Back to Frameworks

Defence Industry Security Program (DISP)

Australia
v2022
4 domains
18 controls

The Defence Industry Security Program (DISP) is a risk‑management and assurance framework administered by the Australian Department of Defence. It enables industry partners to understand and meet their security obligations when working with or for Defence. DISP membership requires compliance across 13 security domains and 41 controls, covering governance, personnel, physical security, information security, cyber security, and other critical areas.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

DISP: ICT and Cyber Security

4 controls
Controls in the DISP: ICT and Cyber Security domain of Defence Industry Security Program (DISP)4 controls
CodeTitle
DISP-ICT-E8Essential Eight Maturity Level 2 on corporate ICT
DISP-ICT-INCIDENTCyber incident detection and response
DISP-ICT-ISMClassified ICT systems aligned to the ISM (authorisation and accreditation)
DISP-ICT-SUPPLYCHAINSupply chain, subcontractor flowdown and export controls

DISP: Membership and Security Governance

7 controls
Controls in the DISP: Membership and Security Governance domain of Defence Industry Security Program (DISP)7 controls
CodeTitle
DISP-GOV-ASSURANCECompliance, assurance and audits
DISP-GOV-CSOChief Security Officer appointment
DISP-GOV-INCIDENTNotifiable security incident reporting
DISP-GOV-MEMBERSHIPDISP membership, sponsorship and levels
DISP-GOV-PLANSecurity plan, policies and processes
DISP-GOV-REPORTAnnual security report and reportable changes
DISP-GOV-SOSecurity Officer appointment

DISP: Personnel Security

4 controls
Controls in the DISP: Personnel Security domain of Defence Industry Security Program (DISP)4 controls
CodeTitle
DISP-PERS-AWARENESSSecurity awareness training
DISP-PERS-CLEARANCESecurity clearances (AGSVA sponsorship)
DISP-PERS-LIFECYCLEOnboarding, offboarding and ongoing suitability
DISP-PERS-SCREENWorkforce screening (AS 4811:2022)

DISP: Physical Security

3 controls
Controls in the DISP: Physical Security domain of Defence Industry Security Program (DISP)3 controls
CodeTitle
DISP-PHYS-ACCESSPhysical access control and visitor management
DISP-PHYS-STORAGESecure storage and SCEC-approved equipment
DISP-PHYS-ZONESSecurity zones and facility certification

Maps to 3 other frameworks

18 total controls
Defence Security Principles Framework (DSPF)
3 source controls mapped|3 target controls covered
17%
NIST Cybersecurity Framework 2.0
1 source controls mapped|1 target controls covered
6%
ACSC Essential Eight
1 source controls mapped|8 target controls covered
6%

Frequently Asked Questions

What is Defence Industry Security Program (DISP)?

Defence Industry Security Program (DISP) is a compliance framework from Australia with 4 domains and 18 controls. The Defence Industry Security Program (DISP) is a risk‑management and assurance framework administered by the Australian Department of Defence. It enables industry partners to understand and meet their security obligations when working with or for Defence. DISP membership requires compliance across 13 security domains and 41 controls, covering governance, personnel, physical security, information security, cyber security, and other critical areas. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Defence Industry Security Program (DISP) have?

Defence Industry Security Program (DISP) has 18 controls organised across 4 domains. The largest domains are DISP: Membership and Security Governance (7 controls), DISP: ICT and Cyber Security (4 controls), DISP: Personnel Security (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Defence Industry Security Program (DISP) map to?

Defence Industry Security Program (DISP) maps to 3 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (17% coverage), NIST Cybersecurity Framework 2.0 (6% coverage), ACSC Essential Eight (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Defence Industry Security Program (DISP) compliance?

Start your Defence Industry Security Program (DISP) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Defence Industry Security Program (DISP) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 18 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required