Skip to content

Evidence request lists

Telecommunications Sector Security Reforms (TSSR)

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Information Sharing

AUTSSR-3
Information Sharing and Direction Authority

Per TSSR: information sharing + Section 315B direction authority + minister directions + Carrier Compliance.

Artefacts an auditor will ask for
  • TSSR evidence for AUTSSR-3
Where this commonly fails
  • SCP + CISC partial

Security Capability

AUTSSR-2
Security Capability Plan and Risk Management

Per TSSR: Security Capability Plan + risk management + Supply Chain Risk Management for Vendors + Access Control to Sensitive Network Functions.

Artefacts an auditor will ask for
  • TSSR evidence for AUTSSR-2
Where this commonly fails
  • SCP + CISC partial

Security Obligation

AUTSSR-1
Security Obligation and Notification

Per Australian Telecommunications Sector Security Reforms (TSSR) Telecommunications Act 1997 Part 14: security obligation. Requirements include (a) Security Obligation to Protect Networks and Facilities + (b) Notification of Material Changes to networks or services + (c) cooperate with Department of Home Affairs + CISC.

Artefacts an auditor will ask for
  • TSSR evidence for AUTSSR-1
Where this commonly fails
  • SCP + CISC partial

TSSR: Network Information Protection

TSSR-INFO-1
Network Data Protection

Carriers must protect the confidentiality of communications and stored data passing over their networks.

Artefacts an auditor will ask for
  • Network confidentiality standard
  • Encryption configuration evidence
  • TSSR notification records
  • Annual carrier report
Where this commonly fails
  • Encryption gaps on legacy nets
  • TSSR notifications late
  • Annual report incomplete
TSSR-INFO-2
Stored Communications Security

Carriers must prevent unauthorised access to stored communications and telecommunications data.

Artefacts an auditor will ask for
  • Stored communications security standard
  • Access control configuration
  • Audit log samples
  • Compliance attestation
Where this commonly fails
  • Access controls misconfigured
  • Audit logs not retained
  • Attestation missing
TSSR-INFO-3
Lawful Interception Capability

Carriers must maintain the capability to provide lawful interception of communications as required by the Telecommunications (Interception and Access) Act 1979.

Artefacts an auditor will ask for
  • Lawful interception capability documentation
  • Warrant handling procedure
  • Capability test records
  • Liaison records
Where this commonly fails
  • Capability not tested
  • Procedure outdated
  • Liaison records incomplete

TSSR: Notification Obligation and Ministerial Powers

TSSR-NOT-1
Changes to Networks and Facilities

Carriers and nominated CSPs must notify the Department of Home Affairs of planned changes to their networks or facilities that could have a material adverse effect on security.

Artefacts an auditor will ask for
  • Notification register for material network and facility changes
  • Security incident notification playbook for TSSR scope
  • Engagement record with Critical Infrastructure Centre
  • Ministerial direction response procedures
Where this commonly fails
  • Material change criteria unclear to engineering teams
  • Incident criteria not aligned with operations definitions
  • Direction response procedures lack legal review checkpoints
TSSR-NOT-2
Security Incident Notification

Carriers must notify the Department of Home Affairs of security incidents that could compromise the security of networks or facilities.

Artefacts an auditor will ask for
  • Notification register for material network and facility changes
  • Security incident notification playbook for TSSR scope
  • Engagement record with Critical Infrastructure Centre
  • Ministerial direction response procedures
Where this commonly fails
  • Material change criteria unclear to engineering teams
  • Incident criteria not aligned with operations definitions
  • Direction response procedures lack legal review checkpoints
TSSR-NOT-3
Ministerial Direction Power

The Minister for Communications may direct carriers to do, or refrain from doing, specified things to manage security risks to telecommunications networks.

Artefacts an auditor will ask for
  • Notification register for material network and facility changes
  • Security incident notification playbook for TSSR scope
  • Engagement record with Critical Infrastructure Centre
  • Ministerial direction response procedures
Where this commonly fails
  • Material change criteria unclear to engineering teams
  • Incident criteria not aligned with operations definitions
  • Direction response procedures lack legal review checkpoints

TSSR: Security Obligation

TSSR-SEC-1
Security Capability Obligation

Carriers and nominated carriage service providers must do their best to protect their networks and facilities from unauthorised interference and unauthorised access.

Artefacts an auditor will ask for
  • Security capability assessment against TSSR expectations
  • Competent supervision evidence including vendor oversight
  • National security risk register reviewed with government
  • Operational control documentation for sensitive functions
Where this commonly fails
  • Effective control claims not supported by audit evidence
  • Sensitive vendors lack ongoing assurance
  • Risk register not stress tested against named threats
TSSR-SEC-2
Competent Supervision and Effective Control

Carriers must ensure that network operations are under the competent supervision and effective control of the carrier at all times.

Artefacts an auditor will ask for
  • Security capability assessment against TSSR expectations
  • Competent supervision evidence including vendor oversight
  • National security risk register reviewed with government
  • Operational control documentation for sensitive functions
Where this commonly fails
  • Effective control claims not supported by audit evidence
  • Sensitive vendors lack ongoing assurance
  • Risk register not stress tested against named threats
TSSR-SEC-3
National Security Risk Management

Carriers must manage risks to the security of their networks from actions that might compromise national security.

Artefacts an auditor will ask for
  • Security capability assessment against TSSR expectations
  • Competent supervision evidence including vendor oversight
  • National security risk register reviewed with government
  • Operational control documentation for sensitive functions
Where this commonly fails
  • Effective control claims not supported by audit evidence
  • Sensitive vendors lack ongoing assurance
  • Risk register not stress tested against named threats
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Telecommunications Sector Security Reforms (TSSR) framework page.