An independent enterprise security threat and risk assessment gave a Commonwealth agency the evidence it needed to review its PSPF security plan.

THE CHALLENGE

Non-corporate Commonwealth entities must meet the Protective Security Policy Framework, which includes an enterprise-level security risk assessment to support review of the entity’s security plan at least every two years. A Commonwealth agency with a nationally distributed operation needed an independent assessment to support its next review. The scope was broad: every PSPF domain, every location the agency operates, flexible work arrangements and official international travel. The assessment also had to show where security risk intersects with fraud, privacy and business continuity risk, and identify risks the agency shares with other government bodies, all across a geographically dispersed workforce.

OUR APPROACH

Agilient conducted the assessment in accordance with the PSPF, the Information Security Manual and the Commonwealth Risk Management Policy. The work examined threats and risks to the agency’s people, information and resources, identifying their sources, the agency’s exposure and the potential consequences. A security threat assessment established the credible threat environment. A criticality assessment identified the assets and functions that matter most to service delivery. A vulnerability assessment then examined how effectively existing controls manage each risk. Risks were rated using the agency’s own risk management framework, so results aligned with its existing risk governance and reporting. Agilient documented the results in security risk registers organised across the PSPF domains, each with suggested treatments, and drew out the points where security risk overlaps with fraud, privacy and continuity risk, and where risks are shared with partner agencies.

THE OUTCOME

The agency received a complete enterprise security threat and risk assessment that meets PSPF requirements and informs the review of its security plan.

Related services: protective security and PSPF consulting, the Protective Security Policy Framework (PSPF), security risk management. Sector experience: government security consultant. To discuss a similar project, contact Agilient.