Scope definition
Define the system boundary, data flows and classification before assessment begins.
The ASD-endorsed program that certifies cybersecurity professionals to assess ICT systems against the ISM.
IRAP is the ASD program that trains and authorises cybersecurity professionals to conduct independent security assessments of ICT systems against the ISM. Assessments are a prerequisite for systems that process Australian Government information at OFFICIAL: Sensitive or higher, and they are commonly used by cloud providers and SaaS vendors seeking to host Commonwealth workloads. An IRAP assessment produces a Security Assessment Report; the Authorising Officer then accepts residual risk through an Authority to Operate.
Any cloud service or system proposed for use by a Commonwealth entity at OFFICIAL: Sensitive or PROTECTED. Often adopted by state and territory governments, critical-infrastructure operators and defence suppliers.
Define the system boundary, data flows and classification before assessment begins.
Design-stage review of whether the proposed controls adequately protect the classified data.
Operational review of implemented controls - evidence, testing and residual risk identification.
Formal report for the system owner and Authorising Officer, aligned to ISM controls.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.