<!--The Official Report of Parliamentary Debates (Hansard) of the Legislative Council and the House of Assembly of the Parliament of South Australia are covered by parliamentary privilege. Republication by others is not afforded the same protection and may result in exposure to legal liability if the material is defamatory. You may copy and make use of excerpts of proceedings where (1) you attribute the Parliament as the source, (2) you assume the risk of liability if the manner of your use is defamatory, (3) you do not use the material for the purpose of advertising, satire or ridicule, or to misrepresent members of Parliament, and (4) your use of the extracts is fair, accurate and not misleading. Copyright in the Official Report of Parliamentary Debates is held by the Attorney-General of South Australia.-->
<hansard id="" tocId="" xml:lang="EN-AU" schemaVersion="1.0" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:xsi="http://www.w3.org/2007/XMLSchema-instance" xmlns:mml="http://www.w3.org/1998/Math/MathML" xsi:noNamespaceSchemaLocation="hansard_1_0.xsd">
  <name>Legislative Council</name>
  <date date="2018-06-06" />
  <sessionName>Fifty-Fourth Parliament, First Session (54-1)</sessionName>
  <parliamentNum>54</parliamentNum>
  <sessionNum>1</sessionNum>
  <parliamentName>Parliament of South Australia</parliamentName>
  <house>Legislative Council</house>
  <venue></venue>
  <reviewStage>published</reviewStage>
  <startPage num="385" />
  <endPage num="431" />
  <dateModified time="2022-08-06T14:30:00+00:00" />
  <proceeding continued="true">
    <name>Answers to Questions</name>
    <subject>
      <name>Online Payment Security</name>
      <page num="431" />
      <text id="20180606d9712e13f7c14ef1a0000648">
        <inserted>
          <heading>Online Payment Security</heading>
        </inserted>
      </text>
      <talker role="member" id="3130" kind="question">
        <name>The Hon. M.C. PARNELL</name>
        <house>Legislative Council</house>
        <questions>
          <question date="2018-06-06">
            <name>Online Payment Security</name>
          </question>
        </questions>
        <text id="20180606d9712e13f7c14ef1a0000649">
          <inserted>In reply to <by role="member" id="3130">the Hon. M.C. PARNELL </by>(6 June 2018).  </inserted>
        </text>
      </talker>
      <talker role="member" id="605" kind="answer">
        <name>The Hon. R.I. LUCAS</name>
        <house>Legislative Council</house>
        <questions>
          <question date="2018-06-06">
            <name>Online Payment Security</name>
          </question>
        </questions>
        <text id="20180606d9712e13f7c14ef1a0000650">
          <inserted>
            <by role="member" id="605">The Hon. R.I. LUCAS (Treasurer):</by>  I have been advised:</inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000651">
          <inserted>Individual government agencies are responsible for ensuring that their ICT infrastructure, systems (including payment related websites) and information are secure. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000652">
          <inserted>The Department of the Premier and Cabinet maintains a number of polices for website security that all government agencies are required to comply with. These policies are consistent with international standards for information security management and include those requirements specified in the Payment Card Industry Data Security Standards for any websites that store, process or transmit payment card data.</inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000653">
          <inserted>As part of these policies agencies are required to conduct regular security testing and undergo an audit before a new website is commissioned. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000654">
          <inserted>I am advised that, based on a high level review undertaken across agencies where Shared Services SA provides an accounts receivable service, none of the associated government websites actually store, process or transmit payment data. In all cases where a customer seeks to make a payment, these websites open a secure interface to the Commonwealth Banks's BPOINT system (which would typically display to a user as HTTPS). </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000655">
          <inserted>BPOINT is owned and managed by the Commonwealth Bank and is the preferred solution under the whole of government banking contract. Proper use of BPOINT ensures that sensitive payment data is being managed within the bank's systems without reliance on the security arrangements applying to the government website. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000656">
          <inserted>Specifically in relation to the SA Pathology, I am advised that the transaction performed by your constituent was indeed secure. This website opened a secure connection into BPOINT, in the same way as described above. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000657">
          <inserted>I understand that based on previous feedback from member of the public, SA Pathology updated their website on 7 May 2018 to use a different technical method for connecting with BPOINT, which now clearly highlights that the user is accessing a secure site. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000658">
          <inserted>In terms of other payment methods offered by government agencies such as, over the phone services or provision of card details via a form, the Payment Card Industry Data Security Standards also apply to the associated processes and systems. In particular there is a clear requirement not to store any sensitive cardholder data on computer systems or in paper form. I am advised that this is typically achieved through fully or partly redacting card numbers from documents after the applicable payment has been processed. </inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000659">
          <inserted>Should there be any further queries regarding specific agency payment websites, I would encourage that these be referred to the responsible minister.</inserted>
        </text>
        <text id="20180606d9712e13f7c14ef1a0000660" />
      </talker>
    </subject>
  </proceeding>
</hansard>