Protective Security Policy Framework (PSPF) Release 2026
Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0090: 0090 Reassess authorisation on significant change

Requirement 0090 (Part Four: Technology, section 13.3.1 Technology Lifecycle Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Each technology system's suitability to be authorised to operate is reassessed when it undergoes significant functionality or architectural change, or where the system's security environment has changed considerably. Triggers include changes to ISM controls or policy, new threats, ineffective controls, major incidents and major functional or architectural change; system owners monitor that risk stays within tolerance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.