Handling government data? We prepare the documentation that ISM alignment and an IRAP assessment require — system security plans, risk management, and the evidence assessors look for.
ISM / IRAP-aligned / SSP & SRMP
The Information Security Manual (ISM) sets the security requirements for systems handling Australian Government information, and the Infosec Registered Assessors Program (IRAP) is how those systems are independently assessed. Both are documentation-heavy. We prepare the security artefacts — mapped to ISM controls — so an IRAP assessment goes smoothly.
Define the system boundary and classify the data it handles.
Map the applicable ISM controls to your system and identify gaps.
Document how your system meets the required controls.
Document risks, treatments and residual risk for assessment.
Assemble the evidence and artefacts an IRAP assessor will review.
Book a call and we’ll scope the documentation your system needs to face an IRAP assessment with confidence.