ATO Digital Service Provider (DSP) Operational Security Framework
Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework CERT.IND: Independent certification (iRAP or ISO/IEC 27001) where the category requires it

Category A must hold independent certification against iRAP (the ISM) or ISO/IEC 27001 (the questionnaire names the 2022 edition); categories B and C may choose independent certification, and it is optional but recommended for category D. The certification scope covers the organisational policies, procedures and data repositories that hold or manage tax or superannuation information (a large organisation may limit ISO/IEC 27001 scope to the business unit responsible); non-applicable controls are addressed in the statement of applicability; a qualified independent assessor audits annually; certification is maintained and evidence supplied to the ATO. Conditional approval may be granted for a limited time while certification is under way, with a timeline, progress updates, a recent self-assessment and a letter of engagement naming dates, scope and assessor.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.