How to Prepare for an IRAP Assessment
Preparation should make the implemented system, its security decisions and the evidence supporting them clear to an independent assessor.
Good preparation is not about manufacturing evidence immediately before assessment. It is about defining the real system, validating its controls and presenting current operational evidence in a secure, traceable form.
Start With the System Scope
Document the system boundary, users, information, hosting, environments, connections, dependencies and service providers. Agree what is included, excluded and inherited before mapping evidence.
Understand the Applicable ISM Controls
Use the current Information Security Manual and organisational requirements to identify applicable controls. Selection needs to reflect classification, threats, architecture, risk decisions and government policy—not a generic control list.
Get the Security Documentation in Order
Bring the System Security Plan, architecture, risk records, procedures and control descriptions into line with production. Resolve conflicting versions and assign owners for gaps and decisions.
Validate Controls Before the Assessor Arrives
Test whether controls operate across the complete boundary. Sample devices, accounts and configurations; trace operational processes; and confirm that exceptions and inherited controls are documented.
Prepare Technical Evidence
Gather current configuration outputs, reports, logs, records and demonstrations that show implementation and effectiveness. Protect evidence according to its sensitivity and agree transfer, storage and disposal arrangements.
Review Essential Eight Implementation
Assess each mitigation strategy against the agreed target maturity using ASD guidance. Essential Eight can provide an important baseline, but it does not represent the full set of ISM controls that may apply.
Resolve Known Security Gaps
Prioritise gaps that affect material risk or multiple controls. Where remediation cannot be completed, record the issue, risk owner, treatment decision and planned action instead of obscuring it.
Prepare System Owners and Technical Teams
Ensure system owners, administrators, security personnel and service providers understand the assessment approach and can explain or demonstrate the controls they operate.
Conduct an IRAP Readiness Assessment
A readiness review can test scope, documentation, evidence quality and control operation before formal independent assessment. It should identify issues early enough for informed remediation planning. Advisory and assessment responsibilities must be separated where independence requires it.
Common IRAP Preparation Problems
- Documentation does not match implementation
- Old screenshots are presented as current evidence
- Policies exist but controls are not implemented
- Privileged access is poorly controlled
- Patching is incomplete or cannot be measured
- Evidence is weak, untraceable or outside scope
- System boundaries and inherited controls are unclear
- Unsupported systems remain without a treatment plan
- Teams assume Essential Eight alone equals full ISM compliance
Need Help Preparing?
Explore CCircle's IRAP readiness and assessment services, discuss ACT delivery with our Canberra IRAP assessors, and use the IRAP preparation checklist for a structured review.