COI Report – Part III
Page
72 of
425 15.1 Network connections between the SGH Citrix servers and the SCM database were allowed 211. At the time of the Cyber Attack, network connections between SGH Citrix server farm to the SCM database server at HDC were allowed (this network connectivity has been referred to in the proceedings as the open network connection. The network connection was a critical
pathway to the SCM database, over which the attacker was able to make SQL queries to and retrieve data from the SCM database. The Committee accepts the Solicitor-General’s submission that but for this open network connection, the SCM database was adequately protected within the H-Cloud perimeter defences, and the attacker would not have been able to access the SCM database as easily.
212. These facts raise the issue of why the network connection was maintained. The Committee has heard evidence that during migration of the SCM system to the H-Cloud in June 2017, network connectivity between the SGH Citrix servers to the SCM database was required. After the migration in June 2017, the SCM infrastructure
at SGH was decommissioned, but the network connection remained. This was because the SGH Citrix servers were used to host (i) administrative tools used for administering and managing SQL databases, including the SCM database in H-Cloud, and (ii) custom applications used by staff to query and retrieve data from the SCM database. These administrative tools and custom applications made use of the open network connection to perform their functions.
213. The administrative tools were hosted on the SGH Citrix servers as a matter of operational efficiency and not necessity. These tools were not used solely
to administer the SCM database, but were also used to administer other SQL databases servers that were hosted in SGH and not H-Cloud. By hosting the tools on the SGH Citrix servers and maintaining network connectivity with the SCM database, the same set of tools could be used by administrators across all relevant SQL databases. Lum has clarified that this was not strictly necessary, as separate sets of tools could have been hosted on the H-Cloud Citrix servers (to
service the SCM database, and on the SGH Citrix servers (to service the other SGH