Skip to content

Evidence request lists

Defence Security Principles Framework (DSPF)

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DSPF: Defence Industry and Research Security

DSPF-P16
Defence Industry Security Program

Defence industry entities handling Defence classified information must meet the requirements of the Defence Industry Security Program (DISP) at the appropriate membership level.

Artefacts an auditor will ask for
  • DISP membership at the appropriate level
  • Flowdown of DISP requirements to relevant entities
Where this commonly fails
  • Handling Defence classified information without DISP membership
DSPF-P31
Defence research, innovation and collaboration security

Defence research, innovation and collaboration activities must apply security controls appropriate to the sensitivity of the research and the parties involved.

Artefacts an auditor will ask for
  • Security controls for research/collaboration activities
  • Assessment of collaborators and sensitivity
Where this commonly fails
  • Sensitive research collaboration without security controls

DSPF: Information Security

DSPF-P10
Classification and protection of official information

Official information must be assessed for sensitivity/classification and protected with controls commensurate with its classification across its lifecycle.

Artefacts an auditor will ask for
  • Information classification and protective-marking scheme
  • Handling controls by classification level
Where this commonly fails
  • Unclassified handling of classified information
  • No protective markings
DSPF-P13
Communications security (COMSEC)

Communications carrying official/classified information must be protected through approved cryptographic and COMSEC measures.

Artefacts an auditor will ask for
  • COMSEC and approved cryptographic measures for classified communications
Where this commonly fails
  • Classified communications without approved COMSEC
DSPF-P14
Audio-visual security

Audio-visual and conferencing environments handling classified discussions must be protected against technical and acoustic compromise.

Artefacts an auditor will ask for
  • Audio-visual/secure-conferencing protections for classified discussions
Where this commonly fails
  • Classified discussions in uncontrolled audio-visual environments
DSPF-P15
Foreign release of official information

The release of official information to foreign governments and entities must follow the foreign release and disclosure controls.

Artefacts an auditor will ask for
  • Foreign release/disclosure approvals and records
Where this commonly fails
  • Foreign release without the required approval

DSPF: Information and Technology (Cyber) Security

DSPF-P20
Information and technology security - logging and monitoring

ICT systems must implement event logging and log management sufficient to detect and investigate security events.

Artefacts an auditor will ask for
  • Log management configuration and retention for ICT systems
  • Monitoring of security-relevant events
Where this commonly fails
  • Inadequate logging on classified/ICT systems
DSPF-P21-22
Information and technology security - physical and personnel

ICT systems must be protected through physical security of equipment/facilities and through personnel security of those with privileged or system access.

Artefacts an auditor will ask for
  • Physical protection of ICT equipment
  • Personnel security for system administrators and privileged users
Where this commonly fails
  • Unprotected ICT equipment
  • Privileged access without personnel security
DSPF-P23
Cyber security assessment and authorisation

ICT systems must undergo security assessment and be formally authorised (accredited) to operate at the appropriate classification before handling official/classified information.

Artefacts an auditor will ask for
  • System security assessment and authorisation/accreditation records
  • System security plan aligned to the ISM
Where this commonly fails
  • Operating an unauthorised/unaccredited system
DSPF-P24
Information and technology security - incident management

Cyber and ICT security incidents must be detected, responded to and reported in accordance with the framework.

Artefacts an auditor will ask for
  • Cyber incident response and reporting procedures
  • Records of incidents handled and reported
Where this commonly fails
  • No cyber incident response capability
DSPF-P25
Information and technology security - gateways and data transfer

Connections between systems/domains and transfers of data across security boundaries must be controlled through approved gateways and data-transfer mechanisms.

Artefacts an auditor will ask for
  • Approved gateway and cross-domain transfer controls
  • Data import/export procedures across classifications
Where this commonly fails
  • Uncontrolled data transfer across security domains
DSPF-P26
Information and technology security - portable devices and media

Portable devices and removable media used with official/classified information must be controlled, encrypted and managed.

Artefacts an auditor will ask for
  • Portable-device/removable-media policy and encryption
  • Register of approved devices/media
Where this commonly fails
  • Unencrypted or unmanaged portable media holding classified data
DSPF-P27-29
Information and technology security - system planning, management and business impact

ICT systems must be planned, managed and operated with consideration of business impact levels, including secure configuration, change management and ongoing maintenance.

Artefacts an auditor will ask for
  • System planning and management documentation
  • Business impact assessment for ICT systems
Where this commonly fails
  • No business impact assessment
  • Unmanaged ICT system configuration/change

DSPF: Personnel Security

DSPF-P40
Personnel security clearance

Personnel requiring access to classified information or assets must hold and maintain an appropriate security clearance.

Artefacts an auditor will ask for
  • Register of cleared personnel and clearance levels
  • Clearance maintenance and revalidation records
Where this commonly fails
  • Access to classified information without the required clearance
DSPF-P41
Temporary access to classified information and assets

Where temporary access to classified information or assets is required pending clearance, it must be managed under defined conditions and supervision.

Artefacts an auditor will ask for
  • Temporary-access authorisations with conditions and supervision
  • Records of temporary access granted
Where this commonly fails
  • Unmanaged temporary access to classified information
DSPF-P42
Identity security

The identity of personnel must be established and verified to an appropriate level of assurance before granting access.

Artefacts an auditor will ask for
  • Identity verification/proofing records to the required assurance level
Where this commonly fails
  • Granting access without verifying identity
DSPF-P44
Overseas travel

Personnel with access to classified information must follow overseas travel security requirements, including pre-travel briefings and reporting.

Artefacts an auditor will ask for
  • Overseas-travel security briefings and approvals for cleared personnel
  • Travel reporting records
Where this commonly fails
  • No overseas-travel security process for cleared personnel
DSPF-P45
Contact reporting

Personnel must report contacts, approaches or relationships that may present a security concern (including foreign contact).

Artefacts an auditor will ask for
  • Contact-reporting procedure and records
Where this commonly fails
  • No contact-reporting mechanism
DSPF-P46
Counterintelligence

Defence and partners must apply counterintelligence measures to detect and mitigate espionage, foreign interference and insider threats.

Artefacts an auditor will ask for
  • Counterintelligence and insider-threat measures
  • Foreign-interference mitigation
Where this commonly fails
  • No insider-threat or counterintelligence program

DSPF: Physical Security

DSPF-PHYS-PRIN
Physical security of facilities, zones and assets

Facilities, security zones and physical assets holding classified information must be protected through certified physical security measures (zones, access control, secure storage).

Artefacts an auditor will ask for
  • Security zones and facility certification
  • Secure storage and physical access controls
Where this commonly fails
  • Classified assets held outside a certified physical environment

DSPF: Security Governance and Risk

DSPF-GOV-PRIN
Security governance, risk management and culture

Defence and its partners must establish security governance (accountable authority, roles and responsibilities), manage security risk, foster a positive security culture, and provide assurance over the security of people, information and assets.

Artefacts an auditor will ask for
  • Security governance arrangements and accountable-authority roles
  • Security risk management records and assurance reporting
Where this commonly fails
  • No accountable authority for security
  • No security risk management process
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Defence Security Principles Framework (DSPF) framework page.