Knowledge / practitioner au-compliance frameworks cloud

IRAP

Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud services against the ISM. An IRAP report is evidence, not an authorisation.

IRAP is ASD's Infosec Registered Assessors Program. ASD endorses suitably qualified professionals to assess ICT systems, cloud services, and gateways against the Information Security Manual. The assessor writes a report. The system owner still authorises the system. Buying an IRAP-assessed cloud service does not transfer that authorisation, or the residual risk, to the provider.

For Commonwealth use of outsourced cloud and managed services, the ISM requires IRAP assessment on a cycle. Controls in the procurement and outsourcing guidelines (including ISM-1570 and ISM-1793) call for IRAP assessment of those services, using a current ISM, at least every 24 months at the relevant classification, with TOP SECRET handled by ASD assessors or their delegates rather than IRAP.

ASD's cloud assessment FAQ is blunt: international certifications (FedRAMP, EU cloud schemes, and the rest) do not replace an IRAP assessment against the ISM for Commonwealth entities. Assessors may reuse evidence from other certifications where it is applicable, accurate, and valid — including checking the assessment boundary. That is reuse of evidence, not a stamp.

Read an IRAP report for scope, date, classification, residual risks, and what was out of scope. A two-year-old report on a different region or a subset of services is a starting point, not a current control. Ask for the residual-risk table. If the provider will not show it, you do not have assurance. You have marketing.

Fact source: ACSC, cloud assessment and authorisation FAQ.