IRAP ISM security testing is how Australian government systems, and the suppliers that serve them, gain confidence that their security controls actually work against the requirements of the Information Security Manual. IRAP, the Infosec Registered Assessors Program, endorses independent assessors to evaluate systems against the ISM, and well-scoped offensive security testing is one of the most effective ways to prepare for and strengthen that process.
This guide explains how IRAP, the ISM and the Protective Security Policy Framework fit together, what they mean for government and government suppliers, and how IRAP-aligned testing supports compliance. It is important to be precise here: StrikeCyber delivers IRAP-aligned testing and supports IRAP assessments, but StrikeCyber does not perform IRAP assessments and is not an IRAP assessor.
Understanding IRAP, the ISM and the PSPF
These three terms are often used together, but they play distinct roles. Understanding the difference makes it much easier to know what applies to you.
- The Protective Security Policy Framework, or PSPF, sets the Australian Government's overarching protective security policy across governance, information, personnel and physical security.
- The Information Security Manual, or ISM, provides the detailed, risk-based cyber security controls that support the information security elements of the PSPF. It is published and regularly updated by the Australian Signals Directorate.
- IRAP, the Infosec Registered Assessors Program, is the program of endorsed assessors who independently evaluate whether a system meets the ISM.
Put simply, the PSPF sets policy, the ISM sets the technical controls, and IRAP is how those controls are independently assessed. Security testing sits underneath all three, providing the practical evidence that controls are implemented and effective.
What an IRAP Assessment Involves
An IRAP assessment is conducted by an ASD-endorsed assessor. The assessor independently examines whether a system's security controls are implemented correctly and operating effectively against the relevant ISM requirements. The output is a report that helps the system owner make an informed, risk-based decision about authorising the system to operate.
Key points to understand about the assessment itself:
- It is carried out by an endorsed IRAP assessor, not by any security firm that chooses to describe its work as IRAP related.
- It results in documentation the system owner uses to support an authorisation decision.
- It reflects a point in time, so the underlying security posture must be maintained afterwards.
To be clear about roles, StrikeCyber does not conduct this assessment and is not an IRAP assessor. Where a formal IRAP assessment is required, it must be performed by an endorsed assessor. What StrikeCyber offers is the testing that makes that assessment stronger and smoother.
Where IRAP-Aligned Testing Fits
IRAP-aligned testing means offensive security work scoped and reported against the relevant ISM controls, so that it directly supports a formal assessment rather than running parallel to it. This is genuinely valuable because an IRAP assessment is far easier when the technical weaknesses have already been found and fixed.
IRAP-aligned penetration testing helps by:
- Surfacing real, exploitable weaknesses in systems that will be assessed, before an endorsed assessor examines them.
- Mapping findings to the ISM controls they affect, so remediation is targeted and traceable.
- Providing evidence that technical controls operate effectively in practice, not just on paper.
- Reducing the likelihood of significant findings during the formal assessment.
This does not replace the IRAP assessment. It prepares you for it, so the endorsed assessor finds a system that is already in good shape.
Testing Detection and Response
The ISM covers far more than preventive controls. Detection, response and recovery all matter, and government systems are attractive targets for capable adversaries. Testing whether your organisation can detect and respond to an intrusion is therefore an important complement to control-by-control verification.
A red team engagement exercises this end to end. Rather than checking individual controls in isolation, it simulates a realistic adversary attempting to achieve defined objectives, testing:
- Whether malicious activity is detected by your monitoring and people.
- How quickly and effectively your teams respond once something is noticed.
- Whether layered controls hold when an attacker chains weaknesses together.
For government and suppliers, this kind of testing produces evidence that the human and procedural side of the ISM, not only the technical configuration, stands up under pressure.
What This Means for Government Suppliers
The ISM and PSPF increasingly reach beyond agencies themselves. Contracts and connection requirements often flow relevant controls down to suppliers who store, process or access government information, or who connect to government systems. The precise obligations depend on the sensitivity of the data and the nature of the engagement.
If you are a supplier aiming to work with government, it pays to:
- Understand which ISM controls are likely to apply to your systems and services early.
- Test your systems against those controls before a formal assessment becomes a contractual gate.
- Remediate weaknesses methodically, with evidence, so you can demonstrate a mature posture.
- Plan for detection and response, so you can meet expectations if an incident occurs.
