Software engineering teams at banks and telecommunication companies in Australia may soon be required to meet secure-by-design principles for software, similar to those imposed on software vendors to governments. The Quad nations, including Australia, the United States, Japan, and India, published joint principles for secure software after a meeting in Hiroshima during the G7 summit.
The principles entail that software vendors selling to governments must ensure compliance with secure software development practices and participate in a “national vulnerability disclosure program.” Governments, on their part, need to manage risks by implementing adequate controls and committing to prompt incident response.
Mike Pezzullo, Secretary of the Home Affairs department, mentioned during senate estimates that these guidelines should prompt software and service providers to the federal government to reevaluate their practices. He highlighted that the principles agreed upon by the Quad partners would likely be extended beyond software supply and applied to other sectors such as banks and telecommunication companies.
Pezzullo suggested that if the government does not tolerate high-risk software in the products and services procured, vendors need to improve their practices accordingly. The discussion also touched on the possibility of extending government suspensions and bans on Chinese-made hardware and software beyond government entities, potentially impacting critical infrastructure operators or those responsible for systems of national significance (SoNS).


