What are Australia's security compliance frameworks?

Australian security compliance frameworks are the set of government, regulatory and legislative regimes that impose information security obligations on organisations operating in Australia. The main ones are the ACSC Essential Eight, the Information Security Manual, APRA CPS 234 and CPS 230, the Security of Critical Infrastructure Act and the Privacy Act 1988.

Australian security obligations come from several directions at once: government policy, industry regulators, privacy law and critical infrastructure legislation. Which ones apply depends on what you do and who you sell to, and more than one usually applies at the same time.

One point is worth making before the detail. No tool makes you compliant. A test produces technical evidence, and an assessor, auditor or regulator decides whether that evidence, combined with your policies and processes, meets the obligation. Any vendor who tells you their product delivers compliance is overselling.

The ACSC Essential Eight

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate's Australian Cyber Security Centre. It is the most widely referenced baseline in Australia and is mandatory for non-corporate Commonwealth entities. The authoritative source is the ACSC itself: see the Essential Eight.

The eight are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is assessed at Maturity Level Zero through Three, with the maturity model defining what evidence each level expects.

StrategyWhat testing can evidence
Patch applicationsMissing and outdated components found on reachable services, correlated to CVEs
Patch operating systemsUnpatched hosts discovered during internal and external scanning
Restrict administrative privilegesOver-privileged accounts and privilege-escalation paths surfaced during testing
Multi-factor authenticationExposed interfaces that accept single-factor authentication
User application hardeningWeak service and application configuration on tested systems
Application controlLimited: this is largely an endpoint control and is assessed by configuration review
Office macro settingsNot assessed by network or application testing
Regular backupsNot assessed by testing; verified through process and restore evidence

Being honest about coverage

Testing gives you strong evidence for the patching, privilege and authentication strategies. It gives you little or nothing for macro settings and backups, which are configuration and process controls. Treat a test as one input to a maturity assessment, not the assessment itself.

The Information Security Manual and IRAP

The Information Security Manual (ISM) is the ACSC's control catalogue for systems handling government information. Controls are selected according to a system's risk profile rather than applied wholesale. It is reissued regularly, so always work from the current release: see the Information Security Manual.

IRAP, the Infosec Registered Assessors Program, is the mechanism by which an independent assessor evaluates a system against the ISM. An IRAP assessment is performed by a registered assessor, not by a product. If a vendor implies their platform is IRAP assessed, ask to see the assessment scope, because the term is frequently misused. The assessor register and the programme rules are published by the ACSC alongside the ISM itself.

Penetration testing supports an ISM assessment by producing technical findings and evidence an assessor can review against specific controls. It does not replace the assessment.

APRA CPS 234 and CPS 230

CPS 234 is the Australian Prudential Regulation Authority's information security standard, and it applies to APRA-regulated entities: banks, insurers and superannuation funds. It requires information security capability commensurate with the threat, clear roles, controls tested for effectiveness, and notification to APRA of material incidents. The standard and its guidance are published by APRA.

The phrase that matters for testing is control effectiveness. CPS 234 expects you to test controls systematically and at a frequency justified by the rate of change in your environment. An annual test of a monthly-changing estate is difficult to defend on that wording, which is a large part of why continuous testing has become common in the sector.

CPS 230, the operational risk management standard, broadens this to critical operations, service provider management and business continuity. Its relevance here is third-party risk: if you are a supplier to an APRA-regulated entity, expect their obligations to arrive in your contract. Both standards are accompanied by prudential practice guides, which are worth reading because they show what the regulator expects in practice.

The SOCI Act and critical infrastructure

The Security of Critical Infrastructure Act applies to entities in defined critical sectors, which now extend well beyond the traditional utilities to include data storage and processing, healthcare, food and grocery, financial services, higher education and more. The Act has been amended several times, so read the consolidated current version on the Federal Register of Legislation rather than a summary.

Obligations can include registering assets, adopting a critical infrastructure risk management program covering cyber and other hazards, and mandatory incident reporting within short statutory timeframes. Whether and how it applies depends on your sector and asset class, so confirm your position rather than assuming.

Testing contributes evidence to the cyber hazard element of a risk management program, particularly around demonstrating that identified risks are real and that mitigations work.

