IRAP Assessment Preparation Checklist
A structured review of the scope, documentation, technical controls and evidence that commonly need attention before assessment.
This checklist supports preparation; it does not replace assessment planning with an ASD-endorsed IRAP assessor. Evidence and control requirements must be tailored to the system and agreed scope.
Assessment Scope
- System boundary is defined and agreed
- Information classification and handling requirements are understood
- Users and user groups are identified
- External interfaces and trust relationships are documented
- Supporting services and dependencies are recorded
- Hosting and network architecture reflect the current environment
Security Documentation
Confirm, where applicable, that the System Security Plan, security risk assessment, security architecture, policies, incident response plan, business continuity and recovery material, change management process, access control procedures and vulnerability management process are current and internally consistent.
Identity and Access Management
- Active user accounts have an owner and business purpose
- Privileged accounts are separated and tightly controlled
- Multi-factor authentication coverage is known
- Joiner, mover and leaver processes are evidenced
- Access reviews are completed and recorded
- Service accounts and administrative access paths are documented
Patch and Vulnerability Management
- Operating system and application patch status is measurable
- Vulnerability scanning covers the assessed boundary
- Remediation decisions and exceptions are recorded
- Unsupported software is identified and treated as a risk
- Reports can be reconciled to an authoritative asset inventory
Logging and Monitoring
- Security-relevant events are logged
- Retention meets operational and applicable security needs
- Administrative activity can be traced
- Alerts cover agreed threat and control scenarios
- Log review responsibilities are defined
- Detection and incident response workflows have been exercised
Network and Infrastructure Security
- Segmentation and data flows are understood
- Firewall rules have current owners and justification
- Remote access is strongly authenticated and monitored
- Management interfaces are restricted
- Secure administration methods are defined and followed
Backups and Recovery
- Backup scope and schedules cover critical systems and data
- Restoration testing demonstrates recoverability
- Backup administration and access are restricted
- Isolation or immutability is used where required by risk and target controls
- Failures and corrective actions are recorded
Essential Eight
Organise evidence for each applicable Essential Eight control and the relevant target maturity. Do not assume an Essential Eight result demonstrates compliance with every applicable ISM control. See the Essential Eight assessment process for evidence and validation considerations.
Evidence Organisation
Evidence should be current, traceable, understandable, relevant to the control and representative of the actual production environment. Label it with the source system, capture date, owner and control relationship, while applying the agreed handling and protection requirements.
Final Readiness Review
Before assessment starts, reconcile scope, documents, asset data and evidence; confirm system-owner and technical-team availability; close or formally record known gaps; and verify that evidence can be shared securely with the assessor.
Discuss IRAP Readiness With CCircle
Review our IRAP assessment and readiness services, contact our Canberra IRAP assessors, or learn how the IRAP assessment process typically works.