The Australian Government’s Protective Security Policy Framework (PSPF) Release 2024 takes effect today, the most significant overhaul of Commonwealth protective security policy in several years.
Key points
- Requirements are reorganised into six security domains, including new domains for risk and technology.
- New requirements address supply chain and third-party risk, foreign interference and emerging technologies.
- Reporting moves from a maturity-based model to a compliance-based model.
- Cyber security expectations continue to draw on the ASD Information Security Manual and Essential Eight.
UK suppliers of cloud, software and services to Australian government agencies should expect sharper supply-chain and third-party security requirements in contracts, alongside IRAP assessments against the ISM.
Source: PSPF Release 2024 (Protective Security Policy Framework)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.