Australia IRAP — Information Security Registered Assessors Program
The Information Security Registered Assessors Program (IRAP) is an Australian Government initiative administered by the Australian Signals Directorate (ASD). IRAP provides a framework for assessing the implementation and effectiveness of security controls against the Australian Government Information Security Manual (ISM). IRAP assessors are endorsed by ASD to conduct security assessments for Australian Government agencies and cloud service providers seeking to host government data. Assessment against ISM controls at OFFICIAL, PROTECTED, and SECRET levels.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Access
| Code | Title |
|---|---|
| IRAP-14 | Identity and Privileged Access |
Assessment Framework
| Code | Title |
|---|---|
| IRAP-6 | ISM Compliance Assessment |
| IRAP-7 | Security Control Assessment |
| IRAP-8 | Risk Assessment |
Assessment Setup
| Code | Title |
|---|---|
| IRAP-01 | IRAP Assessor Engagement |
Assessor Qualifications
| Code | Title |
|---|---|
| IRAP-1 | Australian Citizenship and Clearance |
| IRAP-2 | Professional Experience |
| IRAP-3 | Professional Qualifications |
Authorisation
| Code | Title |
|---|---|
| IRAP-17 | Authority to Operate Decision |
Cloud
| Code | Title |
|---|---|
| IRAP-15 | Cloud Service Assessment |
Continuous Assurance
| Code | Title |
|---|---|
| IRAP-18 | Continuous Monitoring and Reassessment |
Crypto
| Code | Title |
|---|---|
| IRAP-09 | Cryptography and ASD Approved Algorithms |
Data
| Code | Title |
|---|---|
| IRAP-05 | Information Classification and Handling |
Detection
| Code | Title |
|---|---|
| IRAP-11 | Event Logging and Monitoring |
Documentation
| Code | Title |
|---|---|
| IRAP-02 | System Security Plan |
Governance and Declarations
| Code | Title |
|---|---|
| IRAP-10 | Gateway and Boundary Protection |
| IRAP-9 | Conflict of Interest Declaration |
Incident
| Code | Title |
|---|---|
| IRAP-12 | Cyber Incident Response |
Mitigations
| Code | Title |
|---|---|
| IRAP-08 | Essential Eight Maturity |
Network
| Code | Title |
|---|---|
| IRAP-10 | Gateway and Boundary Protection |
Personnel
| Code | Title |
|---|---|
| IRAP-06 | Personnel Security and Clearances |
Physical
| Code | Title |
|---|---|
| IRAP-07 | Physical Security Zones |
Reporting
| Code | Title |
|---|---|
| IRAP-16 | Security Assessment Report |
Reporting and Maintenance
| Code | Title |
|---|---|
| IRAP-11 | Event Logging and Monitoring |
| IRAP-12 | Cyber Incident Response |
Risk
| Code | Title |
|---|---|
| IRAP-03 | Security Risk Management Plan |
Scoping
| Code | Title |
|---|---|
| IRAP-04 | Statement of Applicability |
Training and Examination
| Code | Title |
|---|---|
| IRAP-4 | IRAP New Starter Training |
| IRAP-5 | IRAP Assessor Examination |
Vulnerability
| Code | Title |
|---|---|
| IRAP-13 | Vulnerability and Patch Management |
Your Compliance Coverage
If you comply with Australia IRAP — Information Security Registered Assessors Program, you already cover:
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
7%
2 controls mapped
Compare →US Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule
7%
2 controls mapped
Compare →NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements
7%
2 controls mapped
Compare →+ 322 more: CIS Controls v8 (7%), C-TPAT — Customs-Trade Partnership Against Terrorism (7%)
See all 325 mapped frameworks ↓Maps to 325 other frameworks
Frequently Asked Questions
What is Australia IRAP — Information Security Registered Assessors Program?
Australia IRAP — Information Security Registered Assessors Program is a compliance framework from Australia (ASD) with 23 domains and 30 controls. The Information Security Registered Assessors Program (IRAP) is an Australian Government initiative administered by the Australian Signals Directorate (ASD). IRAP provides a framework for assessing the implementation and effectiveness of security controls against the Australian Government Information Security Manual (ISM). IRAP assessors are endorsed by ASD to conduct security assessments for Australian Government agencies and cloud service providers seeking to host government data. Assessment against ISM controls at OFFICIAL, PROTECTED, and SECRET levels. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australia IRAP — Information Security Registered Assessors Program have?
Australia IRAP — Information Security Registered Assessors Program has 30 controls organised across 23 domains. The largest domains are Assessment Framework (3 controls), Assessor Qualifications (3 controls), Governance and Declarations (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australia IRAP — Information Security Registered Assessors Program map to?
Australia IRAP — Information Security Registered Assessors Program maps to 325 other compliance frameworks. The top mapping partners are CFTC System Safeguards (17 CFR 37, 38, 39, 49) (7% coverage), US Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule (7% coverage), NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australia IRAP — Information Security Registered Assessors Program compliance?
Start your Australia IRAP — Information Security Registered Assessors Program compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia IRAP — Information Security Registered Assessors Program requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required