Failing an IRAP assessment drains your time, budget, and market momentum. To avoid delays, organizations must identify gaps and finalize documentation before the formal engagement starts. The Information Security Registered Assessors Program (IRAP) evaluates systems against the ISM. You need a complete System Security Plan (SSP) and Statement of Applicability (SoA) to begin. Technical evidence must validate your claims. This checklist defines the mandatory prerequisites to survive the audit.
Understanding the IRAP Assessment Process
An IRAP assessment validates your security posture across two distinct phases. Stage 1 focuses strictly on scoping and documentation review to confirm baseline readiness. Stage 2 requires live technical validation and evidence collection. The final output is a Security Assessment Report (SAR) detailing identified risks, which the Authorising Officer uses for accreditation.
Key Domains Covered by IRAP
Assessors probe your infrastructure across multiple domains to verify defense-in-depth architecture. Weaknesses in foundational areas like documentation or governance will trigger a cascade of severe findings. For example, a missing incident response playbook guarantees a finding, even if your technical controls are robust.
| Domain | Primary Focus |
|---|---|
| Documentation | System Security Plan (SSP), Statement of Applicability (SoA), Security Risk Management Plan (SRMP) |
| Technical Controls | Essential Eight maturity, network segmentation, centralized logging, encryption |
| Governance | Security roles, change management, incident response |
| Physical Security | Access controls, environmental monitoring, secure facilities |
Pre-Assessment Steps and Documentation Review
Complete documentation is the fundamental prerequisite for initiating an assessment. Assessors require an accurate SSP, SoA, and SRMP to understand the system architecture and target classification. Missing documentation halts the assessment process immediately.
- Confirm system boundary and external interconnections.
- Assign key roles: CISO, System Owner, and Authorising Officer.
- Identify target security classification (e.g., PROTECTED).
- Collect existing architectural diagrams and operational procedures.
- Schedule a configuration freeze prior to the formal assessment.
Technical Controls and Evidence Collection
Written policies must be substantiated by technical evidence. Assessors require configuration exports, log excerpts, and live demonstrations to validate control efficacy. Configuration drift between documentation and the live system is the most frequent source of findings. Review the Information Security Manual (ISM) to ensure technical implementations align with ASD expectations.
- Implement and tune application control rulesets.
- Validate patching timeframes against Essential Eight requirements.
- Enforce multi-factor authentication for all privileged and remote access.
- Configure centralized logging with 18-month retention and alerting.
- Deploy ASD Approved Cryptographic Algorithms (AACA) for data at rest and in transit.
Identifying and Addressing Common IRAP Readiness Gaps
Undefined system boundaries and untested incident response plans routinely derail assessments. Organizations often claim compliance without the necessary log retention or multi-factor authentication enforcement. Identifying these gaps through a formal readiness review allows teams to implement remediation strategies before the assessor arrives. Ensure your environment also aligns with the Essential Eight maturity model.
Partnering with an IRAP Assessor for Success
Engaging an experienced consultancy streamlines the accreditation pathway. A preliminary IRAP readiness assessment provides actionable remediation steps tailored to your infrastructure. This proactive approach minimizes formal assessment findings and accelerates time-to-market. For primary guidance on assessor endorsement, consult the ACSC IRAP framework.
Frequently Asked Questions
Do we need to be fully compliant before engaging an assessor?
No, complete compliance is rarely achieved. Assessors expect to find residual risks. Your goal in readiness is to document those known risks accurately and implement compensating controls, preventing surprises during the formal audit.
Can we reuse ISO 27001 or SOC 2 evidence for IRAP?
While existing compliance artifacts are useful baselines, IRAP requires mapping specifically to ISM controls. You must translate and adapt your existing evidence to meet the specific technical rigor demanded by the Australian Cyber Security Centre (ACSC).
Who acts as the Authorising Officer (AO)?
The AO is a senior executive within the government agency consuming your service. They hold the ultimate authority to accept the residual risks outlined in the Security Assessment Report (SAR) and grant Authority to Operate (ATO).