Skip to content

Evidence request lists

Protective Security Policy Framework (PSPF) Release 2024

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Governance and Culture

PSPF24-1
Security Culture, Governance, Risk Management

Per Australian Protective Security Policy Framework (PSPF) Release 2024 Governance: security culture + governance. Requirements include (a) develop + maintain Security Culture across entity + (b) implement Security Risk Management including identification + treatment + (c) integrate with enterprise risk management + (d) maintain Chief Security Officer (CSO) role + governance + (e) implement security planning + reporting + (f) cooperate with Commonwealth Security Advisor + AGSVA.

Artefacts an auditor will ask for
  • PSPF evidence for PSPF24-1
Where this commonly fails
  • Essential Eight maturity + clearances + zones partial

Incident Response

PSPF24-5
Information and Cyber Incidents

Per PSPF Incidents: handle security incidents. Requirements include (a) operate incident response capability including detection + triage + containment + recovery + lessons learned + (b) notify ASD ACSC + AFP per requirements + (c) maintain incident log + reporting + (d) implement business continuity + disaster recovery + (e) maintain documented IR + (f) align with broader Commonwealth incident reporting.

Artefacts an auditor will ask for
  • PSPF evidence for PSPF24-5
Where this commonly fails
  • Essential Eight maturity + clearances + zones partial

Information Security

PSPF24-2
Information Security, Cybersecurity Maturity, Essential Eight

Per PSPF Information Security: protect official information. Requirements include (a) implement Essential Eight Maturity Model aligned to data sensitivity + (b) implement Information Security Manual (ISM) controls + (c) protect classified information per Australian Government classification scheme + (d) implement encryption + access control + monitoring + (e) align with Cyber Security Strategy + ACSC guidance + (f) maintain documented security baseline.

Artefacts an auditor will ask for
  • PSPF evidence for PSPF24-2
Where this commonly fails
  • Essential Eight maturity + clearances + zones partial

Information Security Policies (5 to 9)

PSPF-2024-POL-5
Policy 5: Classification system

Information must be classified according to the harm that could result from its compromise, with markings applied consistently and only by authorised originators.

Artefacts an auditor will ask for
  • Originator authority register
  • Marking and protective markings procedure
  • Tooling configuration enforcing marking on email and documents
  • Reclassification log with rationale and approval
  • Sample audit of documents for correct marking
Where this commonly fails
  • Originators not trained, leading to over- or under-classification
  • Marking tools deployed inconsistently across business units
  • Reclassification ad hoc with no documented decision trail
PSPF-2024-POL-6
Policy 6: Sensitive and classified information access

Access to sensitive and classified information must be limited to personnel with appropriate clearance, a demonstrated need-to-know, and an acknowledgement of their information handling responsibilities.

Artefacts an auditor will ask for
  • Clearance management system and verification process
  • Need-to-know matrix mapping roles to information categories
  • Signed acknowledgement of handling obligations
  • Access review logs showing periodic reauthorisation
  • Breach handling procedure for unauthorised access
Where this commonly fails
  • Need-to-know justified by role, not specific business purpose
  • Acknowledgements signed once at induction and never refreshed
  • Access reviews conducted yearly only, missing role changes mid-year
PSPF-2024-POL-7
Policy 7: Security governance for ICT systems

Entities must ensure that ICT systems holding official information are governed in accordance with the Information Security Manual, with documented authorisation to operate by the Accountable Authority or delegate.

Artefacts an auditor will ask for
  • System Security Plan (SSP) per system
  • Authority to Operate (ATO) letter signed by Accountable Authority or delegate
  • Annual ISM compliance assessment results
  • Continuous monitoring report including vulnerability scans
  • Change control records for security-relevant changes
Where this commonly fails
  • ATO issued years ago and not refreshed after major changes
  • ISM assessment performed by the same team that built the system
  • Continuous monitoring metrics not reviewed by the Accountable Authority
PSPF-2024-POL-8
Policy 8: Sensitive and classified information sharing

Entities must apply caveats and releasability markings, and ensure that sharing arrangements with other entities, contractors, and foreign partners include controls consistent with PSPF requirements.

