Full Report
Adelaide, Australia, 19th August 2026, CyberNewswire The post Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level appeared first on The Security Ledger with Paul F. Roberts.
Analysis Summary
# Regulation/Compliance: Australian IRAP Assessment (PROTECTED Level)
## Overview
The Information Security Registered Assessors Program (IRAP) is an Australian Signals Directorate (ASD) initiative that provides a framework for endorsing individuals to conduct independent assessments of an organization’s security controls. Completion of an IRAP assessment at the **PROTECTED** level signifies that a service provider (in this case, Airlock Digital) has been audited against the rigorous security standards required to handle sensitive Australian Government data.
## Key Details
- **Issuing Authority:** Australian Signals Directorate (ASD)
- **Effective Date:** Assessment completion announced August 19, 2026
- **Jurisdiction:** Australia (Federal Government, Defence, and Critical Infrastructure)
- **Status:** In Effect (Assessment Completed)
## Requirements
### Mandatory Requirements
1. **ISM Compliance:** Alignment with the Australian Government Information Security Manual (ISM) controls.
2. **PSPF Alignment:** Adherence to the Protective Security Policy Framework (PSPF) for government entity security.
3. **Independent Audit:** Assessment must be conducted by an ASD-endorsed IRAP assessor.
4. **Classification Scoping:** The system must meet specific control requirements for the "PROTECTED" data classification level.
### Recommended Practices
1. **Essential Eight Alignment:** Implementation of Application Control as defined by the ACSC’s Essential Eight Maturity Model.
2. **"Deny by Default" Posture:** Moving beyond detection to proactive allowlisting.
3. **Hybrid Availability:** Maintaining security controls across cloud, on-premises, and air-gapped environments.
## Affected Organizations
- **Industries:** Government, Defence, Critical Infrastructure, Financial Services, Healthcare, and Manufacturing.
- **Organization Size:** All sizes, provided they handle Australian Government data or operate within regulated critical sectors.
- **Geographic Scope:** Primarily Australian-based organizations or international entities providing services to the Australian Government.
## Compliance Timeline
- **2013:** Airlock Digital founded (Establishment of baseline security services).
- **August 19, 2026:** Official completion of the independent IRAP assessment at the PROTECTED level.
- **Ongoing:** Periodic re-assessment required to maintain alignment with updated ISM releases.
## Implementation Guidance
### Assessment Phase
- Review the scope of the Airlock Digital IRAP assessment to ensure it covers the specific deployment model (Cloud vs. On-Premises) intended for use.
- Conduct a gap analysis against the Essential Eight Maturity Model, specifically focusing on Application Control.
### Implementation Phase
- Deploy allowlisting to define "what runs" across all endpoints.
- Integrate the solution into existing infrastructure (Cloud, Hybrid, or Air-gapped).
- Establish organizational "Trust Decisions" to define approved software.
### Validation Phase
- Utilize the IRAP Letter of Compliance as part of internal due diligence.
- Verify that unauthorised software execution is blocked in a "Deny by Default" configuration.
## Technical Requirements
- **Application Control:** Precision allowlisting to prevent unauthorized binary execution.
- **OS Hardening:** Measures to reduce the attack surface of the host operating system.
- **Environment Flexibility:** Capability to operate without constant external cloud connectivity for air-gapped segments.
- **Visibility:** Real-time telemetry and reporting on what is running across the endpoint environment.
## Penalties & Enforcement
- **Fines:** While IRAP itself is an assessment framework, failure to protect government data can lead to penalties under the Privacy Act or specific government contracts.
- **Other Consequences:** Loss of government contracts, exclusion from Defence supply chains, and reputational damage.
- **Enforcement:** Compliance is enforced through government procurement mandates and agency-specific risk management requirements.
## Related Standards
- **Essential Eight Maturity Model:** Directly supports the Application Control pillar.
- **Information Security Manual (ISM):** The primary source of security controls for the assessment.
- **Protective Security Policy Framework (PSPF):** Governs the broader security culture and governance.
## Resources
- **Official Documentation:** [https://www.cyber.gov.au/acsc/view-all-content/programs/irap](hXXps://www.cyber.gov.au/acsc/view-all-content/programs/irap)
- **Guidance Documents:** [https://www.airlockdigital.com/irap](hXXps://www.airlockdigital.com/irap)
- **Tools:** Airlock Digital Application Control Platform.
## Practical Recommendations
- **Action Item 1:** Request the IRAP assessment summary report from Airlock Digital to support your organization’s internal Risk Management Framework (RMF).
- **Action Item 2:** Prioritize the implementation of "Deny by Default" to achieve higher maturity levels in the Essential Eight framework.
- **Action Item 3:** Ensure that security teams, not just vendors, retain ownership of "Trust Decisions" to maintain operational stability and security integrity.