The Privacy Act, the NDB scheme and the CDR

The Privacy Act 1988 and the Australian Privacy Principles govern handling of personal information. APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. The regulator publishes the principles and its guidelines on them: see the Australian Privacy Principles.

The Notifiable Data Breaches scheme requires notification to the OAIC and to affected individuals where a breach is likely to result in serious harm. Testing helps by finding the exposures that would cause such a breach before someone else does. The OAIC publishes the assessment thresholds and reporting timeframes for the NDB scheme.

The Consumer Data Right applies to accredited data recipients in banking, energy and beyond, and carries its own information security requirements including regular assurance. If you hold CDR data, your testing cadence is effectively set for you.

New Zealand: NZISM and the Privacy Act 2020

The New Zealand Information Security Manual (NZISM) is the control framework for government systems, issued under the GCSB and maintained alongside the National Cyber Security Centre. It plays a role comparable to the ISM in Australia.

The Privacy Act 2020 introduced mandatory notification of notifiable privacy breaches to the Office of the Privacy Commissioner, which publishes the thresholds and the reporting process: see the Office of the Privacy Commissioner.

For trans-Tasman buyers there is a practical question beyond the frameworks: where the data goes. Any platform holding your findings has a residency position, and it is a material fact for a New Zealand organisation assessing a vendor. Ask for it in writing early rather than discovering it during review.

Which apply to you

If you areExpect to deal with
A Commonwealth agency or supplierEssential Eight, ISM, IRAP assessment, PSPF
A bank, insurer or super fundAPRA CPS 234 and CPS 230, plus the Privacy Act
An accredited CDR participantCDR security requirements and regular assurance
A critical infrastructure entityThe SOCI Act risk management program and incident reporting
A merchant or payment handlerPCI DSS v4.0, including the client-side script requirements
Any organisation holding personal informationThe Privacy Act, the APPs and the NDB scheme
A New Zealand organisationNZISM where government-facing, and the Privacy Act 2020

How PentestOps helps

PentestOps produces the technical evidence these regimes ask for, and maps findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. That mapping shows where a finding sits against a framework; it is not a certification of your compliance.

Because testing runs continuously rather than annually, the evidence stays current, which is the practical difficulty with control-effectiveness wording like CPS 234's. See continuous penetration testing and our methodology.

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified and the platform is built to SOC 2-aligned controls. PentestOps is not IRAP assessed and holds no government accreditation. The platform is hosted in Australia and customer data is stored in Australia, which answers the residency question a trans-Tasman or Commonwealth buyer will ask. Hosting, retention and access are set out in the Trust Centre.

Frequently Asked Questions

Does penetration testing make us Essential Eight compliant?

No. Testing evidences several strategies well, particularly patching, administrative privilege and multi-factor authentication, and barely touches others such as macro settings and backups. Your maturity level is determined by an assessor reviewing controls and processes, not by a tool.

Is PentestOps IRAP assessed?

No, and we will not imply otherwise. IRAP assessments are performed by registered assessors against the ISM for a defined system and scope. Extranet Systems is ISO/IEC 27001:2022 certified, and the certificate is available on request.

How often does CPS 234 expect us to test?

CPS 234 does not name a fixed interval. It requires testing of control effectiveness at a frequency justified by the rate of change in your environment and the criticality of the assets. For a fast-changing estate, an annual test is hard to justify on that wording.

Does the SOCI Act apply to us?

It depends on your sector and asset class, and the definitions have broadened over time to include data storage and processing, healthcare, education and others. Confirm your status rather than assuming, because the obligations include registration and short statutory incident-reporting timeframes.

We are a New Zealand company. Where would our data be stored?

In Australia. The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. Authorised support personnel in our overseas offices may access it to operate the platform, as set out in the Trust Centre.

Can we get reports mapped to these Australian frameworks specifically?

Reports map findings to the 8 supported frameworks plus CIS Benchmarks. Several Australian regimes reference those same underlying controls, so the mapping is usable as evidence, but there is no per-regime certification output and we do not claim one.

Do we still need an independent assessor?

For anything requiring formal assessment or attestation, yes. PentestOps provides continuous technical evidence between engagements. It is built to sit alongside independent assessment rather than replace it.

Evidence your assessors can use

Continuous testing that keeps compliance evidence current, with findings mapped to 8 reporting frameworks plus CIS Benchmarks. Start with a free demo scan against a domain you own, or talk to us about scoping a programme.