Australian Government ISM and IRAP Advisory 

Organisations that wish to do business with the Australian Federal Government typically undergo an assessment against the ISM conducted by an ASD-endorsed Infosec Registered Assessors Program (IRAP) assessor. The assessment process is complex and time-consuming, but the benefits from a sales perspective are many. By completing the assessment, companies can attest to the appropriateness and effectiveness of the system’s security controls and their implementation status so that agencies can determine if the risk of using the system to process their data is at an acceptable level. Companies that have undergone an IRAP assessment demonstrate to their clients that they take cybersecurity seriously and have taken proactive steps to meet ISM requirements, as the Australian government requires. This helps win new business and provides a valuable boost to their reputation.

There are currently only a limited number of assessors in Australia. This can make it difficult to find someone to assess your security controls. Lucky for you, 38North partners with several IRAP assessors with a long history of helping companies meet Australia’s security requirements. Collaboratively, we can help ensure that you document your control implementation clearly for agency customers . Trust Us to Get You There.

38North logo

38North and Independent IRAP Assessors

38North is recognized as an expert cybersecurity organisation. Partnering with in-country IRAP assessors, we prepare organisations to tackle the IRAP assessment process— working side-by-side with them throughout the full process.

A little or a lot, we can provide guidance — or help with documentation development, gap analyses, and security engineering — to help you meet ISM requirements.

The IRAP Assessment Process

The Australian IRAP assessment process is deceptively long and complex, with updates to the Information Security Manual (ISM) being published by the Australian Cyber Security Centre (ACSC) on a quarterly basis. The applicant and the assessor determine the size and scope of the assessment, meaning there can be a great deal of variability. Fortunately, 38North is an established cloud security compliance advisory firm — providing expert guidance and support — to help you define your boundary and ensure that your implementation is clear when undergoing an IRAP assessment. No matter where you are in your IRAP assessment process, 38North can make it easier. ‌Talk with one of our IRAP experts.

IRAP Assessment Challenges

Undergoing an IRAP assessment can be a challenging process due to the complexity and rigor of the security requirements, as well as the quarterly updates to the ISM. Overall, these challenges can cause delays and increased costs in pursuing Australian Federal customers and contracts.

38North IRAP Services

38North can help you demonstrate how you meet ISM requirements, no matter where you are in the process.

Boundary Scoping

We start by helping you understand what data you have that must be protected . This lets us know what assets are in scope, and excludes those that aren’t.

Workshops

Our workshops get you started — with control requirement training and consulting. We also help by using Australian Federal Government practices to design systems and approaches that will withstand IRAP assessments.

ISM Requirements Gap Analysis

Gap analyses help cloud providers and contractors meet ISM requirements. Our gap analysis will find your gaps against the requirements and deliver a prioritized roadmap of actions required to close gaps against the ISM.

ISM Advisory Support

38North’s senior security advisors can help you design, deploy, document and maintain a scalable security approach that meets your target ISM baseline.

What do I need for my IRAP assessment?

The IRAP assessor will request documentation and artifacts that show the appropriateness and effectiveness of the system’s security controls. This includes policies, procedures, and samplings of artifacts to show procedures are being followed in a consistent and repeatable manner. 38North advisors can work with your teams and help with developing this documentation, in preparation for assessment.

Typically, you should be prepared to present the following documentation, as a baseline:

  • System Security Plan (SSP) – including all guidelines 
  • Audit and Accountability Policy (AAP) 
  • Configuration Management Plan (CMP) 
  • Cryptographic Key Management Plan (CKM) 
  • Incident Response Plan (IRP) 
  • Media Management Policy (MMP)  
  • Security Risk Management Plan (SRMP) 
  • Vulnerability and Patch Management Plan (VPM) 
  • User Access Management (UAM) Plan 

What do I need for my IRAP authorisation package?

The system owner will compile an Authorisation Package to submit to the authorising authority. In addition to the Security Assessment Report, it should contain:

  • System Security Plan (SSP)  
  • Policies and Plans 
  • Continuous Monitoring Plan (CMP) 
  • Plan Of Action And Milestones (POA&M)
Two people shaking hands at a meeting with package and cloud icon overlay

Your IRAP Assessment Starts Here

Book an initial IRAP conversation with one of our Australian cloud security experts today and we’ll help you prepare for your IRAP assessment — and stronger security.

Contact Us

This field is for validation purposes and should be left unchanged.
Name(Required)
(Please do not provide additional PII in this box)