Skip to content

Evidence request lists

Defence Industry Security Program (DISP)

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DISP: ICT and Cyber Security

DISP-ICT-E8
Essential Eight Maturity Level 2 on corporate ICT

The entity must demonstrate that it meets or exceeds the ACSC Essential Eight mitigation strategies at Maturity Level 2 across the corporate ICT systems used to correspond with Defence.

Artefacts an auditor will ask for
  • Essential Eight Maturity Level 2 assessment across corporate ICT
  • Evidence per mitigation strategy
Where this commonly fails
  • Essential Eight below Maturity Level 2
  • Assessment not covering the systems used with Defence
DISP-ICT-INCIDENT
Cyber incident detection and response

The entity must be able to detect, respond to and report cyber security incidents affecting its systems, including reporting to Defence and the ACSC as required.

Artefacts an auditor will ask for
  • Cyber incident response plan and reporting paths to Defence/ACSC
  • Records of incidents handled
Where this commonly fails
  • No cyber incident response capability
  • No reporting path to Defence/ACSC
DISP-ICT-ISM
Classified ICT systems aligned to the ISM (authorisation and accreditation)

ICT systems that store, process or communicate security classified information must be built and operated in accordance with the Australian Government Information Security Manual (ISM) and be authorised/accredited at the appropriate level.

Artefacts an auditor will ask for
  • ISM-aligned system documentation and authorisation/accreditation records
  • System security plan for classified systems
Where this commonly fails
  • Classified systems not aligned to the ISM
  • No authorisation/accreditation for a classified system
DISP-ICT-SUPPLYCHAIN
Supply chain, subcontractor flowdown and export controls

The entity must flow down relevant DISP and security requirements to subcontractors handling classified information, and comply with export-control and controlled-technology obligations (Defence Trade Controls / ITAR where applicable).

Artefacts an auditor will ask for
  • Subcontractor flowdown clauses for DISP/security requirements
  • Export-control/controlled-technology compliance records
Where this commonly fails
  • No flowdown to subcontractors handling classified information
  • Export-control obligations not addressed

DISP: Membership and Security Governance

DISP-GOV-ASSURANCE
Compliance, assurance and audits

DISP membership is subject to ongoing assurance, including Defence-conducted reviews and audits of the entity's compliance with the security requirements of its membership level.

Artefacts an auditor will ask for
  • Readiness for Defence assurance reviews/audits
  • Evidence of ongoing compliance with the four-domain requirements
Where this commonly fails
  • No readiness for a DISP assurance review
DISP-GOV-CSO
Chief Security Officer appointment

The entity must appoint a Chief Security Officer (CSO) accountable for security across all four domains, who is an Australian citizen and security cleared as required.

Artefacts an auditor will ask for
  • CSO appointment record with accountability for the security program
  • CSO citizenship/clearance evidence
Where this commonly fails
  • No appointed CSO
  • CSO without the required clearance/citizenship
DISP-GOV-INCIDENT
Notifiable security incident reporting

The entity must report notifiable security incidents (including security breaches and cyber incidents) to Defence within the required timeframes.

Artefacts an auditor will ask for
  • Incident-reporting procedure aligned to DISP notifiable-incident requirements
  • Records of incidents reported to Defence
Where this commonly fails
  • No process to report notifiable incidents to Defence
DISP-GOV-MEMBERSHIP
DISP membership, sponsorship and levels

An entity joins DISP through Defence (or a sponsoring Defence contract) and holds membership across four security domains at one of four levels aligned to Australian Government security classifications; the security governance level must equal the highest level held in any other domain.

Artefacts an auditor will ask for
  • DISP membership confirmation and the level held per domain
  • Sponsorship/eligibility evidence
Where this commonly fails
  • Operating without the required DISP membership level for the classified work
  • Governance level lower than another domain's level
DISP-GOV-PLAN
Security plan, policies and processes

The entity must have a documented security plan, policies and processes covering governance, personnel, physical, and information/cyber security appropriate to its membership level.

Artefacts an auditor will ask for
  • Security plan covering all four domains
  • Supporting policies and procedures
Where this commonly fails
  • No security plan, or a plan not covering all four domains
DISP-GOV-REPORT
Annual security report and reportable changes

The entity must submit an annual security report to Defence and notify reportable changes (including changes in foreign ownership, control or influence, key personnel, and security posture).

Artefacts an auditor will ask for
  • Annual security report submissions
  • Records of reportable changes notified (incl FOCI)
Where this commonly fails
  • Missed annual report
  • Unreported reportable change or FOCI
DISP-GOV-SO
Security Officer appointment

The entity must appoint one or more Security Officers (SO) responsible for the day-to-day implementation of security across the domains.

Artefacts an auditor will ask for
  • Security Officer appointment and responsibilities
  • Contact details notified to Defence
Where this commonly fails
  • No appointed Security Officer

DISP: Personnel Security

DISP-PERS-AWARENESS
Security awareness training

Personnel must receive security awareness training appropriate to their role and the entity's membership level.

Artefacts an auditor will ask for
  • Security awareness training records
  • Role-appropriate training content
Where this commonly fails
  • No security awareness training program
DISP-PERS-CLEARANCE
Security clearances (AGSVA sponsorship)

Where access to security classified information is required, the entity must sponsor and maintain personnel security clearances through the Australian Government Security Vetting Agency (AGSVA) at the appropriate level.

Artefacts an auditor will ask for
  • Register of cleared personnel and clearance levels
  • AGSVA sponsorship and maintenance records
Where this commonly fails
  • Access to classified information without the required clearance
DISP-PERS-LIFECYCLE
Onboarding, offboarding and ongoing suitability

The entity must manage the personnel security lifecycle, including onboarding, ongoing suitability and insider-threat management, and offboarding (removal of access and return of assets).

Artefacts an auditor will ask for
  • Onboarding/offboarding procedures with access provisioning/revocation
  • Ongoing-suitability and insider-threat measures
Where this commonly fails
  • Access not revoked on offboarding
  • No ongoing-suitability process
DISP-PERS-SCREEN
Workforce screening (AS 4811:2022)

The entity must screen its workforce in accordance with the Australian Standard for Workforce Screening AS 4811:2022, appropriate to the roles and access involved.

Artefacts an auditor will ask for
  • Workforce screening records meeting AS 4811:2022
  • Screening policy
Where this commonly fails
  • Screening that does not meet AS 4811:2022
  • Unscreened personnel with access

DISP: Physical Security

DISP-PHYS-ACCESS
Physical access control and visitor management

The entity must control physical access to secure areas and manage visitors and escorts to prevent unauthorised access to people, assets and classified information.

Artefacts an auditor will ask for
  • Access-control system and records
  • Visitor/escort management procedures
Where this commonly fails
  • Uncontrolled access to secure areas
  • No visitor management
DISP-PHYS-STORAGE
Secure storage and SCEC-approved equipment

Security classified information and assets must be stored using SCEC-approved security equipment (containers, locks, etc.) appropriate to the classification.

Artefacts an auditor will ask for
  • Inventory of SCEC-approved storage/equipment in use
  • Storage matched to classification
Where this commonly fails
  • Storing classified assets without SCEC-approved equipment
DISP-PHYS-ZONES
Security zones and facility certification

The entity must establish security zones appropriate to the classification of information handled, with facilities certified and accredited to the required standard.

Artefacts an auditor will ask for
  • Security-zone design and certification/accreditation records
  • Facility security assessment
Where this commonly fails
  • Handling classified information outside an appropriately certified zone
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Defence Industry Security Program (DISP) framework page.