Mawson Software Pty Ltd Mawson Software (MS) is a development house for various organisations including government (State and Commonwealth) and the Department of Defence (DoD). The DoD is the primary customer and it needs to share information with MS that is classified up to PROTECTED when performing acceptance and functional testing. MS employs 120 staff. 60 staff have baseline clearances and work mostly on the DoD projects. MS has a small ICT team of 8, all except the 2x Help Desk staff are Domain Administrators. Most staff use desktop computers with wireless keyboards/mice although some designers have Apple MacBook Pro devices. MS also has a roving sales team of 4 who use their laptops, iPads to connect back to MS and the Cloud based CRM tool. Most staff members have access to MS email on their personal or corporate mobile phones. MS has a single Internet gateway with a DMZ that is protected by a router with VLANs and Access Control Lists (ACL). Internet usage is fairly relaxed, and staff are expected to moderate their usage. Logging is kept on the individual devices. MS has a single Wi-Fi network, protected by a pre-shared key, that it allows staff and guests to connect to. Email is cloud based using Office365 and there is also a corporate DropBox account used to share files with customers. The office space is open plan once you go beyond reception although the server room is beyond a door with card access to ICT staff only. Helpful Links PSPF Physical Security: https://www.protectivesecurity.gov.au/physical/entity- facilities/Pages/default.aspx PSPF Information Classification: https://www.protectivesecurity.gov.au/information/sensitive-classified- information/Pages/default.aspx ACSC ISM: https://www.cyber.gov.au/sites/default/files/2019- 05/Australian%20Government%20Information%20Security%20Manual%20%28MAY19%29. pdf ACSC ISM Aid: https://www.cyber.gov.au/sites/default/files/2019- 05/Australian%20Government%20Information%20Security%20Manual%20- %20Security%20Assessment%20Aid%20XLSX%20%28MAY19%29.xlsx ASD Essential Eight: https://www.cyber.gov.au/node/284