Protective Security Policy Framework (PSPF) Release 2024
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Governance and Culture
Per Australian Protective Security Policy Framework (PSPF) Release 2024 Governance: security culture + governance. Requirements include (a) develop + maintain Security Culture across entity + (b) implement Security Risk Management including identification + treatment + (c) integrate with enterprise risk management + (d) maintain Chief Security Officer (CSO) role + governance + (e) implement security planning + reporting + (f) cooperate with Commonwealth Security Advisor + AGSVA.
- PSPF evidence for PSPF24-1
- Essential Eight maturity + clearances + zones partial
Incident Response
Per PSPF Incidents: handle security incidents. Requirements include (a) operate incident response capability including detection + triage + containment + recovery + lessons learned + (b) notify ASD ACSC + AFP per requirements + (c) maintain incident log + reporting + (d) implement business continuity + disaster recovery + (e) maintain documented IR + (f) align with broader Commonwealth incident reporting.
- PSPF evidence for PSPF24-5
- Essential Eight maturity + clearances + zones partial
Information Security
Per PSPF Information Security: protect official information. Requirements include (a) implement Essential Eight Maturity Model aligned to data sensitivity + (b) implement Information Security Manual (ISM) controls + (c) protect classified information per Australian Government classification scheme + (d) implement encryption + access control + monitoring + (e) align with Cyber Security Strategy + ACSC guidance + (f) maintain documented security baseline.
- PSPF evidence for PSPF24-2
- Essential Eight maturity + clearances + zones partial
Information Security Policies (5 to 9)
Information must be classified according to the harm that could result from its compromise, with markings applied consistently and only by authorised originators.
- Originator authority register
- Marking and protective markings procedure
- Tooling configuration enforcing marking on email and documents
- Reclassification log with rationale and approval
- Sample audit of documents for correct marking
- Originators not trained, leading to over- or under-classification
- Marking tools deployed inconsistently across business units
- Reclassification ad hoc with no documented decision trail
Access to sensitive and classified information must be limited to personnel with appropriate clearance, a demonstrated need-to-know, and an acknowledgement of their information handling responsibilities.
- Clearance management system and verification process
- Need-to-know matrix mapping roles to information categories
- Signed acknowledgement of handling obligations
- Access review logs showing periodic reauthorisation
- Breach handling procedure for unauthorised access
- Need-to-know justified by role, not specific business purpose
- Acknowledgements signed once at induction and never refreshed
- Access reviews conducted yearly only, missing role changes mid-year
Entities must ensure that ICT systems holding official information are governed in accordance with the Information Security Manual, with documented authorisation to operate by the Accountable Authority or delegate.
- System Security Plan (SSP) per system
- Authority to Operate (ATO) letter signed by Accountable Authority or delegate
- Annual ISM compliance assessment results
- Continuous monitoring report including vulnerability scans
- Change control records for security-relevant changes
- ATO issued years ago and not refreshed after major changes
- ISM assessment performed by the same team that built the system
- Continuous monitoring metrics not reviewed by the Accountable Authority
Entities must apply caveats and releasability markings, and ensure that sharing arrangements with other entities, contractors, and foreign partners include controls consistent with PSPF requirements.
- Information sharing agreements with other entities and partners
- Caveat and releasability register
- Foreign government information handling procedures
- Contractor security clauses in procurement contracts
- Audit log of information shared and recipient acknowledgements
- Sharing agreements signed but not refreshed in years
- Caveats applied inconsistently across business units
- Contractors handling classified data without subcontractor flow-down
Eligibility for security clearance must be based on Australian citizenship (with documented exceptions), favourable character checks, and the entity's assessment that the person can be entrusted with the relevant level of classified information.
- Eligibility matrix per clearance level
- Character assessment template and case records
- Citizenship and residency verification procedure
- Documented exceptions approved at appropriate level
- Periodic review of clearance holders
- Citizenship exceptions granted without documented rationale
- Character assessment not refreshed when major life events occur
- Periodic review limited to expiry checks
Personnel Security
Per PSPF Personnel Security: vet + manage personnel. Requirements include (a) implement pre-engagement screening + AGSVA security clearances per role requirements + (b) ongoing personnel security including aftercare + reportable incidents + (c) implement insider threat programme + (d) maintain offboarding + access revocation + (e) implement training + awareness on personnel security obligations + (f) maintain records.
