector digital services.
The Australian Cyber Security Centre highlights the critical need for “protecting the authoritative source for software is critical to preventing malicious code being surreptitiously introduced into software.”
Agencies must create a reliable source for software, enforce access controls, document all changes, and thoroughly examine all artefacts—including third-party libraries—for any malicious codes or vulnerabilities before use. Organisations must now implement software bills of materials (SBOMs) and establish build provenance records. This initiative enhances transparency about software components and enables agencies to confirm the integrity of builds.
They now integrate the Principles of Secure by Design as a mandatory requirement. Make sure to thoroughly document all security requirements, perform threat modelling at every stage of the lifecycle, and implement memory-safe programming practices whenever possible. Implement digital signatures, event logging, and end-of-life procedures for software releases to enhance long-term resilience.
Regulators have imposed stricter rules on software that interacts with databases and APIs. Safeguard against injection attacks by employing parameterisation in SQL queries, and ensure that all queries are logged centrally. Network APIs must enforce rigors authentication and authorisation measures, along with centralised logging, to safeguard against unauthorised alterations to or disclosures of sensitive information.
Check out: “Australia’s privacy act unveils Compliance Essentials”
The policy requires ongoing security testing, including static, dynamic, and composition analysis, as well as peer reviews for essential components. ASC promotes responsible reporting practices through mandatory vulnerability disclosure programmes. Address vulnerabilities promptly and make them known, including details aligned with Common Weakness Enumeration. This update strengthens the commitment to software security while aligning with national goals for cybersecurity and digital governance.
The ACSC guidelines apply to artificial intelligence systems, mobile applications, cloud storage, and web applications. The statement raises concerns about the potential dangers of misusing artificial intelligence, the challenges of insecure data collection, the issues from fragmented data silos, and the shortcomings in data sharing practices. The framework requires strong data governance and privacy measures by mandating the validation of all inputs, logging access meticulously, and safeguarding sensitive data during collection, collaboration, and exchange processes.
Australia integrates these principles into its software security controls, ensuring that public sector AI and digital services operate on a secure, verifiable, and privacy-protected data infrastructure. The government takes decisive action to mitigate risks posed by malicious actors who exploit vulnerabilities in software supply chains, insecure APIs, and poorly governed data. The recent modifications boost public confidence in digital governance and empower agencies to safely use cutting-edge technologies like artificial intelligence, cloud storage, and advanced data collaboration.
As the ACSC states, “Software developers need to ensure that they are using a secure authoritative source for software as part of their development environment, as doing so can reduce the security risks related to unauthorised access to source code, source code tampering and other possible cyber supply chain attacks on software artefacts.”
A robust new framework for software security signals a significant shift in how Australia safeguards its digital government and public sector data. By using secure design principles, software bills of materials, tracking the origin of builds, regular vulnerability testing, and strict rules for data collection, sharing, and storage, agencies get clear and practical ways to reduce risks from harmful code, unsafe APIs, and weaknesses in the software supply chain.
Recent modifications boost leaders’ confidence in the reliability of software systems and promote privacy along with strong data governance practices. Reliable sources for software and complete lifecycle protections help public services use artificial intelligence, cloud storage, and data collaboration technologies safely. The framework empowers the public sector to confront emerging cybersecurity challenges, boosting resilience and transparency across digital infrastructure.
Justin Lavadia is a content producer and editor at Public Spectrum with a diverse writing background spanning various niches and formats. With a wealth of experience, he brings clarity and concise communication to digital content. His expertise lies in crafting engaging content and delivering impactful narratives that resonate with readers.
- Justin Lance Marcel Lavadia
- Justin Lance Marcel Lavadia
- Justin Lance Marcel Lavadia
- Justin Lance Marcel Lavadia
