IRAP and Cloud Security in Australia: A Guide for Government and Regulated Organisations
For Australian Government agencies and organisations handling sensitive or regulated information, moving workloads to the cloud involves more than choosing a provider with strong security features.
Organisations need to understand where their information is stored, who can access it, which security controls apply, how those controls have been assessed and whether the remaining risk is acceptable.
For many Australian Government cloud environments, the Infosec Registered Assessors Program (IRAP) plays an important role in providing that assurance.
IRAP, however, is often misunderstood. An IRAP assessment is not a government certification of a cloud provider, nor does it automatically mean a system is fully compliant.
This guide explains what IRAP is, how IRAP assessments relate to cloud services, the broader Australian Government security requirements organisations should consider, and how these frameworks work together when evaluating cloud environments.
What is IRAP?
The Infosec Registered Assessors Program, commonly known as IRAP, is an Australian Signals Directorate (ASD) program that provides access to qualified cyber security professionals who can independently assess ICT systems against Australian Government security requirements.
IRAP assessors are endorsed by ASD based on their cyber security assessment and risk management experience, including their knowledge of the Australian Government Information Security Manual (ISM).
IRAP assessors can assess systems, cloud services, gateways and other environments up to the SECRET classification level.
An IRAP assessment examines whether relevant security controls have been implemented effectively and identifies areas where security risks, weaknesses or control deficiencies may remain.
The assessment produces evidence that an organisation can use when determining whether a system or cloud service is suitable for its information, operational requirements and risk appetite.
Is IRAP a certification?
No.
This is one of the most important distinctions for organisations evaluating cloud providers.
IRAP assessors do not certify, accredit or endorse systems on behalf of ASD. Completing an IRAP assessment also does not automatically mean every control within the ISM has been assessed or that the system complies with every requirement.
Instead, an IRAP assessment provides an independent assessment of a defined environment against an agreed scope.
The organisation using the system remains responsible for reviewing the assessment findings, understanding any residual risks and deciding whether the environment is appropriate for its information and workloads.
For this reason, terms such as “IRAP certified” can be misleading.
More accurate language includes “IRAP assessed”, supported by information about the assessment scope, classification level, ISM release used and assessment date.
How do IRAP assessments relate to cloud services?
Cloud environments operate under a shared responsibility model.
A cloud provider may be responsible for physical infrastructure, networking, virtualisation, platform security and some operational controls, while the customer remains responsible for areas such as identity management, application configuration, information classification and user access.
An IRAP assessment helps organisations understand how the provider has addressed its portion of this shared responsibility.
Australian Government cloud security assessments draw heavily on requirements within the Information Security Manual and the Protective Security Policy Framework (PSPF).
Depending on the scope, an IRAP assessment may examine areas such as:
- Identity and privileged access management
- Encryption and cryptographic controls
- Network security
- Logging and monitoring
- Vulnerability and patch management
- Incident response
- Personnel security
- Physical security
- Configuration management
- System administration
- Data protection
However, an IRAP-assessed cloud platform does not automatically make every workload deployed on that platform secure.
Customers still need to configure their services correctly, manage permissions, protect identities, monitor workloads and assess their own risks.
How often should cloud services be assessed?
Cloud security assurance is not a one-time process.
Under current Australian Government guidance, outsourced cloud service providers and cloud services handling information classifications such as non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET are generally expected to undergo IRAP assessments using an appropriate ISM release at least every 24 months.
TOP SECRET environments follow separate assessment arrangements.
Regular assessments are important because cloud services continually change. Providers introduce new capabilities, architectures evolve, security controls are updated and the ISM itself changes over time.
Organisations should therefore consider not only whether a service has undergone an IRAP assessment, but also:
- When the assessment was completed
- Which ISM version was used
- Which services were included
- Whether any material findings remain unresolved
- Whether significant changes have occurred since the assessment
Australian Government cloud security requirements
There is no single compliance framework that covers every aspect of Australian Government cloud security.
Instead, organisations need to understand several interconnected frameworks and assurance mechanisms.
Protective Security Policy Framework
The Protective Security Policy Framework (PSPF) sets Australian Government requirements for protecting people, information and resources.
The PSPF covers areas beyond technical cyber security, including information classification, personnel security, physical security, governance and supply chain risk.
This matters when evaluating cloud environments because government security requirements are not limited to encryption or firewalls.
Organisations may also need to consider:
- Who owns or controls the infrastructure
- Who operates the service
- Where information is stored
- Which personnel can access systems
- Which third parties or subcontractors are involved
- How security obligations are governed
These broader considerations can influence whether a cloud service is appropriate for government workloads.
The Information Security Manual
The Information Security Manual, produced by ASD, provides detailed cyber security principles, guidelines and controls for Australian organisations.
It covers areas such as access control, authentication, privileged administration, vulnerability management, cryptography, communications infrastructure, software security, monitoring and logging, incident response, system management and cloud services.
The ISM provides much of the technical baseline against which government systems and cloud environments are assessed.
It should be used as part of an organisation’s broader risk management approach rather than treated purely as a compliance checklist.
Because responsibility for cloud environments is often shared between providers and customers, both sides may be responsible for implementing different parts of the ISM.
Where does the Essential Eight fit?
The Essential Eight is another ASD cyber security framework, but it serves a different purpose from IRAP.
It includes eight prioritised mitigation strategies designed to make it harder for attackers to compromise systems:
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
The Essential Eight Maturity Model helps organisations assess their current implementation and progressively improve their security posture.
