Assess security controls
Assess security controls for the system and its operating environment to determine if they have been implemented
correctly and are operating as intended.
In conducting a security assessment, it is important that assessors and system owners first agree to the scope, type and
extent of assessment activities, which may be documented in a security assessment plan, such that any risks associated
with the security assessment can be appropriately managed. To a large extent, the scope of the security assessment will
be determined by the type of system and security controls that have been implemented for the system and its
operating environment.
For TOP SECRET systems, including sensitive compartmented information systems, security assessments can be
undertaken by ASD assessors (or their delegates). While for SECRET and below systems, security assessments can be
undertaken by an organisation’s own assessors or Infosec Registered Assessors Program (IRAP) assessors. In all cases,
assessors should hold an appropriate security clearance and have an appropriate level of experience and understanding
of the type of system they are assessing.
At the conclusion of a security assessment, a security assessment report should be produced outlining the scope of the
security assessment, the system’s strengths and weaknesses, security risks associated with the operation of the system,
the effectiveness of the implementation of security controls, and any recommended remediation actions. This will
assist in performing any initial remediation actions as well as guiding the development of the system’s plan of action
and milestones.
Authorise the system
Authorise the system to operate based on the acceptance of the security risks associated with its operation.
Before a system can be granted authorisation to operate, sufficient information should be provided to the authorising
officer in order for them to make an informed risk-based decision as to whether the security risks associated with its
operation are acceptable or not. This information should take the form of an authorisation package that includes the
system’s system security plan, incident response plan, continuous monitoring plan, security assessment report, and
plan of action and milestones.
In some cases, the security risks associated with a system’s operation will be acceptable and it will be granted
authorisation to operate. However, in other cases the security risks associated with operation of a system may be
unacceptable. In such cases, the authorising officer may request further work, and potentially another security
assessment, be undertaken by the system owner. In the intervening time, the authorising officer may choose to grant
authorisation to operate but with constraints placed on the system’s use. Finally, if the authorising officer deems the
security risks to be unacceptable regardless of any potential constraints on the system’s use, they may deny
authorisation to operate until such time that sufficient remediation actions, if possible, have been completed to an
acceptable standard.
For TOP SECRET systems, and systems that process, store or communicate sensitive compartmented information, the
authorising officer is Director-General ASD or their delegate; while for SECRET and below systems, the authorising
officer is an organisation’s CISO or their delegate.
For multinational and multi-organisation systems, the authorising officer should be determined by a formal agreement
between the parties involved.
For commercial providers providing services to an organisation, the authorising officer is the CISO of the supported
organisation or their delegate.
In all cases, the authorising officer should have an appropriate level of seniority and understanding of security risks they
are accepting on behalf of their organisation. In cases where an organisation does not have a CISO, the authorising
officer could be a Chief Security Officer, a Chief Information Officer or other senior executive within the organisation.
3