Artefacts an auditor will ask for
  • Information sharing agreements with other entities and partners
  • Caveat and releasability register
  • Foreign government information handling procedures
  • Contractor security clauses in procurement contracts
  • Audit log of information shared and recipient acknowledgements
Where this commonly fails
  • Sharing agreements signed but not refreshed in years
  • Caveats applied inconsistently across business units
  • Contractors handling classified data without subcontractor flow-down
PSPF-2024-POL-9
Policy 9: Access to information

Eligibility for security clearance must be based on Australian citizenship (with documented exceptions), favourable character checks, and the entity's assessment that the person can be entrusted with the relevant level of classified information.

Artefacts an auditor will ask for
  • Eligibility matrix per clearance level
  • Character assessment template and case records
  • Citizenship and residency verification procedure
  • Documented exceptions approved at appropriate level
  • Periodic review of clearance holders
Where this commonly fails
  • Citizenship exceptions granted without documented rationale
  • Character assessment not refreshed when major life events occur
  • Periodic review limited to expiry checks

Personnel Security

PSPF24-3
Personnel Security and Vetting

Per PSPF Personnel Security: vet + manage personnel. Requirements include (a) implement pre-engagement screening + AGSVA security clearances per role requirements + (b) ongoing personnel security including aftercare + reportable incidents + (c) implement insider threat programme + (d) maintain offboarding + access revocation + (e) implement training + awareness on personnel security obligations + (f) maintain records.

Artefacts an auditor will ask for
  • PSPF evidence for PSPF24-3
Where this commonly fails
  • Essential Eight maturity + clearances + zones partial

Personnel Security Policies (10 to 12)

PSPF-2024-POL-10
Policy 10: Ongoing suitability for personnel

Entities must implement ongoing suitability procedures that detect, assess, and manage changes in personnel circumstances that may impact their continued suitability to access Australian Government resources.

Artefacts an auditor will ask for
  • Ongoing suitability policy with defined trigger events
  • Reporting channels for personnel to declare changes
  • Assessment framework for changes (financial, personal, behavioural)
  • Case management records with outcomes
  • Annual programme report to the Accountable Authority
Where this commonly fails
  • Personnel unaware of obligation to self-report changes
  • Assessments rely on subjective judgement without a framework
  • Cases closed without recording residual risk
PSPF-2024-POL-11
Policy 11: Managing security clearances

Entities must manage clearances actively, including timely revalidation, transfer or sharing of clearances, and revocation when an individual no longer requires or warrants the clearance.

Artefacts an auditor will ask for
  • Clearance lifecycle procedure
  • Transfer and sharing agreements with other entities
  • Revocation workflow with HR and legal involvement
  • Clearance register reconciled with AGSVA
  • Briefing and debriefing records
Where this commonly fails
  • Clearance register out of sync with AGSVA records
  • Revocations delayed after staff departure
  • Briefings and debriefings not documented
PSPF-2024-POL-12
Policy 12: Eligibility and suitability of contractors

Entities must ensure contractors and service providers accessing official resources meet equivalent eligibility, suitability, and ongoing assessment standards as direct employees.

Artefacts an auditor will ask for
  • Standard security clauses in contracts
  • Contractor screening records
  • Audit results of contractor compliance
  • Termination and offboarding procedures
  • Register of contractor personnel with access
Where this commonly fails
  • Security clauses present in head contract but not flowed down
  • Contractor screening evidence held by vendor and not auditable
  • Offboarding delays leaving contractor accounts active

Physical Security

PSPF24-4
Physical Security

Per PSPF Physical Security: secure physical environment. Requirements include (a) implement physical security including perimeter + access control + monitoring + (b) implement secure zones (Zone 1-5 per PSPF) for classified handling + (c) implement secure transport + storage + handling + (d) maintain physical access logging + monitoring + (e) implement environmental controls + (f) maintain documented physical security plan.

Artefacts an auditor will ask for
  • PSPF evidence for PSPF24-4
Where this commonly fails
  • Essential Eight maturity + clearances + zones partial

Physical Security Policies (13 to 15)

PSPF-2024-POL-13
Policy 13: Entity facilities

Entities must apply physical security controls to facilities, including zoning, perimeter security, access control, and intruder detection, proportionate to the threat and the classification of information held.

