Home > Monitoring Compliance >  Law Enforcement Data ...

Law Enforcement Data Systems Acquisition And Development

Law Enforcement Data Systems Acquisition And Development

November 2008

 

The purpose of the Law Enforcement Data Systems Acquisition and Development Standards is to ensure security is appropriately managed during the acquisition and development of applications and databases. Standard 25 requires appropriate security controls to be built into law enforcement data systems. Standard 26 requires that Victoria Police implement procedures to ensure security during the development and maintenance of law enforcement data systems.

Victoria Police was found to be partially compliant with Standard 25 and non-compliant with Standard 26.

Victoria Police currently has suitable policy and supporting documents, but implementation is inconsistent. As a result the overall security posture and severity of data exposure is unknown. There are also distinct policy weaknesses for the implementation of security during the software development and maintenance process and for third-party systems that interface with Victoria Police systems.

Victoria Police has agreed to implement all the recommendations of the review.


 
Top of page