Listing Thumbnail

    Australian ISM/IRAP Advisory Services

     Info
    Complying with Australian’s Information Security Manual (ISM) requirements and achieving Infosec Registered Assessors Program (IRAP) compliance is essential if you want to do business with the Australian Federal Government. The IRAP assessment can be time-consuming and complex, but if offers significant sales advantages and a valuable reputation boost. 38North’s experienced, technically expert IRAP compliance consultants can help you make the most of AWS infrastructure and solutions to make the authorization process easier.

    Overview

    Our approach maximizes the use of AWS infrastucture to reduce common errors in the authorization process, saving your team time and reducing compliance risk. 38North also partners with several certified IRAP assessors with a proven track record of helping companies achieve Australia’s highest security compliance levels. Whether you need guidance, documentation, or hands-on security engineering support, we’re here to streamline your path to get IRAP authorized.

    Boundary Scoping: We start by helping you understand what data you have within AWS that must be protected. This lets us know what assets and ISM requirements are in and out of scope. We will also ensure that appropriate AWS regions and edge services meet data residency requirements.

    Workshops: Our workshops get you started with ISM requirements training and consulting. We use Australian Federal Government practices to design systems on AWS, backed by approaches that will withstand IRAP assessments.

    ISM Requirements Gap Analysis: We perform the industry’s most detailed gap analysis, followed by an actionable compliance roadmap to help you make the most of AWS's tools to facilitate compliance. Impact of interrelated policy and standards such as the Protective Security Policy Framework (PSPF), Essential 8 and the Hosting Certification Framework (HCF), amongst others, is also considered during our Gap Analysis.

    Advisory and Architecture Support: We work with your team and use your existing AWS infrastructure to maximize your security and compliance posture, while carefully selecting and adding new processes and technical solutions as needed to achieve your IRAP business goals. As a trusted AWS partner, we prioritize the selection of native AWS services wherever possible.

    Cloud Security Engineering: We specialize in guiding CSPs through IRAP’s engineering puzzles while shaping your existing security processes to achieve compliance. 38North can build secure AWS environments from scratch or provide cloud engineers to supplement your DevOps workforce.

    Documentation Development: Our technical writers document your IRAP security and compliance posture in complete packages that withstand the IRAP assessment scrutiny and present your best compliance posture to agency customers.

    Assessment Support: We are your advocate throughout the assessment process, with teams on standby to quickly address any identified issues found within your initial/annual assessment.

    Maintenance and Continuous Monitoring: Following IRAP initial authorization, 38North provides the full scope of continuous monitoring support needed to maintain IRAP compliance on AWS.

    Highlights

    • Extensive Experience: Our Senior Advisors blend IRAP assessment and CSP experience to provide our clients with best practices based on years of working with IRAP. There are currently only a limited number of certified assessors in Australia. Fortunately, 38North partners with several certified in-country IRAP assessors to prepare organisations tackle the IRAP compliance process. Our expertise extends to how Australian Federal customers and IRAP assessors perceive risk and compliance.
    • Reduce Time to Market: Our team of experts work side-by-side with you throughout the full IRAP process. We specialize in assisting you in tailoring and refining your approach to IRAP, ensuring it is both appropriate and effective. At 38North, we strive to minimize disruptions to your critical business operations, implementing only necessary changes to meet compliance requirements, and ensuring technical compliance based on proven AWS solutions to avoid unexpected issues.
    • Strategic Planning: The 38North team prioritizes long-term success in every engagement, considering multiple security frameworks. We collaborate closely with each client to develop comprehensive, long-term roadmap plans tailored to their needs. This approach enables us to allocate resources effectively, compress timelines, and meet compliance goals efficiently.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support