Telecommunications Sector Security Reforms (TSSR)
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Information Sharing
Per TSSR: information sharing + Section 315B direction authority + minister directions + Carrier Compliance.
- TSSR evidence for AUTSSR-3
- SCP + CISC partial
Security Capability
Per TSSR: Security Capability Plan + risk management + Supply Chain Risk Management for Vendors + Access Control to Sensitive Network Functions.
- TSSR evidence for AUTSSR-2
- SCP + CISC partial
Security Obligation
Per Australian Telecommunications Sector Security Reforms (TSSR) Telecommunications Act 1997 Part 14: security obligation. Requirements include (a) Security Obligation to Protect Networks and Facilities + (b) Notification of Material Changes to networks or services + (c) cooperate with Department of Home Affairs + CISC.
- TSSR evidence for AUTSSR-1
- SCP + CISC partial
TSSR: Network Information Protection
Carriers must protect the confidentiality of communications and stored data passing over their networks.
- Network confidentiality standard
- Encryption configuration evidence
- TSSR notification records
- Annual carrier report
- Encryption gaps on legacy nets
- TSSR notifications late
- Annual report incomplete
Carriers must prevent unauthorised access to stored communications and telecommunications data.
- Stored communications security standard
- Access control configuration
- Audit log samples
- Compliance attestation
- Access controls misconfigured
- Audit logs not retained
- Attestation missing
Carriers must maintain the capability to provide lawful interception of communications as required by the Telecommunications (Interception and Access) Act 1979.
- Lawful interception capability documentation
- Warrant handling procedure
- Capability test records
- Liaison records
- Capability not tested
- Procedure outdated
- Liaison records incomplete
TSSR: Notification Obligation and Ministerial Powers
Carriers and nominated CSPs must notify the Department of Home Affairs of planned changes to their networks or facilities that could have a material adverse effect on security.
- Notification register for material network and facility changes
- Security incident notification playbook for TSSR scope
- Engagement record with Critical Infrastructure Centre
- Ministerial direction response procedures
- Material change criteria unclear to engineering teams
- Incident criteria not aligned with operations definitions
- Direction response procedures lack legal review checkpoints
Carriers must notify the Department of Home Affairs of security incidents that could compromise the security of networks or facilities.
- Notification register for material network and facility changes
- Security incident notification playbook for TSSR scope
- Engagement record with Critical Infrastructure Centre
- Ministerial direction response procedures
- Material change criteria unclear to engineering teams
- Incident criteria not aligned with operations definitions
- Direction response procedures lack legal review checkpoints
The Minister for Communications may direct carriers to do, or refrain from doing, specified things to manage security risks to telecommunications networks.
- Notification register for material network and facility changes
- Security incident notification playbook for TSSR scope
- Engagement record with Critical Infrastructure Centre
- Ministerial direction response procedures
- Material change criteria unclear to engineering teams
- Incident criteria not aligned with operations definitions
- Direction response procedures lack legal review checkpoints
TSSR: Security Obligation
Carriers and nominated carriage service providers must do their best to protect their networks and facilities from unauthorised interference and unauthorised access.
- Security capability assessment against TSSR expectations
- Competent supervision evidence including vendor oversight
- National security risk register reviewed with government
- Operational control documentation for sensitive functions
- Effective control claims not supported by audit evidence
- Sensitive vendors lack ongoing assurance
- Risk register not stress tested against named threats
Carriers must ensure that network operations are under the competent supervision and effective control of the carrier at all times.
- Security capability assessment against TSSR expectations
- Competent supervision evidence including vendor oversight
- National security risk register reviewed with government
- Operational control documentation for sensitive functions
- Effective control claims not supported by audit evidence
- Sensitive vendors lack ongoing assurance
- Risk register not stress tested against named threats
Carriers must manage risks to the security of their networks from actions that might compromise national security.
- Security capability assessment against TSSR expectations
- Competent supervision evidence including vendor oversight
- National security risk register reviewed with government
- Operational control documentation for sensitive functions
- Effective control claims not supported by audit evidence
- Sensitive vendors lack ongoing assurance
- Risk register not stress tested against named threats
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Telecommunications Sector Security Reforms (TSSR) framework page.