ATO Digital Service Provider (DSP) Operational Security Framework
Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework CERT.SELF: Self-assessment against an approved standard, renewed every two years

Categories B and C (as an alternative to independent certification) and category D (mandatory; optional consideration for E) self-assess against an approved standard: the ISM, ISO/IEC 27001 or 27002 (2022 editions in the questionnaire), ISO/IEC 27017, SOC 2, OWASP ASVS (to Level 2 at least) or NIST CSF (NIST not available to category A), or another standard the DPO accepts case by case. The self-assessment determines which controls apply, answers the full control suite with how each is met or why it does not apply, covers the policies, procedures and data repositories holding in-scope data, is reviewed annually and resubmitted every two years, and is revised and resubmitted as soon as possible after a significant change. A statement of applicability against ISO/IEC 27002:2022 is acceptable evidence for ISO/IEC 27001 self-assessment. One self-assessment may cover several products if the DSP attests each is covered.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.