ISM in Practice: Controls, System Security Plans and Authorisation
How to apply the Australian Government Information Security Manual (ISM) in the real world — selecting controls, writing an SSP and SRMP, and preparing systems for authorisation.
What you’ll learn
- How the ISM’s risk-based approach works — and how it maps to the PSPF and NIST SP 800-53
- A practical method for selecting applicable controls and documenting exclusions
- What a strong System Security Plan, SRMP and Statement of Applicability look like
- How to prepare evidence for IRAP assessments and system authorisation
Who it’s for
Security officers, system owners and GRC teams in government agencies and the Defence supply chain.