Australia IRAP - Information Security Registered Assessors Program
Evidence request list. 16 controls, 16 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assessment Methodology
Plan and prepare the assessment: engage the assessor, agree objectives, and obtain system documentation including the system security plan.
- Engagement/scope agreement
- System security plan and supporting documentation
- Assessment plan
- No documented assessment plan
- System security plan absent
- Objectives undefined
Define the assessment boundary and scope, identifying the assessment objects, controls and system boundary to be assessed.
- Documented assessment boundary and scope
- Identified assessment objects and applicable controls
- System boundary diagram
- Scope/boundary ambiguous
- In-scope assets not identified
- Boundary excludes relevant components
Assess the implementation and effectiveness of controls against the ISM (and other applicable Australian Government frameworks), collecting and reviewing sufficient evidence.
- Controls matrix with effectiveness findings against the ISM
- Evidence reviewed per control
- Assessment of implementation effectiveness
- Controls assessed without sufficient evidence
- Effectiveness not determined
- Assessment not tied to the ISM
Produce the IRAP Security Assessment Report (or Cloud Security Assessment Report) documenting findings, control effectiveness and residual risks.
- IRAP Security Assessment Report / Cloud SAR
- Controls matrix with findings
- Residual risk statements
- No assessment report produced
- Findings not documented per control
- Residual risks not stated
Assessment Outcomes
Determine and document the implementation effectiveness of each in-scope control as the basis for the assessment outcome.
- Per-control effectiveness determinations
- Controls matrix with ratings
- Effectiveness not determined per control
- No basis for the outcome
The assessment informs the system owner's authorisation to operate (ATO) decision; findings and residual risk support the authorising officer.
- Authorisation to operate decision record
- Residual-risk acceptance by the authorising officer
- No ATO decision
- Residual risk not accepted by an authorising officer
Support ongoing assurance through information security continuous monitoring (ISCM) and periodic reassessment of the system.
- ISCM implementation evidence
- Periodic reassessment schedule and records
- No continuous monitoring
- System not reassessed over time
Evidence and Quality
Aim for the best evidence available, distinguishing excellent, good, fair and poor evidence, with conclusions supported by sufficient-quality evidence.
- Evidence rated by quality (excellent/good/fair/poor)
- Firsthand examination/testing where possible
- Conclusions on poor/verbal evidence only
- Evidence quality not considered
Gather evidence of sufficient quality and, where sampling is required, apply and clearly explain a sound sampling methodology and sample size.
- Documented sampling methodology and size
- Representative, genuine (not staged) evidence
- Historical evidence where relevant
- Sampling methodology undocumented
- Unrepresentative or staged samples
- Sample size inadequate
Base the assessment on presented evidence and facts, ensuring depth and coverage support an accurate determination of control effectiveness.
- Depth and coverage documented per control
- Findings substantiated by evidence
- Findings not substantiated
- Insufficient depth/coverage
Where evidence does not adequately support a determination, document the limitation and assessment constraints in the Security Assessment Report and controls matrix.
- Documented evidence limitations/constraints
- Notation in the controls matrix and report
- Limitations undocumented
- Conclusions drawn despite inadequate evidence
IRAP Assessor Program
Only ASD-endorsed IRAP assessors conduct IRAP assessments; endorsement is maintained in accordance with IRAP Policy.
- Evidence of current ASD IRAP endorsement
- Endorsement maintained per IRAP Policy
- Assessment conducted by a non-endorsed assessor
- Endorsement lapsed
IRAP assessors hold the necessary experience and qualifications in ICT security assessment and risk management, with detailed knowledge of the ISM.
- Assessor CV / qualifications
- Evidence of ICT security assessment and risk-management experience
- ISM knowledge
- Insufficient assessor experience
- No demonstrated ISM knowledge
IRAP assessors complete the required IRAP New Starter Training and pass the IRAP assessor examination.
- IRAP New Starter Training completion
- IRAP examination pass record
- Training not completed
- Examination not passed
IRAP assessors declare and manage conflicts of interest and maintain independence from the system being assessed.
- Conflict-of-interest declaration
- Evidence of independence from the assessed entity
- Undeclared conflict of interest
- Assessor not independent of the system
IRAP assessors present unbiased, evidence-based findings substantiated with sufficient quality evidence, in line with the IRAP code of conduct.
- Evidence-based, substantiated findings
- Adherence to the IRAP code of conduct
- Findings not evidence-based
- Bias or unsupported conclusions
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia IRAP - Information Security Registered Assessors Program framework page.