// Risk & Compliance

IRAP
Assessment.

The Information Security Registered Assessors Program (IRAP) provides independent assessment of Australian Government systems against the Information Security Manual. HackLabs delivers rigorous IRAP assessments by ASD-endorsed assessors.

Talk to an Expert
// Government Security Assessment

Independent assessment for government security requirements.

IRAP assessments are required for cloud services and systems handling Australian Government information. HackLabs' IRAP-endorsed assessors provide independent, objective assessment of your system's security posture against the Australian Government Information Security Manual (ISM). We support assessments for Unclassified, Protected, and higher classification environments.

// What We Cover
  • Assessment against the Australian Government ISM
  • PROTECTED and Unclassified system assessments
  • Cloud service provider IRAP assessments
  • System Security Plan (SSP) development support
  • Statement of Applicability (SoA) review
  • Security Assessment Report (SAR) preparation
  • Essential Eight alignment review
  • Continuous monitoring recommendations
  • Remediation advisory against ISM controls
  • ASD-endorsed assessor delivered reports
// Assessment Scope

What an IRAP assessment covers

ISM Control Assessment

Systematic assessment of applicable ISM controls against your system's implementation, producing evidence-based findings and ratings for each control.

System Security Plan Review

Review and development support for SSP documentation that accurately represents your system's security architecture and control implementation.

Cloud Assessment

Assessment of cloud service providers seeking inclusion on the Certified Cloud Services List (CCSL) or supporting government agencies in their cloud adoption.

Network & Architecture Review

Technical review of network architecture, segmentation, and security controls against ISM requirements for the target classification level.

Access Control & Identity

Assessment of identity and access management against ISM requirements including privileged access, MFA, and account lifecycle management.

Continuous Monitoring

Development of continuous monitoring plans to maintain IRAP assessment validity and demonstrate ongoing security posture to your authorising officer.

// Methodology

Our engagement process

01

Scoping

We define engagement objectives, boundaries, and rules of engagement. Clear scope means focused work and accurate results.

02

Assessment

Senior consultants conduct the engagement using proven methodologies tailored to your environment and threat model.

03

Reporting

Detailed findings with risk ratings, evidence, and clear remediation guidance for both technical and executive audiences.

04

Remediation Support

We stay engaged beyond the report. Our team answers remediation questions and offers re-testing on critical findings.

// Why HackLabs
IRAP
Endorsed Assessors

Our assessors are endorsed by the Australian Signals Directorate to conduct IRAP assessments.

ASD
Authorised

HackLabs is an ASD-authorised organisation with experience across government security frameworks and classification levels.

20+
Years Established

Decades of experience working with Australian government agencies and the security frameworks that govern them.

CREST
Accredited

CREST certification underpins our technical assessment quality across all cyber security disciplines.

// Related Services

Explore related services

// Get Started

Need an IRAP assessment?

Talk to a HackLabs IRAP specialist. We work with government agencies and cloud providers across Australia.

Talk to an Expert