ASD Essential Eight Maturity Assessment
The Australian Signals Directorate sets out eight priority defences, each scored at four maturity levels (0-3). We check your organisation against every one: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each control gets a maturity rating and clear steps to reach the level you are aiming for. Government suppliers need this, and enterprise clients now ask for it too.
Per-control maturity rating Target level recommendations Government procurement readiness APRA CPS 234 Compliance Testing
CPS 234 applies to APRA-regulated financial institutions and their material service providers. It requires information security controls that match the size and nature of the threats you face. We work through every CPS 234 obligation: information security capability, the role of the board, policy framework, information asset identification, implementation of controls, incident management, and testing of controls. Each finding points to the CPS 234 paragraph it belongs to. Each fix traces back to the rule behind it. That makes your next APRA submission a much shorter job.
APRA submission readiness ISO 27001 Gap Analysis
ISO 27001 is the world standard for managing information security. To be certified you need an Information Security Management System (ISMS). It covers 93 controls across four themes: organisational, people, physical and technological. Our gap analysis checks where you stand against every applicable control in Annex A. We do it well before the certification audit. We rank each finding by how much it matters. Some controls will cause a nonconformity and block certification. Others are simply an observation, or room to improve. That way you put your effort where it counts.
Certification readiness score PCI DSS Compliance Assessment
The Payment Card Industry Data Security Standard covers cardholder data. It applies to anyone who stores it, handles it or sends it. Our assessment covers all 12 requirements: network security, access controls, vulnerability management, monitoring and policy. Are you a smaller merchant? We work out which Self-Assessment Questionnaire (SAQ) applies to you, then check your answers hold up. If you need a Report on Compliance (ROC), we find the gaps before the assessor (QSA) arrives. That saves an expensive round of fixes in the middle of the audit.
All 12 requirements covered Pre-QSA gap identification Cardholder data flow mapping Privacy Act & NDB Compliance Assessment
The Australian Privacy Act requires organisations to take reasonable steps to protect personal information. What counts as "reasonable" depends on three things: how sensitive the data is, how big your organisation is, and what security is available to you. We map your technical controls against the Australian Privacy Principles (APPs). APP 11 matters most here, because it covers security of personal information. We also test your Notifiable Data Breach (NDB) readiness. Can you spot a breach, judge how serious it is, and tell the people affected inside the required time? We produce evidence of your compliance posture for OAIC enquiries.
Reasonable steps evidence SOC 2 Type I/II Readiness Assessment
SOC 2 is a US security standard. Overseas clients now ask for it. Say you are an Australian software provider, managed service provider or data processor with US or international customers. You will meet it sooner or later. We check your controls against the SOC 2 Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. We find the gaps, recommend the controls to close them, and help you build the evidence file the auditor will want. Passing first time makes the formal audit shorter and cheaper.
Trust Services Criteria mapping Evidence portfolio guidance First-pass success planning