Coming soon · Free

This lesson is being recorded.

Notify me when it launches

Sentinel, the AI agent, will take your details — no spam, one email when it's live.

Free Intermediate 28:00 ISM & PSPF

ISM in Practice: Controls, System Security Plans and Authorisation

How to apply the Australian Government Information Security Manual (ISM) in the real world — selecting controls, writing an SSP and SRMP, and preparing systems for authorisation.

What you’ll learn

  • How the ISM’s risk-based approach works — and how it maps to the PSPF and NIST SP 800-53
  • A practical method for selecting applicable controls and documenting exclusions
  • What a strong System Security Plan, SRMP and Statement of Applicability look like
  • How to prepare evidence for IRAP assessments and system authorisation

Who it’s for

Security officers, system owners and GRC teams in government agencies and the Defence supply chain.

More lessons

45:00
Critical Infrastructure·Advanced

SOCI Act CIRMP Masterclass for Critical Infrastructure

A deep dive into Critical Infrastructure Risk Management Programs under the SOCI Act — all-hazards risk, AESCSF alignment and Board attestation.

Coming soon 32:00
AI Governance·Intermediate

ISO 42001 in Practice: Building an AI Management System

From AI inventory to impact assessments: a step-by-step guide to standing up an ISO/IEC 42001 AI management system in a regulated organisation.

Coming soon 18:00
Essential Eight·Beginner

Essential Eight Explained: Maturity Levels in Plain English

A practical walkthrough of the ACSC Essential Eight — what each strategy protects against, what ML1–ML3 really mean, and how assessors look for evidence.