The Essential Eight should not be confused with a certification program. Instead, it provides a practical baseline for strengthening cyber security, particularly against common attack techniques.
The Essential Eight is also mapped to controls within the ISM, meaning organisations can use both frameworks together.
What is the Hosting Certification Framework?
Australian Government cloud security also involves questions of sovereignty, ownership and control.
The Hosting Certification Framework (HCF) provides additional assurance around hosting services used by Australian Government organisations.
It considers issues including data sovereignty, ownership and control, supply chain risk, privacy, physical infrastructure and operational security.
This is important because data residency and data sovereignty are not the same thing.
Data residency refers primarily to where information is physically stored.
Data sovereignty can also involve questions such as who owns the infrastructure, who operates it, which legal jurisdictions apply, which personnel have access and whether foreign entities can exercise control.
The HCF is therefore designed to address concerns that may not be captured through technical security controls alone.
How Macquarie Cloud Services supports regulated and government-aligned organisations
Understanding these frameworks is particularly important when organisations start translating compliance requirements into decisions about infrastructure, cloud architecture and ongoing operations.
Macquarie Cloud Services has extensive history in supportings Australian organisations operating in environments where security, compliance and sovereignty requirements are important. Macquarie Cloud Services has offered highly compliant solutions to both critical and non-critical industry for over 20 years alongside the Macquarie Government business which supports 42% of Federal Government agencies.
Macquarie’s capabilities span managed cloud, private cloud, hybrid environments and cyber security services, supported by Australian infrastructure and local security expertise.
Macquarie Cloud Service’s hosted platforms comply or align with frameworks including ISO/IEC 27001, ISO/IEC 27017, PCI DSS, Essential Eight, are IRAP-assessed,, and hold membership of the Defence Industry Security Program (DISP) as a group..
In many cases, newer organisations specifically can underestimate obligations to government or Defense customers as supporting regulated and government-aligned environments involves more than meeting a particular framework. It can often includes secure cloud and hybrid architectures, identity security, centralised monitoring and threat detection, incident response planning, and governance around data residency and audit readiness.
Macquarie Cloud Services material also describes security uplift aligned with the Essential Eight and Australian regulatory expectations, alongside secure cloud, hybrid and data centre architectures.
These capabilities can help organisations implement and operate environments that align with their security requirements, but they do not transfer accountability for compliance to the cloud provider.
Customers still need to classify their information, establish which controls apply to their workloads, understand the shared responsibility model, securely configure their services and make their own risk-based decisions.
That distinction is particularly important for IRAP: choosing an IRAP-assessed environment can provide valuable assurance, but organisations still need to determine whether the scope and findings of that assessment are appropriate for their particular use case.
Other relevant certifications and frameworks
IRAP, the ISM and PSPF are not the only frameworks organisations may need to consider.
Depending on the workload and industry, additional requirements may apply.
ISO/IEC 27001
ISO/IEC 27001 provides an internationally recognised framework for establishing and maintaining an information security management system.
It demonstrates that an organisation has structured processes for identifying, managing and reviewing information security risks.
ISO/IEC 27017
ISO/IEC 27017 provides additional security guidance specifically for cloud services and builds on ISO/IEC 27001 controls.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) applies to organisations that store, process or transmit payment card information.
It may be relevant to government or regulated organisations handling cardholder data, but it does not replace Australian Government security frameworks.
Defence Industry Security Program
The Defence Industry Security Program (DISP) is relevant to organisations working within the Australian defence supply chain.
It includes requirements across governance, personnel, physical and cyber security.
Industry-specific requirements
Organisations may also need to consider sector-specific obligations.
For example, financial services organisations regulated by the Australian Prudential Regulation Authority (APRA) may need to meet additional requirements relating to information security and operational resilience.
The key point is that these frameworks complement one another. They should not be treated as interchangeable.
What should organisations look for in an IRAP-assessed cloud provider?
When evaluating a cloud provider, organisations should look beyond whether the words “IRAP assessed” appear on a website and seek to understand the scope of the assessment. Organisations should also understand their own assessable scope and responsibilities to their end clients.
Ask:
- Which cloud services are in scope?
- Which information classification was assessed and what classification do we need to meet?
- Which version of the ISM was used?
- When was the assessment completed?
- Have significant changes occurred since then?
- Are there unresolved findings?
- Which controls remain the my responsibility?
Organisations should also understand the provider’s approach to sovereignty, data residency, personnel access, supply chain risk and operational support.
Most importantly, security assurance should continue throughout the cloud lifecycle.
A cloud environment that was appropriately configured at launch can still become vulnerable through configuration changes, new services, excessive permissions or unpatched systems.
Continuous monitoring, governance, testing and reassessment are therefore essential.
IRAP is part of the assurance process, not the end of it
IRAP provides an important mechanism for independently assessing the security of cloud services and ICT environments used by Australian organisations.
But IRAP is only one part of the broader security and compliance landscape.
For Australian Government and regulated organisations, effective cloud assurance requires an understanding of the PSPF, ISM, IRAP, Essential Eight, Hosting Certification Framework and any industry-specific requirements that apply.
Each plays a different role.
The ISM provides detailed cyber security controls. The PSPF establishes broader protective security requirements. IRAP provides independent assessment. The Essential Eight provides practical mitigation strategies. The HCF addresses hosting and sovereignty considerations.
Together, supported by ongoing risk management and continuous security monitoring, these frameworks can help organisations adopt cloud services while maintaining the security, accountability and sovereignty required for sensitive Australian workloads.