Knowing where you stand is the first step. A security maturity assessment benchmarks your current controls and governance, helping you target the gaps that matter most before you invest in a full assessment cycle.
Preparing for an Incident
No control set eliminates risk entirely, and government-facing systems are high-value targets. A rehearsed response capability is part of meeting ISM expectations and, just as importantly, part of protecting the information you are trusted with. Aligning your testing outcomes with your incident response planning ensures the weaknesses you discover inform how you would detect, contain and recover from a real event.
Common Mistakes to Avoid
Organisations preparing for an IRAP assessment often make the same avoidable errors, which turn what should be a confirmation of good security into a stressful discovery of gaps. Watching for these pitfalls saves time, cost and reputation:
- Confusing IRAP-aligned testing with an IRAP assessment itself. The two are complementary, but only an endorsed assessor can conduct the formal assessment.
- Leaving testing until immediately before the assessment, when there is no time left to remediate the weaknesses it surfaces.
- Scoping testing to a narrow slice of the system while the assessment considers the whole, so significant findings appear where no one looked.
- Treating the ISM as a purely technical checklist and neglecting the governance, personnel and detection elements it and the PSPF also expect.
- Failing to map findings to specific ISM controls, which makes remediation harder to track and evidence harder to present.
The strongest approach is to test early, map findings to the relevant controls, remediate methodically, and then retest to confirm the fixes hold. By the time an endorsed assessor arrives, the system should already reflect the posture the ISM requires, so the assessment validates good work rather than uncovering surprises.
Getting IRAP-Aligned Testing Right
The organisations that navigate IRAP well treat the formal assessment as the endpoint of good security work, not the beginning. They test honestly against the ISM, fix what they find, and arrive at the assessment with evidence that their controls hold. IRAP-aligned testing is how they get there.
If you need IRAP-aligned penetration testing or red teaming to support an upcoming assessment, our team of expert operators can help you scope and report the work against the relevant ISM controls. To be clear, we do not perform IRAP assessments; we strengthen the systems that those assessments examine. Explore our penetration testing services, review our red teaming capability, or get in touch for a scoping conversation. You can also call StrikeCyber on 1300 654 898.
Frequently asked questions
What is IRAP?
IRAP is the Infosec Registered Assessors Program, run by the Australian Signals Directorate. It endorses suitably qualified individuals to provide independent assessments of whether a system's security controls are implemented and operating effectively against the requirements of the Information Security Manual. An IRAP assessment produces a report that helps a system owner make an informed, risk-based decision about authorising a system to operate.
What is the ISM?
The Information Security Manual is the Australian Government's cyber security framework, published and regularly updated by the Australian Signals Directorate. It provides a risk-based set of controls that organisations can apply to protect their systems and data. The ISM is used by government agencies and, increasingly, by suppliers and contractors who handle government information or connect to government systems, as the baseline against which security is measured.
Does StrikeCyber perform IRAP assessments?
No. StrikeCyber does not perform IRAP assessments and is not an IRAP assessor. What StrikeCyber provides is IRAP-aligned security testing, meaning penetration testing and red teaming scoped and reported against the relevant ISM controls. This work supports and strengthens a formal IRAP assessment carried out by an endorsed assessor, by surfacing and helping remediate real weaknesses before the assessment takes place.
What is the difference between IRAP and the PSPF?
The Protective Security Policy Framework sets the Australian Government's overarching protective security policy across governance, information, personnel and physical security. The ISM provides the detailed cyber security controls that support the information security elements of the PSPF. IRAP is the program of endorsed assessors who evaluate systems against the ISM. In short, the PSPF sets policy, the ISM sets technical controls, and IRAP assesses whether those controls are met.
Do government suppliers need to meet the ISM?
Increasingly, yes. Contracts and connection requirements often flow ISM controls and PSPF expectations down to suppliers who store, process or access government information. The exact requirements depend on the sensitivity of the data and the nature of the engagement. Suppliers who want to work with government are well served by understanding the relevant controls early and testing their systems against them before a formal assessment is required.
How does testing help before an IRAP assessment?
IRAP-aligned penetration testing and red teaming find and help you fix real weaknesses before an endorsed assessor examines your system. This reduces the risk of significant findings during the formal assessment, gives you evidence that technical controls work in practice, and helps you prioritise remediation. It does not replace the IRAP assessment itself, but it makes the assessment smoother and the outcome stronger.
