Security governance
Establish accountabilities, reporting and a risk-managed approach to protective security.
The framework that sets how Commonwealth entities protect people, information and assets from trusted-insider and external threats.
The PSPF is the Australian Government's policy framework for protective security. It sets out the government's expectations for managing security risks across four outcomes: governance, information, personnel and physical security. For cybersecurity, the PSPF requires non-corporate Commonwealth entities to apply the ACSC's ISM controls and the Essential Eight. Each entity's Accountable Authority is responsible for attesting annual compliance.
Mandatory for non-corporate Commonwealth entities. Corporate Commonwealth entities and state/territory agencies apply the PSPF as good-practice guidance.
Establish accountabilities, reporting and a risk-managed approach to protective security.
Classify, protect and share official information in line with its sensitivity and business impact.
Vet personnel, manage insider risk, and maintain ongoing suitability for access to classified resources.
Protect people, information and physical assets in line with business impact levels and threat.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.