Back to Standards
Security & Access ControlAustralia

Information Security Registered Assessors Program

IRAP

Australian government cloud security assessment program for systems processing government data.

Purpose

Provides independent assessment of ICT systems against Australian Government security requirements.

Requirements Overview

Security assessment by IRAP assessor; Compliance with ISM (Information Security Manual); Risk management; Ongoing security posture; Government data protection

Overview

The Information Security Registered Assessors Program (IRAP) emerged in response to Australia's growing need for robust government data protection in an increasingly complex digital landscape. Established by the Australian Cyber Security Centre (ACSC), IRAP represents a critical evolution in national cybersecurity standards, replacing previous ad-hoc security assessment methodologies with a comprehensive, standardized framework. At its core, IRAP provides a rigorous mechanism for evaluating cloud and information and communications technology (ICT) systems that process sensitive Australian Government data. The program was developed to address significant gaps in government digital infrastructure security, particularly as agencies increasingly rely on external cloud and technology services. Unlike generic international security certifications, IRAP is specifically engineered to meet the unique requirements of Australian government data protection. The standard distinguishes itself through mandatory alignment with 14 detailed security principles from the Australian Government Information Security Manual (ISM). It requires assessments by ACSC-accredited Registered Assessors who possess deep expertise in government security contexts, threat environments, and Australian-specific compliance obligations. For data center operators, IRAP certification represents more than a compliance checkbox. It signifies a sophisticated capability to host and process sensitive government information across multiple classification levels (from OFFICIAL to TOP SECRET). The certification has become a critical differentiator in government procurement, demonstrating an organization's commitment to the highest standards of information security and national digital resilience.

Key Requirements

IRAP Registered Assessor Engagement

Data center systems must be assessed by ACSC-approved Registered Assessors who have completed specialized training in ISM requirements, government security context, and IRAP methodology.

The data center must engage an independent assessor (not internal or vendor-aligned) to conduct the formal security assessment and produce the Commonwealth Approved System Security Assessment Report (CASSAR).

This requirement ensures objective evaluation against government baseline security controls and prevents conflicts of interest in compliance determination.

ISM Compliance Mapping and Control Implementation

Data centers must implement and evidence compliance with the 14 fundamental security principles from the Information Security Manual: security governance, information and data handling, ICT security, physical security, personnel security, third-party management, cryptography, system acquisition/development, security incident management, continuity of operations, audit and accountability, plus protective security.

Each principle requires specific technical controls (e.g., encryption algorithms, access control models, monitoring capabilities) and operational procedures tailored to the data center's specific system architecture and information classification levels handled.

Data Classification and Segregation Controls

Systems must implement technical and logical segregation proportional to the highest classification of data processed, with specific requirements for OFFICIAL-SENSITIVE, SECRET, and TOP SECRET information.

This includes network segmentation, cryptographic isolation, separate security domains, dedicated infrastructure for classified workloads, and controls preventing classified data spillage to lower-classification networks or systems.

Data centers must demonstrate ability to handle multiple classification levels with appropriate segregation and cannot mix classification levels without explicit security assessment and approval.

Cryptography Implementation and Key Management

Data centers must employ ACSC-approved cryptographic algorithms and implement sophisticated key management frameworks including Hardware Security Modules (HSMs), key escrow procedures, cryptographic key generation in secure environments, and key lifecycle management with documented procedures.

Encryption must be applied to data in transit (TLS 1.2 minimum), data at rest (AES-256 or equivalent), and authentication mechanisms.

The assessment specifically examines cryptographic material handling, storage separation from encrypted data, key rotation schedules, and compromise procedures.

Personnel Security Vetting and Clearance Requirements

All personnel with access to government systems or facilities must hold appropriate security clearances (minimum Baseline, Secret, or Top Secret depending on data classification), undergo background investigation through the Australian Security Vetting Authority (ASVA), and complete security awareness training.

Data centers must maintain clearance verification records, establish need-to-know principles restricting access, implement segregation of duties preventing single individuals from compromising sensitive functions, and document all personnel access with audit trails.

Contractors and third-party personnel face equivalent vetting requirements.

Physical Security and Facility Access Controls

Data center facilities must implement multi-layered physical security including perimeter controls, access card systems with audit logging, closed-circuit video surveillance with retention periods (minimum 30 days), security guards for classified workload areas, visitor management procedures, and environmental monitoring for temperature/humidity control of classified zones.

Facilities processing SECRET or TOP SECRET information require Sensitive Compartmented Information Facility (SCIF) standards with Faraday cage construction, electromagnetic shielding, and acoustic security.

The IRAP assessment specifically evaluates physical security adequacy for the classification of information processed.

Incident Response and Breach Notification Procedures

Data centers must maintain documented incident response plans specifically addressing government data compromise scenarios, with defined escalation procedures to government agencies, ACSC notification requirements (within 30 days for confirmed breaches), containment procedures, forensic investigation capabilities, and evidence preservation.

Assessment requires evidence of incident response testing, tabletop exercises simulating government data breaches, documented procedures for handling classified information in incident contexts, and demonstration of capability for emergency system shutdown or isolation if compromise is suspected.

Continuous Security Monitoring and Vulnerability Management

Systems must implement continuous security monitoring (CSEM) capabilities including intrusion detection/prevention systems (IDS/IPS), Security Information and Event Management (SIEM) platforms with 90-day minimum log retention, regular vulnerability scanning (monthly minimum), automated patch management with documented testing and deployment procedures, and annual penetration testing by independent security firms.

Assessment requires evidence that vulnerability remediation follows defined service level agreements aligned to vulnerability criticality, with compensating controls documented for any unpatched systems with business justification.

Audit Logging and Accountability Mechanisms

Data centers must implement comprehensive audit logging for all access to systems, data, and facilities, with logs stored on separate, protected infrastructure resistant to tampering or deletion.

Logging must capture user identity, timestamps, actions performed, data accessed, and outcomes, with specific enhanced logging for privileged account activities and sensitive data access.

Assessment verifies audit log integrity through cryptographic protection, regular review procedures with documented evidence of log analysis, and log retention periods matching data sensitivity (minimum 7 years for government data).

Third-Party Risk Management and Supply Chain Security

Data centers must establish formal vendor management frameworks assessing security capabilities of suppliers (hosting providers, software vendors, managed service providers) and ensuring supply chain security through contractual requirements, regular audits, and compliance verification.

Assessment requires evidence that third parties undergo security assessment proportional to their access and influence, with documented security agreements, service level agreements including security metrics, and contingency plans for vendor failure scenarios.

Particularly critical for data centers utilizing cloud services or managed security services requiring explicit government approval.

Who Uses & Why

IRAP certification becomes mandatory for data center operators processing, storing, or managing Australian Government information at any classification level. Large, nationally-distributed data centers supporting multiple government agencies derive the most significant value, as a single certification enables service delivery across federal, state, and local government clients. Organizations should strongly consider IRAP certification when: government contracts represent more than 10% of their revenue portfolio, they operate in government-intensive geographic regions (such as Canberra), or they aim to support critical infrastructure and defense-related services. The initial certification investment typically ranges from $150,000 to $300,000, with annual maintenance costs between $50,000 and $100,000. While not universally required, IRAP becomes increasingly beneficial for managed service providers, Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS) vendors targeting government markets. Organizations processing classified information (SECRET or TOP SECRET) will effectively find IRAP certification mandatory due to government information protection legislation. Geographic and strategic considerations play a crucial role in certification decisions, with facilities in major government IT hubs experiencing higher return on investment. The comprehensive assessment process typically requires 18-24 months of dedicated implementation and management resources.