You focus on assessing. We maintain the framework definitions, control libraries, test methods, and assessment templates that power every engagement. Always current, always consistent, always authoritative.
Framework definitions are updated as standards evolve. When ASD publishes a new ISM release or maturity model update, the latest version is available for every new assessment your organisation creates.
Controls are already mapped to a comprehensive library of asset types. Assessments start with the right scope from the beginning, eliminating manual cross-referencing and coverage gaps.
Every assessment across your organisation uses the same authoritative definitions, test methods, and templates. No drift between teams, no outdated spreadsheets.
From framework definitions to test methods and report templates, every component is expert-maintained and centrally managed so your team can focus on assessment execution.
CyberFrame maintains complete, versioned definitions for the frameworks your organisation assesses against. ISM for IRAP and CSP assessments, Essential Eight for maturity-based assessments, NIST CSF for international alignment, state-based frameworks like SACSF, and custom frameworks tailored to your specific requirements. Each framework is structured as a navigable hierarchy of groups, sections, controls, and requirements so assessors can find exactly what they need.
Every control is pre-mapped to the asset types it applies to, covering a comprehensive library of categories including servers, workstations, cloud services, network devices, databases, identity providers, and mobile devices. When an assessment begins, the relevant controls are automatically scoped to the right asset groups. No manual cross-referencing. No missed coverage. Assessors start with a complete, accurate scope from day one.
For every control-asset pairing, CyberFrame provides expert-written test methods that guide assessors through how to evaluate implementation and effectiveness. Test methods are available at multiple quality levels, giving organisations the flexibility to choose the depth of assessment appropriate to their needs. Assessors receive clear, structured guidance rather than a blank text field.
Each assessment type comes with purpose-built workflow templates that define the phases, objectives, and activities an assessment follows. IRAP assessments use IRAP-specific phases. Essential Eight assessments are structured around maturity levels. Report templates mirror each assessment type's required output format, with section hierarchies, content blocks, and data bindings pre-configured. Assessors work within a proven methodology from the moment an assessment is created.
The Framework Manager is maintained centrally by Reckon Security. When a standard is updated, the new version is published once and available for all new assessments across your organisation. There is no manual syncing, no local copies drifting out of date, and no risk of one team starting an assessment from an outdated control set while another uses the latest. Every new assessment references the same authoritative source.
Authoritative definitions for Australian and international security frameworks, with new frameworks added regularly.
The Australian Government Information Security Manual. Complete control library with classification-level applicability, powering both IRAP and Cloud Service Provider assessments.
The ASD Essential Eight Maturity Model. Eight mitigation strategies organised by maturity level with dedicated assessment and reporting methodology.
The NIST Cybersecurity Framework. Organised by function, category, and subcategory with flexible assessment depth.
SACSF, additional Australian and international standards, and support for custom framework definitions. The library is continuously expanding.
Discover how expert-maintained definitions, pre-built mappings, and structured test methods give your assessment practice a solid, consistent foundation.