IRAP Assessment & Readiness

Independent security assessment.Clearer risk decisions.

ASD-endorsed IRAP assessment services for ICT systems, cloud services, gateways and government-facing environments at SECRET and below.

Vectra helps organisations define scope, prepare evidence, remediate weaknesses and complete an objective assessment against the Australian Government Information Security Manual and other relevant government security frameworks.

IRAP support for government, cloud providers and industry ReadinessAssessment BoundaryEvidence ReviewControl AssessmentSecurity Assessment Report
What IRAP does

Assess how security controls are implemented and operating.

IRAP assessors are ICT security professionals endorsed by the Australian Signals Directorate. They independently assess systems against relevant Australian Government frameworks, identify security weaknesses and provide findings that support risk-based decisions by system owners and authorising officers.

01 / DEFINE

Establish the assessment boundary

Confirm systems, services, environments, data classifications, locations, dependencies, shared controls and exclusions.

02 / EVIDENCE

Collect objective evidence

Review architecture, policies, configurations, records, interviews, testing results and operational artefacts.

03 / ASSESS

Evaluate control effectiveness

Determine whether relevant controls are implemented effectively, ineffective, inherited or supported by an alternate control.

04 / REPORT

Document strengths and weaknesses

Produce a Security Assessment Report and control matrix that clearly explain findings, evidence and limitations.

Vectra IRAP services

Support before, during and after the formal assessment.

Readiness

IRAP readiness assessment

Review the system, available evidence and likely control gaps before commencing the formal IRAP assessment.

Scoping

Assessment boundary definition

Define in-scope services, environments, data flows, dependencies, inherited controls and shared-responsibility arrangements.

Documentation

Security documentation review

Review the System Security Plan, architecture, risk artefacts, control descriptions, procedures and supporting evidence.

Assessment

Formal IRAP security assessment

Assess implemented controls against the latest relevant ISM release and other applicable Australian Government policies and guidance.

Cloud

Cloud-service assessment

Assess cloud service providers, service offerings, shared responsibilities, data sovereignty and cloud control implementation.

Technical

Security testing and validation

Use interviews, examination and technical testing to support conclusions about control implementation and effectiveness.

Explore penetration testing →
Remediation

Finding remediation support

Help control owners understand findings, prepare remediation plans and improve evidence for reassessment.

Delta

Change and reassessment support

Assess material changes, new service components and updates required when the ISM evolves during a long-running assessment.

Advisory

Government security framework alignment

Align system security with the ISM, PSPF, Essential Eight and related organisational risk requirements.

Explore security assessments →
Current IRAP requirements

Assessment against the latest relevant ISM.

The IRAP Common Assessment Framework requires assessors to use the latest ISM release available before the assessment begins, or a later release. Where an assessment spans two ISM releases, a delta assessment is required against the current version.

01
Latest ISM baselineAssessments use the most recent applicable ISM release available before commencement or a subsequent release.
02
Evidence over intentionAssessors evaluate what is implemented and operating, not controls that are only planned for future implementation.
03
Clear assessment boundaryInclusions, exclusions, environments, service dependencies, offshore access and shared controls must be explicitly described.
04
Objective reportingFindings must be based on evidence, explain limitations and avoid claims of certification, compliance or authorisation.
Assessment coverage

Systems and services at SECRET and below.

ASD-endorsed IRAP assessors can assess a range of government and industry technology environments.

ICT Systems

Government and enterprise systems

Applications, infrastructure, networks, endpoints and supporting operational processes within the defined boundary.

Cloud Services

Cloud providers and service offerings

Cloud security fundamentals, individual cloud services, shared responsibilities, service regions and dependencies.

Gateways

Cross-domain and connectivity services

Security assessment of gateway architecture, filtering, monitoring, administration and supporting controls.

GovLink

Government connectivity

Assessment support for organisations and services connecting through relevant Australian Government networks.

When an IRAP assessment is required

Outsourced government systems and cloud services.

Australian Government policy requires specific outsourced information technology and cloud services to be IRAP-assessed before they process or store government information.

Government and Agency Consumers

Support informed authorisation decisions.

IRAP assessment reports provide evidence about system strengths, weaknesses and control effectiveness to support risk acceptance and authority-to-operate decisions.

  • PROTECTED and SECRET environments
  • OFFICIAL and OFFICIAL: Sensitive systems
  • Outsourced technology services
  • Cloud-service procurement and reassessment
  • Risk-informed authorisation
Cloud and Technology Providers

Demonstrate security to government customers.

Providers can use an IRAP assessment to give government consumers detailed evidence about implemented controls and the security characteristics of their services.

  • Cloud security assessment reports
  • Service and control matrices
  • Shared-responsibility documentation
  • Data sovereignty and offshore access
  • Reassessment following significant change
Assessment deliverables

Clear evidence for technical and executive decision-makers.

The IRAP assessment report should clearly describe the system, assessment boundary, methods, evidence, strengths, weaknesses, implementation effectiveness and any limitations affecting the conclusions.

Security Assessment ReportSystem-level assessment narrative

Explains architecture, scope, findings, weaknesses, testing, limitations and recommendations.

Control MatrixControl-by-control observations

Records implementation, effectiveness, assessment methods, evidence and shared responsibilities.

FindingsStrengths and weaknesses

Clearly identifies ineffective controls, vulnerabilities, alternate controls and evidence gaps.

Decision SupportInputs to risk acceptance

Provides objective information for the organisation to assess residual risk and make its own authorisation decision.

Assessment process

A controlled path from scope to final report.

01

Plan

Confirm objectives, frameworks, stakeholders, conflicts, timing and assessment approach.

02

Boundary

Validate system architecture, environments, dependencies, locations and applicable controls.

03

Assess

Gather evidence through examination, interviews and technical testing.

04

Report

Prepare the Security Assessment Report and control matrix for stakeholder review.

05

Improve

Support remediation, reassessment and evidence needed for future risk decisions.

An IRAP assessment is not certification or approval.

IRAP assessors do not accredit, certify, endorse, approve or authorise systems on behalf of ASD. The assessed organisation and its authorising officer remain responsible for understanding the report and deciding whether residual risk is acceptable.

Prepare for a stronger assessment outcome

Make the assessment boundary, evidence and control story clear.

Talk to Vectra about IRAP readiness, cloud-service assessment, formal security assessment, remediation or alignment to the current Information Security Manual.

Start with an IRAP scoping discussion

Tell us about the system, classification, service model, government customers and the stage you have reached.

Contact the IRAP Team →