Artefacts an auditor will ask for
  • Facility zoning diagrams
  • Perimeter and access control specifications
  • Intruder detection system configuration and test logs
  • After-hours security procedures
  • Security construction certification for higher zones
Where this commonly fails
  • Higher zones built before PSPF 2024 and not reassessed
  • Access control logs not reviewed for anomalies
  • Intruder detection tested annually rather than monthly
PSPF-2024-POL-14
Policy 14: Security of physical assets

Entities must protect physical assets including ICT equipment, security containers, keys, and devices storing classified information, with controls for handling, storage, and disposal.

Artefacts an auditor will ask for
  • Asset register including classified ICT equipment
  • Key and combination management procedure
  • Security container inspection log
  • Disposal and destruction certificates
  • Sanitisation records aligned to ISM
Where this commonly fails
  • Key registers maintained on paper and rarely audited
  • Disposal of devices done without certificates
  • Container inspection records missing for off-site storage
PSPF-2024-POL-15
Policy 15: Physical security planning

Physical security must be integrated into property planning from project initiation, including site selection, design, construction, and changes to tenancy or operations.

Artefacts an auditor will ask for
  • Property project security checklist
  • Site selection risk assessment
  • Design review records signed off by CSO
  • Construction sign-off including secure spaces
  • Change management records for tenancy and fit-out changes
Where this commonly fails
  • Security engaged late in property projects, requiring rework
  • Site selection criteria omit threat environment
  • Tenancy changes proceed without security review

Secretaries Directions

PSPF-DIR-001-2024
Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets

Requires entities to identify indicators of Foreign Ownership, Control or Influence (FOCI) risk in procurement and maintenance of technology assets, and appropriately manage and report those risks.

Artefacts an auditor will ask for
  • Foreign ownership register
  • Influence assessment report
  • Compliance attestation
  • Vendor declaration records
Where this commonly fails
  • Register incomplete
  • No influence assessment
  • Attestation not submitted
PSPF-DIR-002-2024
Direction 002-2024: Technology Asset Stocktake

Requires entities to conduct a comprehensive stocktake of technology assets to understand technology exposure and risk.

Artefacts an auditor will ask for
  • Technology asset register
  • Stocktake report
  • Reconciliation evidence
  • Asset lifecycle records
Where this commonly fails
  • Register stale
  • Stocktake not performed annually
  • Reconciliation gaps
PSPF-DIR-003-2024
Direction 003-2024: Mitigation of Technology Risks

Requires entities to mitigate identified risks from technology assets associated with foreign interference.

Artefacts an auditor will ask for
  • Technology risk register
  • Mitigation plan
  • Direction status report
  • Executive briefing
Where this commonly fails
  • Mitigation actions overdue
  • No executive briefing
  • Status report missing

Security Governance Policies (1 to 4)

PSPF-2024-POL-1
Policy 1: Roles and responsibilities

The Accountable Authority is responsible for the entity's protective security and must appoint a Chief Security Officer (CSO) at the SES Band 2 level or equivalent, with clear delegations for security advisors.

Artefacts an auditor will ask for
  • Letter of appointment for the CSO
  • Delegation instrument covering security decisions
  • Position descriptions for CSO, ASO, ITSA, and PSO roles
  • Annual attestation from the Accountable Authority
  • Succession plan for the CSO role
Where this commonly fails
  • CSO appointed below the required SES level
  • Delegations not refreshed when key staff leave
  • Annual attestation signed without supporting evidence pack
PSPF-2024-POL-2
Policy 2: Management structures and responsibilities

Entities must implement security management structures and processes that integrate protective security into governance, risk, planning, and assurance activities, including reporting to the Accountable Authority.

Artefacts an auditor will ask for
  • Security integration plan with corporate governance, audit, and risk functions
  • Internal assurance plan covering all four PSPF outcomes
  • Organisational chart showing security reporting lines
  • Security inputs into the annual planning cycle
  • Internal audit reports covering protective security
Where this commonly fails
  • Security plan disconnected from corporate plan
  • Internal audit covers ICT only, missing physical and personnel security
  • No clear escalation path to the Accountable Authority for material risks
PSPF-2024-POL-3
Policy 3: Security planning and risk management

Entities must develop and implement a security plan informed by an enterprise security risk assessment, addressing risks across information, personnel, and physical security, and reviewed at least annually.

