Australia · Australian Signals Directorate (ASD) · IRAP

Information Security Registered Assessors Program

The ASD-endorsed program that certifies cybersecurity professionals to assess ICT systems against the ISM.

What it is

IRAP is the ASD program that trains and authorises cybersecurity professionals to conduct independent security assessments of ICT systems against the ISM. Assessments are a prerequisite for systems that process Australian Government information at OFFICIAL: Sensitive or higher, and they are commonly used by cloud providers and SaaS vendors seeking to host Commonwealth workloads. An IRAP assessment produces a Security Assessment Report; the Authorising Officer then accepts residual risk through an Authority to Operate.

Who it applies to

Any cloud service or system proposed for use by a Commonwealth entity at OFFICIAL: Sensitive or PROTECTED. Often adopted by state and territory governments, critical-infrastructure operators and defence suppliers.

Requirements

Scope definition

Define the system boundary, data flows and classification before assessment begins.

Stage 1 assessment

Design-stage review of whether the proposed controls adequately protect the classified data.

Stage 2 assessment

Operational review of implemented controls - evidence, testing and residual risk identification.

Security assessment report

Formal report for the system owner and Authorising Officer, aligned to ISM controls.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.