CyberFrame gives IRAP assessors a structured methodology with the complete ISM control library, per-asset-group evaluation across environments, classification-level scoping, and report templates that meet ASD formatting requirements. Run your next IRAP assessment with a platform built for it.
ISM Control Structure
Assessment Phases
The Information Security Registered Assessors Program (IRAP) is an Australian Government initiative managed by the Australian Signals Directorate (ASD). It provides a framework for assessing the security posture of systems that handle government information, ensuring they meet the requirements of the Information Security Manual (ISM).
IRAP assessments are conducted by ASD-endorsed assessors who evaluate a system's compliance with the ISM. The ISM contains over a thousand controls covering areas such as personnel security, communications infrastructure, system management, networking, and cryptography. Each control has an applicability level ranging from OFFICIAL through to TOP SECRET.
A typical IRAP assessment involves scoping the system boundary, identifying the applicable controls for the target classification level, evaluating each control across every relevant asset group and environment, collecting evidence, and producing a formal assessment report. For systems handling PROTECTED information, the assessment covers three environment scopes: administration, cloud production common, and cloud production service.
IRAP assessments are required for Australian Government systems handling classified information. They are also increasingly expected by state government agencies and private sector organisations that interact with government systems or handle sensitive government data.
The ISM contains over a thousand controls, each with classification-level applicability. An IRAP assessment requires evaluating every applicable control across each asset group and environment scope, collecting and linking evidence, and producing a report that meets ASD formatting requirements. Running this on spreadsheets means manual scoping, no methodology enforcement, fragmented evidence, and reports assembled by hand.
The full ISM control set with classification-level applicability from OFFICIAL through TOP SECRET. Controls are navigable by guideline, section, and subsection. Applicability filtering ensures assessors only see the controls relevant to their target classification level.
Evaluate each control separately for every applicable asset group across administration, cloud production common, and cloud production service environments. The three-dimensional evaluation model (control by asset group by environment) reflects how IRAP assessments actually work.
A phased workflow structured around the IRAP assessment methodology: scoping, familiarisation, detailed examination review (DER), overall examination review (OER), and reporting. Each phase defines objectives and activities to guide the assessment from start to finish.
Pre-built test methods for every control-asset pairing guide assessors through the evaluation. Multiple quality levels allow assessors to choose the depth of testing appropriate for the engagement. Assessment techniques are categorised by type: documentation review, interview, observation, and technical testing.
Report templates aligned to ASD formatting requirements with classification markings applied automatically. Data-driven sections auto-populate from evaluation data. Assessors author the narrative sections. The report structure matches what ASD expects to receive.
A dedicated portal where the assessed entity responds to information requests and submits evidence. Strict visibility rules ensure clients see only what they need. Evidence flows into the assessment with integrity verification and full chain of custody.
See how a structured platform with the complete ISM library, per-environment evaluation, and ASD-aligned reporting transforms the way you deliver IRAP assessments.