Knowledge / practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.

IRAP is ASD's Infosec Registered Assessors Program. ASD endorses individuals from the private and public sectors to provide independent security assessment services. Assessors help organisations understand strengths and weaknesses and recommend mitigations. They assess SECRET and below for ICT systems, cloud services, gateways, and GovLink. TOP SECRET cloud and systems stay with ASD security assessors or their delegates.

What IRAP does not do matters as much as what it does. ASD's IRAP page is explicit: assessors do not accredit, certify, endorse, or register systems on behalf of ASD. A completed assessment does not imply the system is compliant with every tested control, and the scope will generally not cover all ISM controls. The consumer guide and the report are what you buy. A logo on a slide is not.

For Commonwealth use of outsourced cloud and managed services, the cloud assessment FAQ still drives the cycle: IRAP assessment at least every 24 months, or when events force a revalidation, using a current ISM. CSPs are encouraged to keep reports accurate with addendums when posture changes, and to tell tenants. International certifications (FedRAMP and the rest) do not replace an IRAP assessment against the ISM. Reuse of evidence from other schemes is allowed only where it is applicable, accurate, and valid — including the assessment boundary.

The Cloud Services Certification Program and the Certified Cloud Services List are gone (ceased March and July 2020). There is no current ASD 'certified cloud' stamp to hide behind. Ask for the IRAP report or cloud security assessment report, the date, the classification, the residual-risk table, and what was out of scope. A two-year-old report on a different region or a subset of services is a starting point, not a current control.

On the desk: pick an endorsed assessor, fix the boundary in writing before fieldwork, and read the letter of completion against your shared-responsibility split. Authorisation to operate stays with the system owner. Buying an IRAP-assessed service does not move residual risk to the provider. If the vendor will not show residual risks, you have marketing, not assurance.

Fact source: ASD, Infosec Registered Assessors Program (IRAP).