Knowledge / practitioner au-compliance frameworks

Protective Security Policy Framework

The Australian Government protective security policy for non-corporate Commonwealth entities. Governance, information, personnel, physical — and a cyber floor that points at Essential Eight.

The Protective Security Policy Framework (PSPF) is issued by the Attorney-General's Department. It is how non-corporate Commonwealth entities are expected to manage protective security: governance, information security, personnel security, and physical security. It is government policy, not an ISO certificate and not a substitute for the ISM on the technical controls.

Cyber sits inside that policy. ASD's report on the Commonwealth cyber security posture in 2022 recorded that, as of July 2022, it is a core PSPF requirement that entities implement the Essential Eight strategies to at least Maturity Level 2. A network's overall maturity is equal to its least mature strategy. You do not average eight scores into a vanity number.

Entities report their security posture to AGD. That reporting is how government gets an aggregated view; it is not a licence to claim maturity you cannot evidence. If you are not an NCCE, PSPF is still a useful dialect when you sell into government. It does not, by itself, make you an NCCE.

Use PSPF to name owners, record exceptions, and accept risk in writing. Use the ISM and Essential Eight for the work list. If a board paper says 'we align to PSPF' and the patching queue is a quarter long, the paper is the vulnerability.

Fact source: ASD, Commonwealth cyber security posture 2022.