Handling government data? We prepare the documentation that ISM alignment and an IRAP assessment require — system security plans, risk management, and the evidence assessors look for.
ISM / IRAP-aligned / SSP & SRMP
The ISM is not law. ASD states an organisation is not required to comply unless legislation, or a direction given under legislation or other lawful authority, compels it. For industry the obligation almost always arrives through a contract — a government, Defence or prime contractor agreement that names the ISM or asks for an IRAP assessment.
Who is asking you to meet the ISM?
What is the highest classification of information involved?
Has anyone asked for an IRAP assessment?
Yes — and what you need is an assessment, not a certification.
An IRAP assessor does not certify, accredit or authorise anything. The assessment informs an authorising officer, who decides whether the residual risk sits inside their risk appetite. Budget for the decision, not just the assessment.
ASD is explicit: claiming to be ‘IRAP certified’ misrepresents the program, and ASD will ask for the statement to be withdrawn.
Yes — and the classification sets how far it reaches.
At PROTECTED and above, the ISM applies in depth and the controls are not negotiable down. The classification of the information, not the size of your business, decides the bar.
Probably not — the ISM reaches industry through contracts.
Without a government or prime contract naming it, the ISM is guidance you may choose to use, not an obligation you have to meet. Something else is more likely to be binding you right now.
The classification is the question worth answering first.
How far the ISM reaches depends entirely on what classification of information you hold or handle. That is answerable from the contract and the data itself, usually in an afternoon.
Likely — but the contract decides how far.
Government and prime contracts commonly flow ISM obligations down without saying ‘ISM’ anywhere obvious. The clause that binds you is usually in a security annexure nobody has read end to end.
The Information Security Manual (ISM) sets the security requirements for systems handling Australian Government information, and the Infosec Registered Assessors Program (IRAP) is how those systems are independently assessed. Both are documentation-heavy. We prepare the security artefacts — mapped to ISM controls — so an IRAP assessment goes smoothly.
Define the system boundary and classify the data it handles.
Map the applicable ISM controls to your system and identify gaps.
Document how your system meets the required controls.
Document risks, treatments and residual risk for assessment.
Assemble the evidence and artefacts an IRAP assessor will review.
Book a call and we’ll scope the documentation your system needs to face an IRAP assessment with confidence.