A PSPF gap analysis and compliance roadmap, paired with an independent physical security review of an outsourced data centre, moved a Commonwealth agency from ad hoc security arrangements to a structured, prioritised compliance program.

THE CHALLENGE

A Commonwealth agency holds large volumes of critical data and must meet the mandatory requirements of the Protective Security Policy Framework (PSPF), both for its own operations and for the third parties that host its information. Its existing security measures had developed without an overarching plan. As a result, the agency could not readily establish its level of compliance with each PSPF requirement or plan how to close any gaps, which also made its ministerial reporting obligations harder to meet. At the same time, the agency hosted corporate data in a third-party commercial data centre. The contract required the facility to meet high-level government physical security standards, and the agency needed independent verification that those standards were being implemented and maintained.

OUR APPROACH

Agilient delivered two related workstreams. The first was a PSPF gap analysis and compliance roadmap. Consultants reviewed the agency’s existing security documentation, engaged with key stakeholders and assessed current arrangements against each PSPF mandatory requirement, classifying each as fully, partially or not compliant. From this baseline, Agilient developed a ‘Road to Compliance Map’ setting out a documentation hierarchy, the policies and procedures still required, and a phased work plan to reach full compliance. The second workstream was an independent physical security review of the outsourced data centre. An Agilient consultant inspected the facility and assessed its physical security controls against the ASIO T4 physical security standards required under the contract. The review included discussions with agency personnel about the classification and criticality of the hosted data, and with data centre staff about operational security arrangements. The findings were set out in a formal report confirming the facility’s security level.

THE OUTCOME

The agency gained both a strategic path to PSPF compliance and assurance over a critical outsourced service.

Related services: protective security and PSPF consulting, security audit services, physical security consultant. Sector experience: government security consultant. To discuss a similar project, contact Agilient.