RESOURCE · IRAP

IRAP Assessment Process Explained

A practical overview of how organisations prepare systems for an independent security assessment by an ASD-endorsed IRAP assessor.

The exact approach varies with the system and assessment purpose, but a defensible assessment establishes a clear boundary, uses current evidence and records control effectiveness transparently.

01

What Is an IRAP Assessment?

The Infosec Registered Assessors Program gives organisations access to ASD-endorsed ICT professionals who conduct independent security assessments. An assessor identifies applicable controls from the Information Security Manual, evaluates their effectiveness and reports security strengths, weaknesses and recommendations.

IRAP is not a certification program. Assessors do not accredit, certify, endorse or register systems on behalf of ASD, and they do not grant an Authority to Operate.

02

Step 1 — Define the Assessment Scope

Assessment planning establishes the system boundary, information classification, hosting environment, interfaces, dependencies, assessment objectives and applicable ISM controls. Ambiguity here can make otherwise sound evidence irrelevant or leave important components outside the assessment.

03

Step 2 — Review Security Documentation

The assessor reviews material that describes how the system should operate: the System Security Plan, architecture, policies and procedures, risk records, Essential Eight evidence, configuration standards and security design documentation. Documents need to match the implemented production environment.

04

Step 3 — Evidence Collection

Evidence may include configuration outputs, screenshots, system records, technical artefacts, policies, logs, interviews and demonstrations. Useful evidence is current, attributable to the assessed system and sufficient to support a finding.

05

Step 4 — Technical Validation

Claims are tested in practice. Depending on scope and approvals, validation can include observing configurations, sampling systems and accounts, reviewing logs, tracing administrative processes and confirming that documented controls operate consistently.

06

Step 5 — Assess Applicable ISM Controls

The assessor evaluates applicable controls within the agreed scope and Australian Government requirements. The outcome depends on evidence of implementation and effectiveness; it is not a checklist assertion that a control exists.

07

Step 6 — Findings and Security Assessment Report

Findings record control effectiveness, security weaknesses, associated risks and recommendations. The Security Assessment Report gives system owners and authorising decision-makers evidence for risk decisions. The assessor provides the assessment; the responsible organisation makes its authorisation decision.

08

Step 7 — Remediation and Reassessment

Teams can address identified gaps through technical, procedural or documentation changes. Where required, reassessment confirms whether the new implementation resolves the original finding and is operating across the assessed scope.

09

How Long Does an IRAP Assessment Take?

Duration depends on system complexity, the size of the boundary, evidence maturity, the number of applicable controls, stakeholder availability, readiness and any remediation or reassessment. A useful estimate requires a defined scope; fixed timelines without one are unreliable.

10

Preparing for an IRAP Assessment

Start by defining the boundary, making documentation current and organising evidence. Our IRAP preparation guide explains the work in more detail, and the IRAP readiness checklist helps teams review common evidence areas.

Need an IRAP Assessment?

Explore CCircle's IRAP assessment services or speak with our Canberra IRAP assessors about scope and readiness.