Artefacts an auditor will ask for
  • Enterprise security risk assessment report
  • Approved security plan with control mapping
  • Annual review log of the plan with date and approver
  • Risk treatment register and progress reporting
  • Briefings to senior executives on residual risk
Where this commonly fails
  • Risk assessment focuses on cyber and ignores insider or physical threats
  • Security plan exists but lacks measurable controls and owners
  • Annual review skipped or compressed without evidence
PSPF-2024-POL-4
Policy 4: Security maturity monitoring

Entities must monitor and report their security maturity against PSPF outcomes annually to the Attorney-General's Department, including against Essential Eight cyber controls where applicable.

Artefacts an auditor will ask for
  • PSPF maturity self-assessment workbook
  • Annual PSPF report submission acknowledgement
  • Essential Eight maturity assessment per applicable system
  • Evidence library underpinning self-assessment scores
  • Improvement plan to address gaps identified
Where this commonly fails
  • Maturity ratings inflated relative to evidence on file
  • Essential Eight maturity assessed only on corporate ICT, missing operational systems
  • Improvement plan not tracked in subsequent cycles

Security Incident Policy (16)

PSPF-2024-POL-16
Policy 16: Reporting and management of security incidents

Entities must report and manage security incidents involving people, information, and physical assets, including notifications to relevant authorities such as ASIO, ACSC, and AGSVA, with lessons captured back into the risk programme.

Artefacts an auditor will ask for
  • Security incident response plan
  • Incident register covering all four outcomes
  • Notification records to ASIO, ACSC, AGSVA where required
  • Post-incident review and improvement actions
  • Annual incident statistics reported to the Accountable Authority
Where this commonly fails
  • Incident register only captures cyber events, missing physical and personnel
  • Notification thresholds not defined for each authority
  • Lessons learned not closed out in improvement plans

Security Outcomes

PSPF-2024-OUTCOME-1
Security Governance Outcome

Entities must take a risk-based approach to protective security, with clear governance, accountability, and performance reporting that drives continuous improvement across security functions.

Artefacts an auditor will ask for
  • Accountable Authority security policy statement
  • Protective security governance committee terms of reference and minutes
  • Enterprise security risk register aligned to PSPF outcomes
  • Annual PSPF maturity self-assessment submitted via the PSPF reporting portal
  • Performance reporting dashboard for the four outcomes
Where this commonly fails
  • Governance committee exists in name but does not review risks each cycle
  • Risk register treats security as IT-only and excludes personnel and physical
  • Self-assessment overstates maturity without underlying evidence
PSPF-2024-OUTCOME-2
Information Security Outcome

Entities must safeguard official information consistent with its sensitivity and security classification, throughout its lifecycle and across people, processes, and systems.

Artefacts an auditor will ask for
  • Information classification policy aligned to PSPF and the Australian Government PSPF Information Management Framework
  • Handling guides for OFFICIAL, PROTECTED, SECRET, and TOP SECRET
  • Records management lifecycle procedures
  • Information asset register with classification
  • Training records on handling classified information
Where this commonly fails
  • Classification policy not updated for PSPF Release 2024 changes
  • Inconsistent marking of emails and documents in practice
  • No process to declassify or reclassify information over time
PSPF-2024-OUTCOME-3
Personnel Security Outcome

Entities must ensure their personnel are suitable to access Australian Government resources and continue to meet this requirement throughout their engagement, with controls for ongoing suitability and insider risk.

Artefacts an auditor will ask for
  • Pre-employment screening policy and records
  • AGSVA clearance request and renewal records
  • Ongoing suitability programme procedures and case files
  • Insider risk programme charter and risk indicators
  • Separation and return of asset procedures
Where this commonly fails
  • Pre-employment screening limited to identity and right-to-work checks
  • Ongoing suitability programme exists on paper but rarely triggers actions
  • Insider risk programme not coordinated with HR and legal
PSPF-2024-OUTCOME-4
Physical Security Outcome

Entities must protect their people, information, and physical assets through proportionate physical security measures aligned to the threat environment and the sensitivity of holdings.

Artefacts an auditor will ask for
  • Site security risk assessment per facility
  • Physical security plan with zoning
  • Maintenance and testing schedule for physical controls
  • Incident records and lessons learned
  • Visitor management procedures
Where this commonly fails
  • Risk assessments not refreshed after relocations or tenancy changes
  • Zoning documented but not enforced operationally
  • Maintenance records absent for alarm and access systems
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Protective Security Policy Framework (PSPF) Release 2024 framework page.