- PSPF evidence for PSPF24-3
- Essential Eight maturity + clearances + zones partial
Personnel Security Policies (10 to 12)
Entities must implement ongoing suitability procedures that detect, assess, and manage changes in personnel circumstances that may impact their continued suitability to access Australian Government resources.
- Ongoing suitability policy with defined trigger events
- Reporting channels for personnel to declare changes
- Assessment framework for changes (financial, personal, behavioural)
- Case management records with outcomes
- Annual programme report to the Accountable Authority
- Personnel unaware of obligation to self-report changes
- Assessments rely on subjective judgement without a framework
- Cases closed without recording residual risk
Entities must manage clearances actively, including timely revalidation, transfer or sharing of clearances, and revocation when an individual no longer requires or warrants the clearance.
- Clearance lifecycle procedure
- Transfer and sharing agreements with other entities
- Revocation workflow with HR and legal involvement
- Clearance register reconciled with AGSVA
- Briefing and debriefing records
- Clearance register out of sync with AGSVA records
- Revocations delayed after staff departure
- Briefings and debriefings not documented
Entities must ensure contractors and service providers accessing official resources meet equivalent eligibility, suitability, and ongoing assessment standards as direct employees.
- Standard security clauses in contracts
- Contractor screening records
- Audit results of contractor compliance
- Termination and offboarding procedures
- Register of contractor personnel with access
- Security clauses present in head contract but not flowed down
- Contractor screening evidence held by vendor and not auditable
- Offboarding delays leaving contractor accounts active
Physical Security
Per PSPF Physical Security: secure physical environment. Requirements include (a) implement physical security including perimeter + access control + monitoring + (b) implement secure zones (Zone 1-5 per PSPF) for classified handling + (c) implement secure transport + storage + handling + (d) maintain physical access logging + monitoring + (e) implement environmental controls + (f) maintain documented physical security plan.
- PSPF evidence for PSPF24-4
- Essential Eight maturity + clearances + zones partial
Physical Security Policies (13 to 15)
Entities must apply physical security controls to facilities, including zoning, perimeter security, access control, and intruder detection, proportionate to the threat and the classification of information held.
- Facility zoning diagrams
- Perimeter and access control specifications
- Intruder detection system configuration and test logs
- After-hours security procedures
- Security construction certification for higher zones
- Higher zones built before PSPF 2024 and not reassessed
- Access control logs not reviewed for anomalies
- Intruder detection tested annually rather than monthly
Entities must protect physical assets including ICT equipment, security containers, keys, and devices storing classified information, with controls for handling, storage, and disposal.
- Asset register including classified ICT equipment
- Key and combination management procedure
- Security container inspection log
- Disposal and destruction certificates
- Sanitisation records aligned to ISM
- Key registers maintained on paper and rarely audited
- Disposal of devices done without certificates
- Container inspection records missing for off-site storage
Physical security must be integrated into property planning from project initiation, including site selection, design, construction, and changes to tenancy or operations.
- Property project security checklist
- Site selection risk assessment
- Design review records signed off by CSO
- Construction sign-off including secure spaces
- Change management records for tenancy and fit-out changes
- Security engaged late in property projects, requiring rework
- Site selection criteria omit threat environment
- Tenancy changes proceed without security review
Secretaries Directions
Requires entities to identify indicators of Foreign Ownership, Control or Influence (FOCI) risk in procurement and maintenance of technology assets, and appropriately manage and report those risks.
- Foreign ownership register
- Influence assessment report
- Compliance attestation
- Vendor declaration records
- Register incomplete
- No influence assessment
- Attestation not submitted
Requires entities to conduct a comprehensive stocktake of technology assets to understand technology exposure and risk.
- Technology asset register
- Stocktake report
- Reconciliation evidence
- Asset lifecycle records
- Register stale
- Stocktake not performed annually
- Reconciliation gaps
Requires entities to mitigate identified risks from technology assets associated with foreign interference.
- Technology risk register
- Mitigation plan
- Direction status report
- Executive briefing
- Mitigation actions overdue
- No executive briefing
- Status report missing
Security Governance Policies (1 to 4)
The Accountable Authority is responsible for the entity's protective security and must appoint a Chief Security Officer (CSO) at the SES Band 2 level or equivalent, with clear delegations for security advisors.
