What Australia IRAP — Information Security Registered Assessors Program (ASD ACSC) requires
The Information Security Registered Assessors Program (IRAP) is the Australian government cybersecurity assessment programme administered by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). IRAP-endorsed assessors evaluate the implementation of the controls specified in the Australian Government Information Security Manual (ISM) against the security classification of the system under assessment. IRAP assessments cover Australian government cloud services, Defence systems, critical infrastructure under the Security of Critical Infrastructure Act 2018 (SOCI Act), and high-assurance enterprise systems handling Australian government data. The Australian security classifications covered include OFFICIAL (everyday business information), OFFICIAL:Sensitive (information requiring limited dissemination), PROTECTED (information whose compromise would cause damage to national interests), SECRET (serious damage), and TOP SECRET (exceptionally grave damage). IRAP-assessed services may receive Certified Cloud Services List placement at PROTECTED level under the previous IRAP Certified Cloud Services List and the successor Assured Cloud Services framework, and at OFFICIAL:Sensitive and lower under broader CSP self-assessment regimes. IRAP assessments follow a standard methodology spanning architecture review, control implementation testing, residual-risk evaluation, and consumer guide preparation; the assessment cycle is typically 24 months with annual surveillance for cloud services. IRAP-endorsed CSPs include AWS, Microsoft Azure, Google Cloud, Oracle Cloud Infrastructure, IBM Cloud, Vault Cloud, Macquarie Government, and several Australian sovereign cloud providers. The programme intersects the Hosting Certification Framework administered by the Digital Transformation Agency and the Protective Security Policy Framework (PSPF) administered by the Attorney-General's Department.
Pillar: Cloud & SaaS · Authority: Australian Signals Directorate (ASD), Australian Cyber Security Centre (ACSC), Australia · Version: 1.0.0 · Last updated:
Primary source: https://www.cyber.gov.au/resources-business-and-government/assessment-and-evaluation-programs/irap
SHA-256 integrity: 0591931742afa92acb6c39e5aa2b89c26d980b1fe23ad8acaadda97f054b83be
Primary Citations — 10 traced to source
- Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC) Information Security Registered Assessors Program (IRAP) - cybersecurity assessment programme for Australian government cloud and high-assurance systems
- Australian Government Information Security Manual (ISM) - the operative cybersecurity controls baseline for IRAP assessments, updated monthly by ASD
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/au-irap-information-security-registered-assessors-program.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/au-irap-information-security-registered-assessors-program.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/au-irap-information-security-registered-assessors-program
- Back to registry: Browse all 10,085 compliance nodes