Category A must hold independent certification against iRAP (the ISM) or ISO/IEC 27001 (the questionnaire names the 2022 edition); categories B and C may choose independent certification, and it is optional but recommended for category D. The certification scope covers the organisational policies, procedures and data repositories that hold or manage tax or superannuation information (a large organisation may limit ISO/IEC 27001 scope to the business unit responsible); non-applicable controls are addressed in the statement of applicability; a qualified independent assessor audits annually; certification is maintained and evidence supplied to the ATO. Conditional approval may be granted for a limited time while certification is under way, with a timeline, progress updates, a recent self-assessment and a letter of engagement naming dates, scope and assessor.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.