This parliamentary question scrutinises a Department of Transport and Major Infrastructure (DTMI) contract for Atlassian Cloud Migration Services, focusing heavily on cybersecurity risks, vendor due diligence, data residency, and the procurement process.

⏳ Awaiting AnswerQoN 2981Legislative Assembly
Asked
11 August 2026
Portfolio
Transport and Major Infrastructure

QuestionView source ↗

I refer to Department of Transport and Major Infrastructure (DTMI) contract DTMI404126 regarding Atlassian Cloud Migration Services and I ask
:
(a) Why did a contract for migration of Department of Transport and Major Infrastructure Atlassian applications receive only one submission;
(b) Did the Department conduct a formal cyber security risk assessment before deciding to migrate Jira and Confluence to Atlassian Cloud
;
(c) What was the risk rating assigned to the migration before treatment, and what is the residual risk rating after controls and was the risk assessment provided to the Director General, the Minister, the Government Chief Information Officer, or the WA Cyber Security Unit;
(d) Did the Department assess Atlassian’s recent and historical critical vulnerabilities before selecting Atlassian Cloud as the target platform;
(e) Is the Department aware that Atlassian’s June 2026 bulletin reported 76 high-severity vulnerabilities and 24 critical-severity third-party vulnerabilities;
(f) What assurance has the Department obtained that none of the vulnerabilities disclosed by Atlassian in 2025 or 2026 affect the Department’s environment, migration pathway or plugins;
(g) Has the Department obtained written assurance from Atlassian or Interfuze that the Department’s Jira, Confluence and plugin environment is not exposed to known critical or high-severity vulnerabilities;
(h) Will the Minister table the cyber risk assessment, vendor due diligence assessment and security architecture review for this migration? If the documents cannot be tabled, will the Minister provide their dates, authors, approving officers and risk ratings;
(i) Were all plugins assessed for authentication, authorisation, data access and supply-chain risk before migration;
(j) How many plugins will be removed before migration due to security, compatibility or data-governance risks;
(k) What categories of Department data are stored in Jira and Confluence;
(l) Which Atlassian Cloud region will be used;
(m) Has the Department received legal advice on offshore disclosure, privacy, State Records Act obligations and contractual control of government information;
(n) Will the Minister guarantee that no Department of Transport and Major Infrastructure data will be accessible from offshore support locations without explicit approval; and
(o) Before this contract was signed, did the Director General sign off on a cyber risk assessment, a plugin-by-plugin security review, and an Australian data residency guarantee, if not why not?
Answered on

AnswerView source ↗

This question is awaiting a response from the Minister.

Explore WA Government Data

Search the full archive in the free dashboard, or query programmatically via API.

Explore more