What are Australia's security compliance frameworks?
Australian security compliance frameworks are the set of government, regulatory and legislative regimes that impose information security obligations on organisations operating in Australia. The main ones are the ACSC Essential Eight, the Information Security Manual, APRA CPS 234 and CPS 230, the Security of Critical Infrastructure Act and the Privacy Act 1988.
Australian security obligations come from several directions at once: government policy, industry regulators, privacy law and critical infrastructure legislation. Which ones apply depends on what you do and who you sell to, and more than one usually applies at the same time.
One point is worth making before the detail. No tool makes you compliant. A test produces technical evidence, and an assessor, auditor or regulator decides whether that evidence, combined with your policies and processes, meets the obligation. Any vendor who tells you their product delivers compliance is overselling.
The ACSC Essential Eight
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate's Australian Cyber Security Centre. It is the most widely referenced baseline in Australia and is mandatory for non-corporate Commonwealth entities. The authoritative source is the ACSC itself: see the Essential Eight.
The eight are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is assessed at Maturity Level Zero through Three, with the maturity model defining what evidence each level expects.
| Strategy | What testing can evidence |
|---|---|
| Patch applications | Missing and outdated components found on reachable services, correlated to CVEs |
| Patch operating systems | Unpatched hosts discovered during internal and external scanning |
| Restrict administrative privileges | Over-privileged accounts and privilege-escalation paths surfaced during testing |
| Multi-factor authentication | Exposed interfaces that accept single-factor authentication |
| User application hardening | Weak service and application configuration on tested systems |
| Application control | Limited: this is largely an endpoint control and is assessed by configuration review |
| Office macro settings | Not assessed by network or application testing |
| Regular backups | Not assessed by testing; verified through process and restore evidence |
Being honest about coverage
Testing gives you strong evidence for the patching, privilege and authentication strategies. It gives you little or nothing for macro settings and backups, which are configuration and process controls. Treat a test as one input to a maturity assessment, not the assessment itself.
The Information Security Manual and IRAP
The Information Security Manual (ISM) is the ACSC's control catalogue for systems handling government information. Controls are selected according to a system's risk profile rather than applied wholesale. It is reissued regularly, so always work from the current release: see the Information Security Manual.
IRAP, the Infosec Registered Assessors Program, is the mechanism by which an independent assessor evaluates a system against the ISM. An IRAP assessment is performed by a registered assessor, not by a product. If a vendor implies their platform is IRAP assessed, ask to see the assessment scope, because the term is frequently misused. The assessor register and the programme rules are published by the ACSC alongside the ISM itself.
Penetration testing supports an ISM assessment by producing technical findings and evidence an assessor can review against specific controls. It does not replace the assessment.
APRA CPS 234 and CPS 230
CPS 234 is the Australian Prudential Regulation Authority's information security standard, and it applies to APRA-regulated entities: banks, insurers and superannuation funds. It requires information security capability commensurate with the threat, clear roles, controls tested for effectiveness, and notification to APRA of material incidents. The standard and its guidance are published by APRA.
The phrase that matters for testing is control effectiveness. CPS 234 expects you to test controls systematically and at a frequency justified by the rate of change in your environment. An annual test of a monthly-changing estate is difficult to defend on that wording, which is a large part of why continuous testing has become common in the sector.
CPS 230, the operational risk management standard, broadens this to critical operations, service provider management and business continuity. Its relevance here is third-party risk: if you are a supplier to an APRA-regulated entity, expect their obligations to arrive in your contract. Both standards are accompanied by prudential practice guides, which are worth reading because they show what the regulator expects in practice.
The SOCI Act and critical infrastructure
The Security of Critical Infrastructure Act applies to entities in defined critical sectors, which now extend well beyond the traditional utilities to include data storage and processing, healthcare, food and grocery, financial services, higher education and more. The Act has been amended several times, so read the consolidated current version on the Federal Register of Legislation rather than a summary.
Obligations can include registering assets, adopting a critical infrastructure risk management program covering cyber and other hazards, and mandatory incident reporting within short statutory timeframes. Whether and how it applies depends on your sector and asset class, so confirm your position rather than assuming.
Testing contributes evidence to the cyber hazard element of a risk management program, particularly around demonstrating that identified risks are real and that mitigations work.
The Privacy Act, the NDB scheme and the CDR
The Privacy Act 1988 and the Australian Privacy Principles govern handling of personal information. APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. The regulator publishes the principles and its guidelines on them: see the Australian Privacy Principles.
The Notifiable Data Breaches scheme requires notification to the OAIC and to affected individuals where a breach is likely to result in serious harm. Testing helps by finding the exposures that would cause such a breach before someone else does. The OAIC publishes the assessment thresholds and reporting timeframes for the NDB scheme.
The Consumer Data Right applies to accredited data recipients in banking, energy and beyond, and carries its own information security requirements including regular assurance. If you hold CDR data, your testing cadence is effectively set for you.
New Zealand: NZISM and the Privacy Act 2020
The New Zealand Information Security Manual (NZISM) is the control framework for government systems, issued under the GCSB and maintained alongside the National Cyber Security Centre. It plays a role comparable to the ISM in Australia.
The Privacy Act 2020 introduced mandatory notification of notifiable privacy breaches to the Office of the Privacy Commissioner, which publishes the thresholds and the reporting process: see the Office of the Privacy Commissioner.
For trans-Tasman buyers there is a practical question beyond the frameworks: where the data goes. Any platform holding your findings has a residency position, and it is a material fact for a New Zealand organisation assessing a vendor. Ask for it in writing early rather than discovering it during review.
Which apply to you
| If you are | Expect to deal with |
|---|---|
| A Commonwealth agency or supplier | Essential Eight, ISM, IRAP assessment, PSPF |
| A bank, insurer or super fund | APRA CPS 234 and CPS 230, plus the Privacy Act |
| An accredited CDR participant | CDR security requirements and regular assurance |
| A critical infrastructure entity | The SOCI Act risk management program and incident reporting |
| A merchant or payment handler | PCI DSS v4.0, including the client-side script requirements |
| Any organisation holding personal information | The Privacy Act, the APPs and the NDB scheme |
| A New Zealand organisation | NZISM where government-facing, and the Privacy Act 2020 |
How PentestOps helps
PentestOps produces the technical evidence these regimes ask for, and maps findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. That mapping shows where a finding sits against a framework; it is not a certification of your compliance.
Because testing runs continuously rather than annually, the evidence stays current, which is the practical difficulty with control-effectiveness wording like CPS 234's. See continuous penetration testing and our methodology.
Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified and the platform is built to SOC 2-aligned controls. PentestOps is not IRAP assessed and holds no government accreditation. The platform is hosted in Australia and customer data is stored in Australia, which answers the residency question a trans-Tasman or Commonwealth buyer will ask. Hosting, retention and access are set out in the Trust Centre.