Information Security Registered Assessors Program
(IRAP)
Overview
The Information Security Registered Assessors Program (IRAP) enables Australian Government customers to validate that appropriate controls are in place and determine the appropriate responsibility model for addressing the requirements of the Australian Government Information Security Manual (ISM) produced by the Australian Cyber Security Centre (ACSC).
Protecting Australian Government data from access, unauthorized and disclosure remains a prime consideration when procuring and leveraging cloud services. AWS recognises that customers rely upon the secure delivery of the AWS infrastructure and the importance of having features that enable them to create secure environments. AWS enables customers to meet these objectives by prioritising security in the delivery of its services, through the establishment of a robust control environment, and by making available for use a wide range of security services and features.
The in scope AWS Cloud services that have been IRAP assessed can be found on AWS Services in Scope by Compliance Program. An independent IRAP assessor examined the AWS controls including people, processes, and technology against the requirements of the ISM. If you would like to learn more about using these services and/or have an interest in other services please contact us.
General FAQs
Open all- Close the CSCP and create new co-designed cloud security guidelines with industry
- Grow and enhance IRAP
- Establish Government and Industry Consultative Forums for cyber security
- Update incentives in Procurement and Administrative Instructions and Guidance to reflect the cessation of the CSCP
On Monday, 2 March 2020 the Australian Signals Directorate (ASD) and the Digital Transformation Agency (DTA) announced the results of the review of the Cloud Services Certification Program (CSCP) and Information Security Registered Assessors Program (IRAP). The review made the following recommendations:
As of March 2, 2020, the ASD is no longer be the Certification Authority and has ceased all certification activities, including re-certification activities. All ASD certifications and re-certification letters will be void from July 27, 2020 and the Australian government Information Security Manual (ISM) has been updated to remove the requirement to select cloud services from the Certified Cloud Services List (CCSL).
Under the Australian government Secure Cloud Strategy, Commonwealth agencies are able to self assess cloud services using practices already used to assess ICT systems.
What now:
On July 27, 2020, the Australian Cyber Security Centre (ACSC) and the Digital Transformation Agency (DTA) released new Cloud Security Guidance co-designed with industry to support the secure adoption of cloud services across government and industry. AWS continues to undertake IRAP assessments to maintain currency of the assessment and to onboard new services. Commonwealth entities will continue to be responsible for their own assurance and risk management activities. In accordance with the Australian government Secure Cloud Strategy, Commonwealth entities are able to self-assess cloud services using practices already used to assess ICT systems. ASD will enhance existing cloud security guidance through the development of co-designed guidelines with industry. These guidelines will further aid Commonwealth entities and Australian businesses to increase their cyber security and resilience.
To date, ASD has developed a number of useful guides for organisations to undertake the appropriate security assessments in relation to cloud services. It is recommended that any assessment clearly addresses the security controls in the ISM, and ASD cloud security guidance, including:
The DTA continues to encourage Commonwealth agencies to use the Australian government Secure Cloud Strategy to support their adoption of cloud services.
In support of our Australian government customers, we provide a package of security guidance and documentation to enhance your understanding of security and compliance while using AWS. AWS provides the following publicly available material: