Australia · Attorney-General's Department · PSPF

Protective Security Policy Framework

The framework that sets how Commonwealth entities protect people, information and assets from trusted-insider and external threats.

What it is

The PSPF is the Australian Government's policy framework for protective security. It sets out the government's expectations for managing security risks across four outcomes: governance, information, personnel and physical security. For cybersecurity, the PSPF requires non-corporate Commonwealth entities to apply the ACSC's ISM controls and the Essential Eight. Each entity's Accountable Authority is responsible for attesting annual compliance.

Who it applies to

Mandatory for non-corporate Commonwealth entities. Corporate Commonwealth entities and state/territory agencies apply the PSPF as good-practice guidance.

Requirements

Security governance

Establish accountabilities, reporting and a risk-managed approach to protective security.

Information security

Classify, protect and share official information in line with its sensitivity and business impact.

Personnel security

Vet personnel, manage insider risk, and maintain ongoing suitability for access to classified resources.

Physical security

Protect people, information and physical assets in line with business impact levels and threat.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.