Australian ISM Assessment — IRAP compliance software
Manage Australian ISM assessments end to end — engagements, control-by-control evaluation, automated evidence collection and findings.
What IRAP (AU ISM) requires
The Information Security Registered Assessors Program (IRAP), run by the Australian Signals Directorate, endorses assessors to evaluate systems against the Australian Government Information Security Manual (ISM). IRAP assessments underpin authorisation decisions for systems handling government data, including cloud services consumed by agencies.
An IRAP engagement is evidence-heavy: the assessor must establish scope and boundary, evaluate ISM controls, gather artefacts from the environment itself, and produce defensible findings. Spreadsheets strain under thousands of controls and artefacts.
GRCLens provides a dedicated IRAP workspace: engagements with imported ISM catalogues, per-control assessment, connectors that pull evidence directly from the assessed environment (cloud, SIEM, ITSM, IPAM), and finding registers that flow into a tracked assurance loop.
Who it applies to
- IRAP assessors and assessment firms
- Cloud service providers preparing for IRAP assessment
- Commonwealth entities managing system authorisation
- Suppliers required to evidence ISM alignment for government contracts
At a glance
- Programme owner: Australian Signals Directorate
- Control source: Australian ISM (updated quarterly)
- Engagement outputs: Scope/boundary, control assessment, findings, reports
- Typical consumers: Authorising officers and agency security teams
How GRCLens supports IRAP (AU ISM)
IRAP (AU ISM) runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Engagement workspaces
Each assessment runs as a scoped engagement with its own ISM catalogue revision, controls, evidence and findings.
Connector-collected evidence
Azure, SIEM, ITSM and IPAM connectors pull dated configuration facts from the assessed environment, suggested against ISM topics for the assessor to confirm.
Findings and assurance loop
Accepted failures become findings with owners, severities and remediation tracked through verification — no spreadsheet reconciliation.
Human-in-the-loop by design
Automation suggests; the assessor decides. No automated result asserts compliance in the assessment record on its own.
IRAP (AU ISM) frequently asked questions
Does GRCLens replace an IRAP assessor?
No. IRAP assessments are performed by ASD-endorsed assessors. GRCLens is the working platform for the engagement: catalogue, evidence, findings and reporting.
Which ISM version does the platform use?
ISM catalogues are imported per engagement, so each assessment pins the ISM revision it was performed against.
How does automated evidence collection stay defensible?
Connector results arrive as suggestions with the raw observation attached. The assessor maps them to controls and accepts or dismisses them — the human judgement is preserved in the record.
Can findings be tracked after the assessment?
Yes. Findings flow into the assurance register with owners, treatments, due dates and second-party verification, and can be pushed to the client's ITSM.
One platform, many obligations
Talk to us about IRAP (AU ISM)
Security Solution Consultants provides IRAP and ISM advisory services alongside the platform, so you can combine tooling with hands-on expertise.
Contact us