This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Australian Government Authentication Framework | |
|---|---|
| Name | Australian Government Authentication Framework |
| Abbreviation | AGAF |
| Established | 2010s |
| Jurisdiction | Australia |
| Related | Digital identity, GovPass, myGov |
Australian Government Authentication Framework
The Australian Government Authentication Framework is a policy and technical suite that defines standards for online authentication used across Australian Public Service agencies including Services Australia, Australian Taxation Office, and state governments such as New South Wales Government and Victorian Government. It aligns with broader identity initiatives like myGovID and international instruments such as the eIDAS Regulation and the NIST Digital Identity Guidelines, shaping how citizens and businesses access digital services provided by organizations such as Centrelink, Medicare, and Australian Electoral Commission.
The framework establishes mandatory authentication levels, technical controls, and risk-based approaches influenced by standards including ISO/IEC 27001, ISO/IEC 29115, and the Common Criteria. It interacts with identity systems like GovPass and cross-jurisdictional programs such as Council of Australian Governments digital agendas, and is referenced in policy documents from Australian Cyber Security Centre and Attorney-General's Department.
The objective is to ensure secure, interoperable access to digital services for stakeholders including individuals, businesses, and non-profit organizations while supporting transactions involving Australian Securities and Investments Commission filings, Australian Prudential Regulation Authority reporting, and welfare interactions with Department of Social Services. Scope covers authentication assurance levels, token management, multi-factor authentication mandated for services like myGov, directives from Digital Transformation Agency, and cross-border recognition consistent with frameworks such as OECD digital government principles.
Principles emphasize risk-based assurance, usability, privacy-by-design, and federation modeled after international examples like Gov.UK Verify and Estonian e-Identity. Standards referenced include SAML 2.0, OpenID Connect, OAuth 2.0, and cryptographic baselines compatible with recommendations from Australian Signals Directorate and NIST. Compliance expectations draw upon statutes such as the Privacy Act 1988 (Cth) and guidance from bodies like Office of the Australian Information Commissioner.
Architecture commonly employs federated identity patterns connecting identity providers, relying parties, and attribute services across platforms like myGovID and agency identity brokers. Components include authentication factors (possession, knowledge, inherence) implemented via hardware tokens, software authenticators, biometrics tied to services like Medicare access, and public key infrastructure aligned with Australian Government Authentication Framework principles. Protocol stacks utilize TLS for transport, X.509 certificates for device identity, and directory services interoperable with Australian Signals Directorate guidance.
Identity proofing procedures require verification of documents issued by authorities such as Australian Passport Office, Births, Deaths and Marriages Registry, and state motor vehicle agencies including Transport for NSW. Processes employ document verification, face comparison and credential checks against authoritative data holdings like Document Verification Service and Consumer Data Right registers where applicable, with enhanced checks for high-assurance transactions such as Australian Business Register enrolment.
Governance is coordinated by bodies including the Digital Transformation Agency and oversight by the Australian National Audit Office and Inspector-General of Intelligence and Security for security aspects. Compliance frameworks reference the Protective Security Policy Framework and auditing practices from Australian National Audit Office. Privacy obligations reflect the Privacy Act 1988 (Cth) and guidance from the Office of the Australian Information Commissioner, balancing data minimization and lawful disclosure in interactions with entities like Australian Federal Police when required.
Adoption has progressed through programs led by Digital Transformation Agency, pilot projects with state agencies such as Queensland Government and Western Australia Government, and integration into service platforms including Services Australia and Australian Taxation Office online services. Industry participants like major banks (Commonwealth Bank, Westpac) and identity providers collaborate to enable federated credentials, while standards bodies such as Standards Australia contribute to interoperability testing.
Incidents and reviews involving authentication implementations have prompted updates influenced by incidents examined by Australian Cyber Security Centre and audits from the Australian National Audit Office. International incidents in programs like Gov.UK Verify and technical advances in biometrics and cryptography have driven iterative changes, with future evolution shaped by initiatives from OECD, standards like ISO/IEC 29115, and policy shifts led by the Attorney-General's Department and Digital Transformation Agency.