Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

Australia IRAP — Information Security Registered Assessors Program (ASD ACSC)

The Information Security Registered Assessors Program (IRAP) is the Australian government cybersecurity assessment programme administered by the…

What Australia IRAP — Information Security Registered Assessors Program (ASD ACSC) requires

The Information Security Registered Assessors Program (IRAP) is the Australian government cybersecurity assessment programme administered by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). IRAP-endorsed assessors evaluate the implementation of the controls specified in the Australian Government Information Security Manual (ISM) against the security classification of the system under assessment. IRAP assessments cover Australian government cloud services, Defence systems, critical infrastructure under the Security of Critical Infrastructure Act 2018 (SOCI Act), and high-assurance enterprise systems handling Australian government data. The Australian security classifications covered include OFFICIAL (everyday business information), OFFICIAL:Sensitive (information requiring limited dissemination), PROTECTED (information whose compromise would cause damage to national interests), SECRET (serious damage), and TOP SECRET (exceptionally grave damage). IRAP-assessed services may receive Certified Cloud Services List placement at PROTECTED level under the previous IRAP Certified Cloud Services List and the successor Assured Cloud Services framework, and at OFFICIAL:Sensitive and lower under broader CSP self-assessment regimes. IRAP assessments follow a standard methodology spanning architecture review, control implementation testing, residual-risk evaluation, and consumer guide preparation; the assessment cycle is typically 24 months with annual surveillance for cloud services. IRAP-endorsed CSPs include AWS, Microsoft Azure, Google Cloud, Oracle Cloud Infrastructure, IBM Cloud, Vault Cloud, Macquarie Government, and several Australian sovereign cloud providers. The programme intersects the Hosting Certification Framework administered by the Digital Transformation Agency and the Protective Security Policy Framework (PSPF) administered by the Attorney-General's Department.

Pillar: Cloud & SaaS · Authority: Australian Signals Directorate (ASD), Australian Cyber Security Centre (ACSC), Australia · Version: 1.0.0 · Last updated:

Primary source: https://www.cyber.gov.au/resources-business-and-government/assessment-and-evaluation-programs/irap

SHA-256 integrity: 0591931742afa92acb6c39e5aa2b89c26d980b1fe23ad8acaadda97f054b83be

Primary Citations — 10 traced to source

  • Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC) Information Security Registered Assessors Program (IRAP) - cybersecurity assessment programme for Australian government cloud and high-assurance systems
  • Australian Government Information Security Manual (ISM) - the operative cybersecurity controls baseline for IRAP assessments, updated monthly by ASD

+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.