
Security Governance
Accountability, responsibility, and suitable plans, processes and people to ensure entity security.
Entry Level
OFFICIAL / OFFICIAL:Sensitive6 itemsAppoint a Security Officer
Designate a Security Officer responsible for overseeing the entity's security obligations under DISP.
Security Management Plan
Develop and maintain a Security Management Plan that addresses all DISP security domains relevant to the entity.
Security Risk Assessment
Conduct an initial security risk assessment identifying threats, vulnerabilities and risks to Defence information and assets.
Security Awareness Training
Implement a security awareness training program for all personnel with access to Defence information.
Incident Response Procedures
Establish security incident response and reporting procedures aligned with DISP requirements.
FOCI Declaration
Complete Foreign Ownership, Control or Influence (FOCI) declaration and maintain ongoing awareness.
Level 1
PROTECTED5 itemsChief Security Officer (CSO)
Appoint a Chief Security Officer with appropriate security clearance and authority to manage PROTECTED information.
Enhanced Security Plan
Expand Security Management Plan to address PROTECTED level requirements including detailed risk treatments.
Annual Security Report
Prepare and submit annual security governance report to Defence demonstrating ongoing compliance.
Security Committee
Establish a security governance committee that meets regularly to review security posture and incidents.
Contractor Security Management
Implement procedures for managing security obligations of subcontractors and third parties.
Level 2
SECRET3 itemsSECRET Security Framework
Implement comprehensive security governance framework suitable for SECRET classified information handling.
Security Audit Program
Establish internal security audit program with regular compliance assessments and corrective action tracking.
Supply Chain Security
Implement supply chain security risk management processes for all Defence-related procurement.
Level 3
TOP SECRET2 itemsTOP SECRET Governance
Implement TOP SECRET level security governance with enhanced oversight, reporting and compliance mechanisms.
Continuous Monitoring
Establish continuous security monitoring and real-time threat assessment capabilities.