Australia
Australian government: Procurement fails to vet vendor product security | The Canberra Times

The view of the Australian Information Security Association, Australia’s cyber peak, is that a few things are required to get practical and well-managed delivery right: accountable risk owners for services throughout their lifecycle, built-in security in the early stages of discovery and design, supplier due diligence that goes beyond compliance checklists, and shared responsibility for product security written into contracts rather than rejected.



