Protective Security Policy Framework
The Australian Government protective security policy for non-corporate Commonwealth entities. Governance, information, personnel, physical — and a cyber floor that points at Essential Eight.
The Protective Security Policy Framework (PSPF) is issued by the Attorney-General's Department. It is how non-corporate Commonwealth entities are expected to manage protective security: governance, information security, personnel security, and physical security. It is government policy, not an ISO certificate and not a substitute for the ISM on the technical controls.
Cyber sits inside that policy. ASD's report on the Commonwealth cyber security posture in 2022 recorded that, as of July 2022, it is a core PSPF requirement that entities implement the Essential Eight strategies to at least Maturity Level 2. A network's overall maturity is equal to its least mature strategy. You do not average eight scores into a vanity number.
Entities report their security posture to AGD. That reporting is how government gets an aggregated view; it is not a licence to claim maturity you cannot evidence. If you are not an NCCE, PSPF is still a useful dialect when you sell into government. It does not, by itself, make you an NCCE.
Use PSPF to name owners, record exceptions, and accept risk in writing. Use the ISM and Essential Eight for the work list. If a board paper says 'we align to PSPF' and the patching queue is a quarter long, the paper is the vulnerability.
Evidence for the cyber floor is the same evidence as Essential Eight: scope, artefact, date, owner, and overall maturity equal to the weakest strategy. PSPF tells you the policy duty; Essential Eight evidence is how you show you met it. Keep the two files next to each other, not in separate sharepoint graveyards.
Fact source: ASD, Commonwealth cyber security posture 2022.
