Australian Information Security Manual
Guidelines for cyber security documentation

Australian Information Security Manual ISM-1563: Security assessment report

At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: - the scope of the security assessment - the system's strengths and weaknesses - security risks associated with the operation of the system - the effectiveness of the implementation of controls - any recommended remediation actions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 6 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • IRAP-CAF-3 Stage 3 - Assess the controls
  • IRAP-CAF-4 Stage 4 - Produce the IRAP assessment report
  • IRAP-OUT-1 Control effectiveness determination

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • 4.2.12.C.01 4.2.12.C.01 Residual risk assessment for the Accreditation Authority

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Guidelines for cyber security documentation

Query this from an agent

The graph holds this control, the 6 it maps to, and the evidence behind each claim, over MCP and REST.