Free Readiness Assessment
DISP / ISM / IRAP Defence Security Readiness Checklist
Assess your organisation's readiness for DISP membership, ISM compliance and IRAP assessment. Answer 25 questions across governance, personnel, cyber controls and evidence management — get an instant score and a branded PDF roadmap.
25 questions across 6 domains covering DISP, ISM and IRAP readiness, plus a context block.
Questions calibrated to the controls and evidence an IRAP assessor or DISP auditor will look for.
Score breakdown, priority gaps and a recommended action plan — ready for the executive or Defence contract team.
Tell us about your environment
A few details to tailor your defence security roadmap. Required fields are marked *.
Governance & DISP
DISP categories, Security Officer, and PSPF alignment.
DISP expectations vary significantly by category and level — being explicit avoids scope surprises later.
View evidence examples ->
- Documented decision on DISP membership categories and target levels.
- Rationale aligned to Defence work types and data classifications handled.
- Executive approval of DISP scope and roadmap.
Defence expects clear, named accountability for protective security matters.
View evidence examples ->
- Formal appointment letter or position description for the Security Officer role.
- Role description covering DISP, PSPF, ISM and IRAP responsibilities.
- Evidence of escalation and reporting to executive or board on security matters.
PSPF alignment underpins DISP membership and is a signal of organisational security maturity to Defence.
View evidence examples ->
- PSPF gap assessment or control mapping document.
- Action register addressing identified gaps with owners and due dates.
- Periodic review schedule as PSPF requirements change.
People & Physical Security
Clearances, onboarding/offboarding, training and facilities.
Personnel security must match the sensitivity of the information staff access — DISP auditors check this.
View evidence examples ->
- Baseline pre-employment screening for all staff and contractors.
- Active security clearances held by staff requiring access to classified material.
- Clearance register maintained with revalidation dates tracked.
Personnel changes are a key risk area for Defence engagements — leavers with residual access are a common finding.
View evidence examples ->
- Documented joiner/mover/leaver (JML) process with Defence-specific steps.
- Timely access removal and clearance suspension or transfer on exit.
- Attestation records showing offboarding checks were completed.
Training must be relevant to Defence obligations — generic cyber awareness alone is insufficient.
View evidence examples ->
- Annual security awareness training with DISP and classification-specific content.
- Targeted training for staff who handle PROTECTED or above material.
- Training completion records retained and available for audit.
Physical security controls must match the sensitivity of work performed at each location.
View evidence examples ->
- Physical security assessment completed and aligned to DISP and PSPF requirements.
- Defined security zones with appropriate access controls and visitor management.
- Secure storage for classified material (e.g. approved containers).
Cyber & ISM Controls
Classification, ISM baseline, hardening, logging and incidents.
Classification drives ISM control selection and IRAP assessment scope — confirming it early avoids costly rework.
View evidence examples ->
- Confirmed classification level (e.g. OFFICIAL, OFFICIAL: Sensitive, PROTECTED).
- Handling rules documented and communicated to relevant staff.
- Classification requirements aligned to Defence contract or Deed of Standing Offer (DSO).
ISM compliance is risk-based — but deviations must be explicit and approved, not just assumed.
View evidence examples ->
- Selected ISM baseline documented and tailored to system classification.
- A register of deviations with risk rationale and acceptance by an appropriate authority.
- Baseline reviewed when the ISM is updated or system changes occur.
Defence expects consistent, measurable cyber hygiene — inconsistent application is a common IRAP finding.
View evidence examples ->
- System hardening standards aligned to ASD ISM and Essential Eight.
- Patch and malware protection policies with defined SLAs.
- Compliance evidence from tooling (e.g. Intune, Defender, vulnerability scanner) or internal audits.
Centralised logging supports both detection during operations and evidence during IRAP assessment.
View evidence examples ->
- Central log collection in a SIEM or equivalent platform.
- Log retention periods aligned to ISM and contractual requirements.
- Evidence of monitoring cadence, alerting and response to events.
Proactive vulnerability management is expected by IRAP assessors and demonstrates ongoing risk reduction.
View evidence examples ->
- Scheduled vulnerability scans with defined frequency and scope.
