Establish the assessment boundary
Confirm systems, services, environments, data classifications, locations, dependencies, shared controls and exclusions.
ASD-endorsed IRAP assessment services for ICT systems, cloud services, gateways and government-facing environments at SECRET and below.
Vectra helps organisations define scope, prepare evidence, remediate weaknesses and complete an objective assessment against the Australian Government Information Security Manual and other relevant government security frameworks.
IRAP assessors are ICT security professionals endorsed by the Australian Signals Directorate. They independently assess systems against relevant Australian Government frameworks, identify security weaknesses and provide findings that support risk-based decisions by system owners and authorising officers.
Confirm systems, services, environments, data classifications, locations, dependencies, shared controls and exclusions.
Review architecture, policies, configurations, records, interviews, testing results and operational artefacts.
Determine whether relevant controls are implemented effectively, ineffective, inherited or supported by an alternate control.
Produce a Security Assessment Report and control matrix that clearly explain findings, evidence and limitations.
Review the system, available evidence and likely control gaps before commencing the formal IRAP assessment.
Define in-scope services, environments, data flows, dependencies, inherited controls and shared-responsibility arrangements.
Review the System Security Plan, architecture, risk artefacts, control descriptions, procedures and supporting evidence.
Assess implemented controls against the latest relevant ISM release and other applicable Australian Government policies and guidance.
Assess cloud service providers, service offerings, shared responsibilities, data sovereignty and cloud control implementation.
Use interviews, examination and technical testing to support conclusions about control implementation and effectiveness.
Explore penetration testing →Help control owners understand findings, prepare remediation plans and improve evidence for reassessment.
Assess material changes, new service components and updates required when the ISM evolves during a long-running assessment.
Align system security with the ISM, PSPF, Essential Eight and related organisational risk requirements.
Explore security assessments →The IRAP Common Assessment Framework requires assessors to use the latest ISM release available before the assessment begins, or a later release. Where an assessment spans two ISM releases, a delta assessment is required against the current version.
ASD-endorsed IRAP assessors can assess a range of government and industry technology environments.
Applications, infrastructure, networks, endpoints and supporting operational processes within the defined boundary.
Cloud security fundamentals, individual cloud services, shared responsibilities, service regions and dependencies.
Security assessment of gateway architecture, filtering, monitoring, administration and supporting controls.
Assessment support for organisations and services connecting through relevant Australian Government networks.
Australian Government policy requires specific outsourced information technology and cloud services to be IRAP-assessed before they process or store government information.
IRAP assessment reports provide evidence about system strengths, weaknesses and control effectiveness to support risk acceptance and authority-to-operate decisions.
Providers can use an IRAP assessment to give government consumers detailed evidence about implemented controls and the security characteristics of their services.
The IRAP assessment report should clearly describe the system, assessment boundary, methods, evidence, strengths, weaknesses, implementation effectiveness and any limitations affecting the conclusions.
Explains architecture, scope, findings, weaknesses, testing, limitations and recommendations.
Records implementation, effectiveness, assessment methods, evidence and shared responsibilities.
Clearly identifies ineffective controls, vulnerabilities, alternate controls and evidence gaps.
Provides objective information for the organisation to assess residual risk and make its own authorisation decision.
Confirm objectives, frameworks, stakeholders, conflicts, timing and assessment approach.
Validate system architecture, environments, dependencies, locations and applicable controls.
Gather evidence through examination, interviews and technical testing.
Prepare the Security Assessment Report and control matrix for stakeholder review.
Support remediation, reassessment and evidence needed for future risk decisions.
IRAP assessors do not accredit, certify, endorse, approve or authorise systems on behalf of ASD. The assessed organisation and its authorising officer remain responsible for understanding the report and deciding whether residual risk is acceptable.
Talk to Vectra about IRAP readiness, cloud-service assessment, formal security assessment, remediation or alignment to the current Information Security Manual.
Tell us about the system, classification, service model, government customers and the stage you have reached.
Contact the IRAP Team →| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |