
The Information Security Registered Assessors Program (IRAP) is an ASD program that endorses qualified cyber security professionals to perform independent assessments of ICT systems against the Australian Information Security Manual (ISM). An IRAP assessment identifies a system's security strengths, weaknesses, and control effectiveness — enabling an Authorising Officer to make a risk-based decision to authorise the system.
Australia's Commonwealth cyber security posture operates as a three-layer stack. The PSPF sets policy obligations; the ISM is the technical control catalogue; and IRAP is the independent assessment mechanism.
Sets what Commonwealth entities MUST do. Mandatory for non-corporate Commonwealth entities under the PGPA Act. Organised into six domains: Governance, Risk, Information Security, Technology, Personnel, and Physical.
Official siteDefines HOW to implement security technically. Published quarterly by ASD. Controls grouped under six functions: Govern, Identify, Protect, Detect, Respond, and Recover. PSPF Requirement 0098 mandates alignment.
Official siteProvides INDEPENDENT assurance that a system meets the ISM. Performed by ASD-endorsed assessors. Effectively mandatory for Commonwealth consumption of cloud and outsourced ICT up to PROTECTED.
Official siteThe IRAP Common Assessment Framework defines four stages. The older "Stage 1 / Stage 2" terminology (design review vs. implementation review) has been superseded.
Engagement planning, Conflict of Interest declaration to ASD (required at least 7 business days before the engagement starts), access arrangements for documentation and personnel, and methodology decisions.
The assessor and system owner's delegate agree on scope, classification, in/out-of-scope components, and shared-responsibility inheritance. The assessment boundary can be broader than — but never a subset of — the authorisation boundary.
Evidence gathered via Examine / Interview / Test against ISM controls. Assessment depth is graded Basic, Focused, or Comprehensive. Evidence quality is graded Excellent / Good / Fair / Poor.
A Security Assessment Report (SAR) plus Controls Matrix is delivered using ASD-provided templates. Assessors do not rate risk on behalf of the entity — that is the Authorising Officer's responsibility.
Assessment Boundary
Everything the assessor examined — components, specifications, mechanisms, activities, personnel, and facilities. Can be broader than the authorisation boundary, never narrower.
Authorisation Boundary
What the Authorising Officer actually authorises to operate. Must be equal to or a subset of the assessment boundary — never larger.
Scoping covers
The IRAP Consumer Guide and Common Assessment Framework specify the expected documentation set. Missing or thin documents will delay the engagement and typically produce "Ineffective" or "No visibility" outcomes.
System Security Plan (SSP)
Describes how ISM controls apply to the system — the primary technical document.
SSP Annex
Control-by-control implementation detail; the basis for the Controls Matrix.
Security Risk Management Plan (SRMP)
Risk context, treatment decisions, and residual risk acceptance.
Cyber Security Incident Response Plan (IRP)
Procedures and playbooks for detecting and responding to incidents.
Continuous Monitoring Plan (CMP)
How the system's security posture is monitored and maintained over time.
System Design Documents
Architectural diagrams, data-flow diagrams, build and configuration artefacts.
Business Continuity & Disaster Recovery Plans
BCP/DRP — organisational resilience posture.
Supporting Policies & SOPs
Operational procedures that support the controls claimed in the SSP.
Authorisation Package (minimum)
The final package delivered to the Authorising Officer must contain at minimum: SSP, Cyber Security IRP, Continuous Monitoring Plan, Security Assessment Report (SAR), Controls Matrix, and a Plan of Action and Milestones (if applicable).
Owns the system. Prepares documentation, makes personnel available for interviews, and nominates a delegate to agree on the assessment boundary with the assessor.
Makes the risk-based authority-to-operate decision. For OFFICIAL through SECRET systems this is typically the Accountable Authority or CISO. For TOP SECRET, it is the Director-General ASD or their delegate.
ASD-endorsed independent assessor. Plans, scopes, assesses, and produces the SAR and Controls Matrix. Must be fully independent — cannot have designed, implemented, or advised on the assessed system.
In-house or contracted assessor permitted for on-premises systems up to SECRET. Not permitted for outsourced IT or cloud services — those must always be assessed by an IRAP assessor.
IRAP assessors classify each applicable ISM control using one of seven standardised outcomes per the IRAP Common Assessment Framework.
Effective
Control is implemented and achieves its intended security objective.
Ineffective
Control is implemented but does not adequately achieve its intent.
Alternate Control
A different control achieves equivalent risk reduction to the specified control.
Not Implemented
The control is applicable to the system but has not been implemented.
Not Applicable
The control does not apply to the system or its specific operational context.
Not Assessed
The control was in scope but not assessed — due to time constraints, sampling, or agreed scope reduction.
No Visibility
The assessor could not gather sufficient evidence to determine the outcome.
Cloud and outsourced ICT at any classification require an IRAP assessor — an entity assessor is not sufficient.
| Classification / Type | On-Premises | Cloud / Outsourced | Authorises |
|---|---|---|---|
| TOP SECRET | ASD Assessor | ASD Assessor | Director-General ASD |
| SECRET (on-premises) | Entity or IRAP | — | Accountable Authority / CISO |
| SECRET (outsourced / cloud) | — | IRAP Assessor | Accountable Authority / CISO |
| PROTECTED / OFFICIAL:S (on-prem) | Entity or IRAP | — | Accountable Authority / CISO |
| PROTECTED / OFFICIAL:S (cloud) | — | IRAP Assessor | Accountable Authority / CISO |
| Gateways (any classification) | IRAP Assessor | IRAP Assessor | Accountable Authority / CISO |
The Australian Information Security Academy (AusISA) — an ASD-endorsed IRAP training provider — offers Australia's flagship IRAP Assessor Training course. A 5-day intensive scenario-based program delivered by active IRAP assessors and practitioners from Redacted Information Security and Malware Security.