Framework Guide

The IRAP Process

The Information Security Registered Assessors Program (IRAP) is an ASD program that endorses qualified cyber security professionals to perform independent assessments of ICT systems against the Australian Information Security Manual (ISM). An IRAP assessment identifies a system's security strengths, weaknesses, and control effectiveness — enabling an Authorising Officer to make a risk-based decision to authorise the system.

An IRAP assessment is not a certification, accreditation, endorsement, or approval by ASD.

Australia's Commonwealth cyber security posture operates as a three-layer stack. The PSPF sets policy obligations; the ISM is the technical control catalogue; and IRAP is the independent assessment mechanism.

Policy
PSPF
Protective Security Policy Framework

Sets what Commonwealth entities MUST do. Mandatory for non-corporate Commonwealth entities under the PGPA Act. Organised into six domains: Governance, Risk, Information Security, Technology, Personnel, and Physical.

Official site
Controls
ISM
Information Security Manual

Defines HOW to implement security technically. Published quarterly by ASD. Controls grouped under six functions: Govern, Identify, Protect, Detect, Respond, and Recover. PSPF Requirement 0098 mandates alignment.

Official site
Assessment
IRAP
Assessment Program

Provides INDEPENDENT assurance that a system meets the ISM. Performed by ASD-endorsed assessors. Effectively mandatory for Commonwealth consumption of cloud and outsourced ICT up to PROTECTED.

Official site

The IRAP Common Assessment Framework defines four stages. The older "Stage 1 / Stage 2" terminology (design review vs. implementation review) has been superseded.

01

Plan & Prepare

Engagement planning, Conflict of Interest declaration to ASD (required at least 7 business days before the engagement starts), access arrangements for documentation and personnel, and methodology decisions.

02

Define the Assessment Boundary

The assessor and system owner's delegate agree on scope, classification, in/out-of-scope components, and shared-responsibility inheritance. The assessment boundary can be broader than — but never a subset of — the authorisation boundary.

03

Assess the Controls

Evidence gathered via Examine / Interview / Test against ISM controls. Assessment depth is graded Basic, Focused, or Comprehensive. Evidence quality is graded Excellent / Good / Fair / Poor.

04

Produce the Assessment Report

A Security Assessment Report (SAR) plus Controls Matrix is delivered using ASD-provided templates. Assessors do not rate risk on behalf of the entity — that is the Authorising Officer's responsibility.

IRAP Common Assessment Framework (ASD PDF)

Assessment Boundary

Everything the assessor examined — components, specifications, mechanisms, activities, personnel, and facilities. Can be broader than the authorisation boundary, never narrower.

Authorisation Boundary

What the Authorising Officer actually authorises to operate. Must be equal to or a subset of the assessment boundary — never larger.

Scoping covers

  • System version and environments (PROD / PRE-PROD / TEST / DEV)
  • Intended security classification of data processed
  • People, processes, technologies, and facilities the system relies on
  • Shared-responsibility and control inheritance from upstream providers
  • Data sovereignty, offshore staff, and offshore equipment
Both inclusions and exclusions must be justified. The SAR records what was assessed and — equally important — what was deliberately excluded, with reasoning. Components outside the assessment boundary also fall outside any authorisation to operate.

The IRAP Consumer Guide and Common Assessment Framework specify the expected documentation set. Missing or thin documents will delay the engagement and typically produce "Ineffective" or "No visibility" outcomes.

System Security Plan (SSP)

Describes how ISM controls apply to the system — the primary technical document.

SSP Annex

Control-by-control implementation detail; the basis for the Controls Matrix.

Security Risk Management Plan (SRMP)

Risk context, treatment decisions, and residual risk acceptance.

Cyber Security Incident Response Plan (IRP)

Procedures and playbooks for detecting and responding to incidents.

Continuous Monitoring Plan (CMP)

How the system's security posture is monitored and maintained over time.

System Design Documents

Architectural diagrams, data-flow diagrams, build and configuration artefacts.

Business Continuity & Disaster Recovery Plans

BCP/DRP — organisational resilience posture.

Supporting Policies & SOPs

Operational procedures that support the controls claimed in the SSP.

Authorisation Package (minimum)

The final package delivered to the Authorising Officer must contain at minimum: SSP, Cyber Security IRP, Continuous Monitoring Plan, Security Assessment Report (SAR), Controls Matrix, and a Plan of Action and Milestones (if applicable).

System Owner

Owns the system. Prepares documentation, makes personnel available for interviews, and nominates a delegate to agree on the assessment boundary with the assessor.

Authorising Officer

Makes the risk-based authority-to-operate decision. For OFFICIAL through SECRET systems this is typically the Accountable Authority or CISO. For TOP SECRET, it is the Director-General ASD or their delegate.

IRAP Assessor

ASD-endorsed independent assessor. Plans, scopes, assesses, and produces the SAR and Controls Matrix. Must be fully independent — cannot have designed, implemented, or advised on the assessed system.

Entity Assessor

In-house or contracted assessor permitted for on-premises systems up to SECRET. Not permitted for outsourced IT or cloud services — those must always be assessed by an IRAP assessor.

IRAP assessors classify each applicable ISM control using one of seven standardised outcomes per the IRAP Common Assessment Framework.

Effective

Control is implemented and achieves its intended security objective.

Ineffective

Control is implemented but does not adequately achieve its intent.

Alternate Control

A different control achieves equivalent risk reduction to the specified control.

Not Implemented

The control is applicable to the system but has not been implemented.

Not Applicable

The control does not apply to the system or its specific operational context.

Not Assessed

The control was in scope but not assessed — due to time constraints, sampling, or agreed scope reduction.

No Visibility

The assessor could not gather sufficient evidence to determine the outcome.

Cloud and outsourced ICT at any classification require an IRAP assessor — an entity assessor is not sufficient.

Classification / TypeOn-PremisesCloud / OutsourcedAuthorises
TOP SECRETASD AssessorASD AssessorDirector-General ASD
SECRET (on-premises)Entity or IRAPAccountable Authority / CISO
SECRET (outsourced / cloud)IRAP AssessorAccountable Authority / CISO
PROTECTED / OFFICIAL:S (on-prem)Entity or IRAPAccountable Authority / CISO
PROTECTED / OFFICIAL:S (cloud)IRAP AssessorAccountable Authority / CISO
Gateways (any classification)IRAP AssessorIRAP AssessorAccountable Authority / CISO
ASD-Endorsed IRAP Training · Jun 2026 — Seats Available

Become an ASD-Endorsed IRAP Assessor

The Australian Information Security Academy (AusISA) — an ASD-endorsed IRAP training provider — offers Australia's flagship IRAP Assessor Training course. A 5-day intensive scenario-based program delivered by active IRAP assessors and practitioners from Redacted Information Security and Malware Security.

  • ISM controls & IRAP Common Assessment Framework aligned
  • Hands-on labs assessing a simulated government environment
  • Prepares you for the IRAP assessor examination & ASD endorsement
  • Delivered in Canberra, Sydney, Melbourne, Brisbane & Online
  • $7,620 AUD + GST · Current IRAP assessors: $3,950 + GST
Enrol Now View AusISA

Opens ausinfosec.academy in a new tab

Feisty Fox Logo
Feisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.