Defence Security Principles Framework (DSPF)
Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DSPF: Defence Industry and Research Security
Defence industry entities handling Defence classified information must meet the requirements of the Defence Industry Security Program (DISP) at the appropriate membership level.
- DISP membership at the appropriate level
- Flowdown of DISP requirements to relevant entities
- Handling Defence classified information without DISP membership
Defence research, innovation and collaboration activities must apply security controls appropriate to the sensitivity of the research and the parties involved.
- Security controls for research/collaboration activities
- Assessment of collaborators and sensitivity
- Sensitive research collaboration without security controls
DSPF: Information Security
Official information must be assessed for sensitivity/classification and protected with controls commensurate with its classification across its lifecycle.
- Information classification and protective-marking scheme
- Handling controls by classification level
- Unclassified handling of classified information
- No protective markings
Communications carrying official/classified information must be protected through approved cryptographic and COMSEC measures.
- COMSEC and approved cryptographic measures for classified communications
- Classified communications without approved COMSEC
Audio-visual and conferencing environments handling classified discussions must be protected against technical and acoustic compromise.
- Audio-visual/secure-conferencing protections for classified discussions
- Classified discussions in uncontrolled audio-visual environments
The release of official information to foreign governments and entities must follow the foreign release and disclosure controls.
- Foreign release/disclosure approvals and records
- Foreign release without the required approval
DSPF: Information and Technology (Cyber) Security
ICT systems must implement event logging and log management sufficient to detect and investigate security events.
- Log management configuration and retention for ICT systems
- Monitoring of security-relevant events
- Inadequate logging on classified/ICT systems
ICT systems must be protected through physical security of equipment/facilities and through personnel security of those with privileged or system access.
- Physical protection of ICT equipment
- Personnel security for system administrators and privileged users
- Unprotected ICT equipment
- Privileged access without personnel security
ICT systems must undergo security assessment and be formally authorised (accredited) to operate at the appropriate classification before handling official/classified information.
- System security assessment and authorisation/accreditation records
- System security plan aligned to the ISM
- Operating an unauthorised/unaccredited system
Cyber and ICT security incidents must be detected, responded to and reported in accordance with the framework.
- Cyber incident response and reporting procedures
- Records of incidents handled and reported
- No cyber incident response capability
Connections between systems/domains and transfers of data across security boundaries must be controlled through approved gateways and data-transfer mechanisms.
- Approved gateway and cross-domain transfer controls
- Data import/export procedures across classifications
- Uncontrolled data transfer across security domains
Portable devices and removable media used with official/classified information must be controlled, encrypted and managed.
- Portable-device/removable-media policy and encryption
- Register of approved devices/media
- Unencrypted or unmanaged portable media holding classified data
ICT systems must be planned, managed and operated with consideration of business impact levels, including secure configuration, change management and ongoing maintenance.
- System planning and management documentation
- Business impact assessment for ICT systems
- No business impact assessment
- Unmanaged ICT system configuration/change
DSPF: Personnel Security
Personnel requiring access to classified information or assets must hold and maintain an appropriate security clearance.
- Register of cleared personnel and clearance levels
- Clearance maintenance and revalidation records
- Access to classified information without the required clearance
Where temporary access to classified information or assets is required pending clearance, it must be managed under defined conditions and supervision.
- Temporary-access authorisations with conditions and supervision
- Records of temporary access granted
- Unmanaged temporary access to classified information
The identity of personnel must be established and verified to an appropriate level of assurance before granting access.
- Identity verification/proofing records to the required assurance level
- Granting access without verifying identity
Personnel with access to classified information must follow overseas travel security requirements, including pre-travel briefings and reporting.
- Overseas-travel security briefings and approvals for cleared personnel
- Travel reporting records
- No overseas-travel security process for cleared personnel
Personnel must report contacts, approaches or relationships that may present a security concern (including foreign contact).
- Contact-reporting procedure and records
- No contact-reporting mechanism
Defence and partners must apply counterintelligence measures to detect and mitigate espionage, foreign interference and insider threats.
- Counterintelligence and insider-threat measures
- Foreign-interference mitigation
- No insider-threat or counterintelligence program
DSPF: Physical Security
Facilities, security zones and physical assets holding classified information must be protected through certified physical security measures (zones, access control, secure storage).
- Security zones and facility certification
- Secure storage and physical access controls
- Classified assets held outside a certified physical environment
DSPF: Security Governance and Risk
Defence and its partners must establish security governance (accountable authority, roles and responsibilities), manage security risk, foster a positive security culture, and provide assurance over the security of people, information and assets.
- Security governance arrangements and accountable-authority roles
- Security risk management records and assurance reporting
- No accountable authority for security
- No security risk management process
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Defence Security Principles Framework (DSPF) framework page.