Australian Government ISM and IRAP Advisory
Organisations that wish to do business with the Australian Federal Government typically undergo an assessment against the ISM conducted by an ASD-endorsed Infosec Registered Assessors Program (IRAP) assessor. The assessment process is complex and time-consuming, but the benefits from a sales perspective are many. By completing the assessment, companies can attest to the appropriateness and effectiveness of the system’s security controls and their implementation status so that agencies can determine if the risk of using the system to process their data is at an acceptable level. Companies that have undergone an IRAP assessment demonstrate to their clients that they take cybersecurity seriously and have taken proactive steps to meet ISM requirements, as the Australian government requires. This helps win new business and provides a valuable boost to their reputation.
There are currently only a limited number of assessors in Australia. This can make it difficult to find someone to assess your security controls. Lucky for you, 38North partners with several IRAP assessors with a long history of helping companies meet Australia’s security requirements. Collaboratively, we can help ensure that you document your control implementation clearly for agency customers . Trust Us to Get You There.





