// secureos · govern

ISM & IRAP Documentation Services

Handling government data? We prepare the documentation that ISM alignment and an IRAP assessment require — system security plans, risk management, and the evidence assessors look for.

ISM  /  IRAP-aligned  /  SSP & SRMP

// what it is

The documentation government assessment demands

The Information Security Manual (ISM) sets the security requirements for systems handling Australian Government information, and the Infosec Registered Assessors Program (IRAP) is how those systems are independently assessed. Both are documentation-heavy. We prepare the security artefacts — mapped to ISM controls — so an IRAP assessment goes smoothly.

// what we deliver

What we prepare

Scope & data classification

Define the system boundary and classify the data it handles.

ISM control mapping

Map the applicable ISM controls to your system and identify gaps.

System Security Plan (SSP)

Document how your system meets the required controls.

Security Risk Management Plan

Document risks, treatments and residual risk for assessment.

IRAP assessment preparation

Assemble the evidence and artefacts an IRAP assessor will review.

// faq

Frequently asked questions

What is the ISM?

The Information Security Manual — the ASD’s framework of controls for systems handling Australian Government information.
The Infosec Registered Assessors Program — independent assessment of a system’s security against the ISM.
We prepare you for it — documentation, control mapping and evidence — and work alongside the IRAP assessor.
Essential Eight is part of the ISM’s controls; ISM/IRAP is broader and applies to government data handling.
// next step

Get ready for ISM and IRAP.

Book a call and we’ll scope the documentation your system needs to face an IRAP assessment with confidence.