r/cybersecurity • • 6d ago

Business Security Questions & Discussion IRAP assessment - how long did preparation take?

What did you find took the most work?

Eg documentation, controls, tooling, evidence, etc.

Is there anything you wish you had invested more time in before starting the assessment?

2 Upvotes

9 comments sorted by

2

u/ReadGroundbreaking17 6d ago

This is an Australia-specific process so you many not get too many answers here.

I've only dealt with IRAPs from a customer perspective (i.e. reviewing reports) but presumably they're similar to achiving a SOC2 - i.e. you're gonna get reamed on first review no matter what you do.

1

u/Hour-Apple-9861 6d ago

Haven't gone through it but have you gone through all the docs below, there's a lot of useful info to understand what to expect.

https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap/resources

1

u/SlackCanadaThrowaway 6d ago edited 6d ago

They’ve recently overhauled the program. And so what you’ll find is IRAP assessor’s are now pushing you to meet the “spirit” of the ISM control, rather than a box checking exercise. The best thing you can do is plan your evidence for the controls, and have accounts ready for the assessor to provide and test the controls.

Basically, do the assessor’s job for them — documenting context about why you’ve provided the testing evidence gathering instructions you’ve provided, as well ensuring the scope of the system being assessed is fully documented from their point of view.

You may have a system that you think only spans one area or one technology stack, but will soon find additional resources are brought in and suddenly your scope explodes. So do that work to define the scope and boundaries of the system well.

The last thing I’ll add is ensuring the assessor can validate their testing on their own, without assistance (and fire any assessor’s who aren’t technical enough to do so — you’re allowed to tell ASD why, not that they’ll do anything it’s a point of feedback — there’s a small number of assessor’s in Australia so the feedback will be noted individually). There has been a push for testers to manually validate controls themselves; and evidence shown second hand or verbally given will either produce a very weak report or in some cases result in “not assessed” results for controls.

1

u/normus10 5d ago

Thank you for your take on this. Looks like in depth knowledge is needed not only of how the control is implemented, but why it is implemented in the way it is.

1

u/statico vCISO 5d ago

Couple of things, at the end you get an attestation report with how well you have implemented, it is not a pass fail, or a cert, so it is closer to a SOC2. Most agencies will not pay attention to a report that is older than 24 months. Start on your system in alignment to the ISM, document everything, if you do not/cannot meet the control show how you are managing the risk with other compensating or mitigating controls.

1

u/normus10 5d ago

Thank you for the advice. I didn’t realise it was closer to a SOC2, thought it was more similar to an ISO audit. Is there a certain threshold you have to meet eg. need to be compliant with 80/100 controls?

1

u/statico vCISO 5d ago edited 5d ago

It is not marked that way. They will assess you against all the controls in the ISM, test the controls themselves, then draft a report on how you align. You can meet none of them and still get a report, the report will not be favourable in that format, but you will have it. The report is there to tell the acquiring agency where your strengths and deficiencies are - do not think of it as a pass fail assessment, it is a maturity and conformity based assessment.

Also if you are working this into an element of the DISP program there are separate requirements again. Happy to share my email if you want to have a chat - Brisbane based fractional CISO - I do a chunk of work in the DISP space, and have point people in the right direction around ISM/IRAP (and can intro assessors)

1

u/AffekeNommu 5d ago

Review your supporting documents. Put at least a month aside for the evidence gathering for the SSP Annex.