Defence Industry Security Program (DISP)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DISP: ICT and Cyber Security
The entity must demonstrate that it meets or exceeds the ACSC Essential Eight mitigation strategies at Maturity Level 2 across the corporate ICT systems used to correspond with Defence.
- Essential Eight Maturity Level 2 assessment across corporate ICT
- Evidence per mitigation strategy
- Essential Eight below Maturity Level 2
- Assessment not covering the systems used with Defence
The entity must be able to detect, respond to and report cyber security incidents affecting its systems, including reporting to Defence and the ACSC as required.
- Cyber incident response plan and reporting paths to Defence/ACSC
- Records of incidents handled
- No cyber incident response capability
- No reporting path to Defence/ACSC
ICT systems that store, process or communicate security classified information must be built and operated in accordance with the Australian Government Information Security Manual (ISM) and be authorised/accredited at the appropriate level.
- ISM-aligned system documentation and authorisation/accreditation records
- System security plan for classified systems
- Classified systems not aligned to the ISM
- No authorisation/accreditation for a classified system
The entity must flow down relevant DISP and security requirements to subcontractors handling classified information, and comply with export-control and controlled-technology obligations (Defence Trade Controls / ITAR where applicable).
- Subcontractor flowdown clauses for DISP/security requirements
- Export-control/controlled-technology compliance records
- No flowdown to subcontractors handling classified information
- Export-control obligations not addressed
DISP: Membership and Security Governance
DISP membership is subject to ongoing assurance, including Defence-conducted reviews and audits of the entity's compliance with the security requirements of its membership level.
- Readiness for Defence assurance reviews/audits
- Evidence of ongoing compliance with the four-domain requirements
- No readiness for a DISP assurance review
The entity must appoint a Chief Security Officer (CSO) accountable for security across all four domains, who is an Australian citizen and security cleared as required.
- CSO appointment record with accountability for the security program
- CSO citizenship/clearance evidence
- No appointed CSO
- CSO without the required clearance/citizenship
The entity must report notifiable security incidents (including security breaches and cyber incidents) to Defence within the required timeframes.
- Incident-reporting procedure aligned to DISP notifiable-incident requirements
- Records of incidents reported to Defence
- No process to report notifiable incidents to Defence
An entity joins DISP through Defence (or a sponsoring Defence contract) and holds membership across four security domains at one of four levels aligned to Australian Government security classifications; the security governance level must equal the highest level held in any other domain.
- DISP membership confirmation and the level held per domain
- Sponsorship/eligibility evidence
- Operating without the required DISP membership level for the classified work
- Governance level lower than another domain's level
The entity must have a documented security plan, policies and processes covering governance, personnel, physical, and information/cyber security appropriate to its membership level.
- Security plan covering all four domains
- Supporting policies and procedures
- No security plan, or a plan not covering all four domains
The entity must submit an annual security report to Defence and notify reportable changes (including changes in foreign ownership, control or influence, key personnel, and security posture).
- Annual security report submissions
- Records of reportable changes notified (incl FOCI)
- Missed annual report
- Unreported reportable change or FOCI
The entity must appoint one or more Security Officers (SO) responsible for the day-to-day implementation of security across the domains.
- Security Officer appointment and responsibilities
- Contact details notified to Defence
- No appointed Security Officer
DISP: Personnel Security
Personnel must receive security awareness training appropriate to their role and the entity's membership level.
- Security awareness training records
- Role-appropriate training content
- No security awareness training program
Where access to security classified information is required, the entity must sponsor and maintain personnel security clearances through the Australian Government Security Vetting Agency (AGSVA) at the appropriate level.
- Register of cleared personnel and clearance levels
- AGSVA sponsorship and maintenance records
- Access to classified information without the required clearance
The entity must manage the personnel security lifecycle, including onboarding, ongoing suitability and insider-threat management, and offboarding (removal of access and return of assets).
- Onboarding/offboarding procedures with access provisioning/revocation
- Ongoing-suitability and insider-threat measures
- Access not revoked on offboarding
- No ongoing-suitability process
The entity must screen its workforce in accordance with the Australian Standard for Workforce Screening AS 4811:2022, appropriate to the roles and access involved.
- Workforce screening records meeting AS 4811:2022
- Screening policy
- Screening that does not meet AS 4811:2022
- Unscreened personnel with access
DISP: Physical Security
The entity must control physical access to secure areas and manage visitors and escorts to prevent unauthorised access to people, assets and classified information.
- Access-control system and records
- Visitor/escort management procedures
- Uncontrolled access to secure areas
- No visitor management
Security classified information and assets must be stored using SCEC-approved security equipment (containers, locks, etc.) appropriate to the classification.
- Inventory of SCEC-approved storage/equipment in use
- Storage matched to classification
- Storing classified assets without SCEC-approved equipment
The entity must establish security zones appropriate to the classification of information handled, with facilities certified and accredited to the required standard.
- Security-zone design and certification/accreditation records
- Facility security assessment
- Handling classified information outside an appropriately certified zone
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Defence Industry Security Program (DISP) framework page.