- Penetration test reports where required by classification or contract.
- Remediation tracking register with closure evidence for high and critical findings.
Defence has specific notification obligations — generic IR plans often miss these.
View evidence examples ->
- Incident response plan referencing ACSC and Defence notification pathways and timeframes.
- Evidence retention procedures aligned to ISM requirements.
- Post-incident review records showing improvements actioned.
Risk & System Documentation
System description, SSP, SRMP and ATO pathway.
IRAP assessors rely heavily on accurate, up-to-date system documentation — gaps here slow assessments significantly.
View evidence examples ->
- System description document covering purpose, users and data handled.
- Architecture and data flow diagrams showing components and network boundaries.
- Dependencies and shared responsibility boundaries for cloud or third-party services.
The SSP is the core artefact for both ISM compliance and IRAP assessment — it must be current.
View evidence examples ->
- Current SSP aligned to the selected ISM control baseline.
- Named ownership for each control implementation.
- Shared responsibility statements for cloud or managed service components.
Risk decisions must be explicit and documented — verbal risk acceptance is not sufficient for Defence.
View evidence examples ->
- SRMP covering identified threats, risks and likelihood/impact ratings.
- Risk treatment plans with owners and due dates.
- Residual risk acceptance documented by an appropriate authority and reviewed regularly.
Resilience requirements increase with classification — untested backups are a common finding.
View evidence examples ->
- Defined RTO and RPO aligned to classification and contract requirements.
- Backup and DR test results documented with evidence.
- Issues identified in testing actioned and tracked to closure.
Clear ATO pathways reduce IRAP friction and avoid late-stage delays.
View evidence examples ->
- Identified Authorising Authority (AA) aligned to system classification.
- ATO briefing materials and ongoing reporting cadence agreed.
- Ongoing risk and change notification process documented.
IRAP Planning & Evidence
Scope, previous findings, evidence workspace and POA&M.
Clear scoping prevents assessment delays, rework and cost overruns.
View evidence examples ->
- Defined systems, environments and physical locations in scope.
- Agreed assessment type (gap analysis, full assessment or reassessment).
- Indicative assessment period and timeline agreed with assessor.
Outstanding findings from prior IRAPs must be addressed — assessors will review the previous report.
View evidence examples ->
- Previous IRAP report retained and accessible.
- Status register showing which recommendations have been addressed.
- Evidence of remediation progress for outstanding or partially-addressed findings.
Well-organised evidence significantly accelerates IRAP assessments and reduces assessor time.
View evidence examples ->
- Central SharePoint or equivalent evidence library mapped to ISM controls.
- Clear folder structure with version-controlled artefacts.
- Access controls configured so assessors can review without accessing production systems.
Defence expects transparent, accountable remediation tracking — informal lists are not sufficient.
View evidence examples ->
- POA&M with finding descriptions, owners, due dates and current status.
- Regular status updates reviewed by the Security Officer.
- Closure evidence retained for each finding.
Contracts, Suppliers & Hosting
Sovereign hosting, security clauses and supplier assurance.
Data sovereignty is a critical Defence consideration — offshore hosting of PROTECTED data is generally not acceptable.
View evidence examples ->
- Documented hosting locations (region, data centre) for all in-scope systems.
- Assessment against Defence and PSPF sovereign hosting requirements.
- Risk acceptance or compensating controls documented where constraints exist.
Defence security obligations must flow down through the supply chain — gaps in contracts are a liability.
View evidence examples ->
- Security and confidentiality clauses tailored to classification and DISP requirements.
- Incident notification timeframes aligned to Defence contractual obligations.
- DISP and ISM obligations explicitly included or referenced in subcontracts.
Third-party suppliers can introduce significant Defence risk — understanding shared responsibility is essential.
View evidence examples ->
- Supplier inventory with criticality ratings and data access levels.
- Defined shared responsibility matrix covering ISM controls.
- Assurance evidence (e.g. IRAP letters, ISM certifications, SOC reports) held on file.
Available once all questions are answered
Your report is ready
Your PDF has downloaded automatically. A copy of your responses has been sent to our team — we'll follow up if you'd like to discuss the results.