- Letter of appointment for the CSO
- Delegation instrument covering security decisions
- Position descriptions for CSO, ASO, ITSA, and PSO roles
- Annual attestation from the Accountable Authority
- Succession plan for the CSO role
- CSO appointed below the required SES level
- Delegations not refreshed when key staff leave
- Annual attestation signed without supporting evidence pack
Entities must implement security management structures and processes that integrate protective security into governance, risk, planning, and assurance activities, including reporting to the Accountable Authority.
- Security integration plan with corporate governance, audit, and risk functions
- Internal assurance plan covering all four PSPF outcomes
- Organisational chart showing security reporting lines
- Security inputs into the annual planning cycle
- Internal audit reports covering protective security
- Security plan disconnected from corporate plan
- Internal audit covers ICT only, missing physical and personnel security
- No clear escalation path to the Accountable Authority for material risks
Entities must develop and implement a security plan informed by an enterprise security risk assessment, addressing risks across information, personnel, and physical security, and reviewed at least annually.
- Enterprise security risk assessment report
- Approved security plan with control mapping
- Annual review log of the plan with date and approver
- Risk treatment register and progress reporting
- Briefings to senior executives on residual risk
- Risk assessment focuses on cyber and ignores insider or physical threats
- Security plan exists but lacks measurable controls and owners
- Annual review skipped or compressed without evidence
Entities must monitor and report their security maturity against PSPF outcomes annually to the Attorney-General's Department, including against Essential Eight cyber controls where applicable.
- PSPF maturity self-assessment workbook
- Annual PSPF report submission acknowledgement
- Essential Eight maturity assessment per applicable system
- Evidence library underpinning self-assessment scores
- Improvement plan to address gaps identified
- Maturity ratings inflated relative to evidence on file
- Essential Eight maturity assessed only on corporate ICT, missing operational systems
- Improvement plan not tracked in subsequent cycles
Security Incident Policy (16)
Entities must report and manage security incidents involving people, information, and physical assets, including notifications to relevant authorities such as ASIO, ACSC, and AGSVA, with lessons captured back into the risk programme.
- Security incident response plan
- Incident register covering all four outcomes
- Notification records to ASIO, ACSC, AGSVA where required
- Post-incident review and improvement actions
- Annual incident statistics reported to the Accountable Authority
- Incident register only captures cyber events, missing physical and personnel
- Notification thresholds not defined for each authority
- Lessons learned not closed out in improvement plans
Security Outcomes
Entities must take a risk-based approach to protective security, with clear governance, accountability, and performance reporting that drives continuous improvement across security functions.
- Accountable Authority security policy statement
- Protective security governance committee terms of reference and minutes
- Enterprise security risk register aligned to PSPF outcomes
- Annual PSPF maturity self-assessment submitted via the PSPF reporting portal
- Performance reporting dashboard for the four outcomes
- Governance committee exists in name but does not review risks each cycle
- Risk register treats security as IT-only and excludes personnel and physical
- Self-assessment overstates maturity without underlying evidence
Entities must safeguard official information consistent with its sensitivity and security classification, throughout its lifecycle and across people, processes, and systems.
- Information classification policy aligned to PSPF and the Australian Government PSPF Information Management Framework
- Handling guides for OFFICIAL, PROTECTED, SECRET, and TOP SECRET
- Records management lifecycle procedures
- Information asset register with classification
- Training records on handling classified information
- Classification policy not updated for PSPF Release 2024 changes
- Inconsistent marking of emails and documents in practice
- No process to declassify or reclassify information over time
Entities must ensure their personnel are suitable to access Australian Government resources and continue to meet this requirement throughout their engagement, with controls for ongoing suitability and insider risk.
- Pre-employment screening policy and records
- AGSVA clearance request and renewal records
- Ongoing suitability programme procedures and case files
- Insider risk programme charter and risk indicators
- Separation and return of asset procedures
- Pre-employment screening limited to identity and right-to-work checks
- Ongoing suitability programme exists on paper but rarely triggers actions
- Insider risk programme not coordinated with HR and legal
Entities must protect their people, information, and physical assets through proportionate physical security measures aligned to the threat environment and the sensitivity of holdings.
- Site security risk assessment per facility
- Physical security plan with zoning
- Maintenance and testing schedule for physical controls
- Incident records and lessons learned
- Visitor management procedures
- Risk assessments not refreshed after relocations or tenancy changes
- Zoning documented but not enforced operationally
- Maintenance records absent for alarm and access systems
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Protective Security Policy Framework (PSPF) Release 2024 framework page.