Protective Security Policy Framework (PSPF) Release 2024
The Australian Government Protective Security Policy Framework sets out government protective security policy across six security domains. It applies to all non-corporate Commonwealth entities and is a key framework for safeguarding government people, information and assets. Release 2024 introduces requirements addressing supply chain security, third-party risk management, foreign interference, and security of operational or emerging technology.
Protective Security Policy Framework (PSPF) Release 2024 is a compliance framework from Australia with 12 domains and 28 controls that map to 228 other frameworks. The largest domains are Information Security Policies (5 to 9) (5 controls), Security Governance Policies (1 to 4) (4 controls), Security Outcomes (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Governance and Culture
| Code | Title |
|---|---|
| PSPF24-1 | Security Culture, Governance, Risk Management |
Incident Response
| Code | Title |
|---|---|
| PSPF24-5 | Information and Cyber Incidents |
Information Security
| Code | Title |
|---|---|
| PSPF24-2 | Information Security, Cybersecurity Maturity, Essential Eight |
Information Security Policies (5 to 9)
Information Security Policies (5 to 9)
| Code | Title |
|---|---|
| PSPF-2024-POL-5 | Policy 5: Classification system |
| PSPF-2024-POL-6 | Policy 6: Sensitive and classified information access |
| PSPF-2024-POL-7 | Policy 7: Security governance for ICT systems |
| PSPF-2024-POL-8 | Policy 8: Sensitive and classified information sharing |
| PSPF-2024-POL-9 | Policy 9: Access to information |
Personnel Security
| Code | Title |
|---|---|
| PSPF24-3 | Personnel Security and Vetting |
Personnel Security Policies (10 to 12)
Personnel Security Policies (10 to 12)
| Code | Title |
|---|---|
| PSPF-2024-POL-10 | Policy 10: Ongoing suitability for personnel |
| PSPF-2024-POL-11 | Policy 11: Managing security clearances |
| PSPF-2024-POL-12 | Policy 12: Eligibility and suitability of contractors |
Physical Security
| Code | Title |
|---|---|
| PSPF24-4 | Physical Security |
Physical Security Policies (13 to 15)
Physical Security Policies (13 to 15)
| Code | Title |
|---|---|
| PSPF-2024-POL-13 | Policy 13: Entity facilities |
| PSPF-2024-POL-14 | Policy 14: Security of physical assets |
| PSPF-2024-POL-15 | Policy 15: Physical security planning |
Secretaries Directions
Secretaries Directions
| Code | Title |
|---|---|
| PSPF-DIR-001-2024 | Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets |
| PSPF-DIR-002-2024 | Direction 002-2024: Technology Asset Stocktake |
| PSPF-DIR-003-2024 | Direction 003-2024: Mitigation of Technology Risks |
Security Governance Policies (1 to 4)
Security Governance Policies (1 to 4)
| Code | Title |
|---|---|
| PSPF-2024-POL-1 | Policy 1: Roles and responsibilities |
| PSPF-2024-POL-2 | Policy 2: Management structures and responsibilities |
| PSPF-2024-POL-3 | Policy 3: Security planning and risk management |
| PSPF-2024-POL-4 | Policy 4: Security maturity monitoring |
Security Incident Policy (16)
Security Incident Policy (16)
| Code | Title |
|---|---|
| PSPF-2024-POL-16 | Policy 16: Reporting and management of security incidents |
Security Outcomes
Security Outcomes
| Code | Title |
|---|---|
| PSPF-2024-OUTCOME-1 | Security Governance Outcome |
| PSPF-2024-OUTCOME-2 | Information Security Outcome |
| PSPF-2024-OUTCOME-3 | Personnel Security Outcome |
| PSPF-2024-OUTCOME-4 | Physical Security Outcome |
Your Compliance Coverage
If you comply with Protective Security Policy Framework (PSPF) Release 2024, you already cover:
ISO/IEC 27010:2015
14%
4 controls mapped
Compare →API 1164
14%
4 controls mapped
Compare →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
14%
4 controls mapped
Compare →+ 225 more: NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (14%), FBI CJIS Security Policy (14%)
See all 228 mapped frameworks ↓Maps to 228 other frameworks
What is Protective Security Policy Framework (PSPF) Release 2024 and who does it apply to?
Protective Security Policy Framework (PSPF) Release 2024 is a compliance framework from Australia with 12 domains and 28 controls. The Australian Government Protective Security Policy Framework sets out government protective security policy across six security domains. It applies to all non-corporate Commonwealth entities and is a key framework for safeguarding government people, information and assets. Release 2024 introduces requirements addressing supply chain security, third-party risk management, foreign interference, and security of operational or emerging technology. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Protective Security Policy Framework (PSPF) Release 2024 actually require?
Protective Security Policy Framework (PSPF) Release 2024 has 28 controls organised across 12 domains. The largest domains are Information Security Policies (5 to 9) (5 controls), Security Governance Policies (1 to 4) (4 controls), Security Outcomes (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Protective Security Policy Framework (PSPF) Release 2024 do I already cover?
Protective Security Policy Framework (PSPF) Release 2024 maps to 228 other compliance frameworks. The top mapping partners are ISO/IEC 27010:2015 (14% coverage), API 1164 (14% coverage), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Protective Security Policy Framework (PSPF) Release 2024?
Start your Protective Security Policy Framework (PSPF) Release 2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Protective Security Policy Framework (PSPF) Release 2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required