// secureos · govern

ISM & IRAP Documentation Services

Handling government data? We prepare the documentation that ISM alignment and an IRAP assessment require — system security plans, risk management, and the evidence assessors look for.

ISM  /  IRAP-aligned  /  SSP & SRMP

// does this apply to you

Does the ISM apply to my business?

The ISM is not law. ASD states an organisation is not required to comply unless legislation, or a direction given under legislation or other lawful authority, compels it. For industry the obligation almost always arrives through a contract — a government, Defence or prime contractor agreement that names the ISM or asks for an IRAP assessment.

Who is asking you to meet the ISM?

What people get wrong

  • Saying ‘IRAP certified’. There is no such thing. ASD states an IRAP assessor will not accredit, certify, endorse or register a system on its behalf — and that publishing such claims misrepresents the program and will result in ASD asking for the statement to be removed. It still appears in tender responses regularly.
  • Thinking the assessment is the approval. An IRAP assessment informs a risk-based authority-to-operate decision. The authorising officer accepts the residual risk — not the assessor. Buying an assessment does not buy an approval.
  • Treating the ISM as a checklist. It is a risk framework: define the system, select controls, implement, assess, authorise, monitor. ASD says the controls should not be treated as an exhaustive list for any given system.
  • Assuming it applies because you are in the sector. The ISM binds Commonwealth entities through policy. It binds you through a contract — so the contract, not the sector, is where the answer is.
// what it is

The documentation government assessment demands

The Information Security Manual (ISM) sets the security requirements for systems handling Australian Government information, and the Infosec Registered Assessors Program (IRAP) is how those systems are independently assessed. Both are documentation-heavy. We prepare the security artefacts — mapped to ISM controls — so an IRAP assessment goes smoothly.

// what we deliver

What we prepare

Scope & data classification

Define the system boundary and classify the data it handles.

ISM control mapping

Map the applicable ISM controls to your system and identify gaps.

System Security Plan (SSP)

Document how your system meets the required controls.

Security Risk Management Plan

Document risks, treatments and residual risk for assessment.

IRAP assessment preparation

Assemble the evidence and artefacts an IRAP assessor will review.

// faq

Frequently asked questions

What is the ISM?

The Information Security Manual — the ASD’s framework of controls for systems handling Australian Government information.
The Infosec Registered Assessors Program — independent assessment of a system’s security against the ISM.
We prepare you for it — documentation, control mapping and evidence — and work alongside the IRAP assessor.
Essential Eight is part of the ISM’s controls; ISM/IRAP is broader and applies to government data handling.
// next step

Get ready for ISM and IRAP.

Book a call and we’ll scope the documentation your system needs to face an IRAP assessment with confidence.