← Back to Case Studies

Queensland Government — IS18 Reporting & Assurance

Blended ISO 27001 and Essential Eight assessment to deliver IS18 reporting, uplift roadmap, and evidence packs across Microsoft 365.

Sector: Government Services: IS18 Reporting, ISO 27001 Gap Assessment, ASD Essential Eight, Evidence Automation Tags: Government, IS18, ISO 27001, Essential Eight
IS18 report delivered in 4 weeks
Mapped 68 controls to ISO 27001 & E8
Evidence collection time reduced by 55%
Audit readiness score improved from 48% to 82%

At a glance

Problem

The agency had pockets of assurance work underway (policy refresh, risk register drafts, Microsoft 365 hardening), but no single view across IS18, ISO 27001 and the Essential Eight. The executive team needed a consolidated report that:

Approach

  1. Scoping & control mapping

    • Agreed IS18 scope and context, then aligned each IS18 clause with ISO 27001 domains and Essential Eight strategies.
    • Defined evidence locations across SharePoint, Entra, Defender, Intune and Purview.
  2. Rapid gap assessment (4 weeks)

    • Ran interviews and targeted sampling against ISO 27001 (scope, parties, roles, SoA) and E8 (AC, patching, macros, hardening, admin, OS patching, MFA, backups).
    • Tagged each control as Yes / Partial / No with rationale and links to source evidence.
  3. Evidence automation

    • Implemented a light-weight evidence register and scheduled exports (M365 logs, policy approvals, change records, backup reports) to support repeatable IS18 reporting.
  4. Uplift roadmap

    • Prioritised actions by risk reduction and delivery effort.
    • Sequenced activities that unlock multiple control wins (e.g., conditional access + MFA coverage; GPO/Intune baselines).

Outcome

Key Results

What we delivered

Need a similar outcome?

We help government, health, and technology organisations achieve certification faster with automated evidence and expert delivery.

Book a call