A refreshed PSPF security risk assessment and security plan helped a Commonwealth regulator reflect changes in its operating environment and strengthen its protective security arrangements under the PSPF.
THE CHALLENGE
A Commonwealth regulator needed to review and update its Security Risk Assessment and Security Plan to maintain alignment with the Protective Security Policy Framework (PSPF). Its operating environment had changed since the previous assessment, including its shared services arrangements, and the threat landscape had continued to evolve. The agency wanted findings tailored to its own context, operational structure and security maturity. It also wanted to assess whether its current security measures remained adequate and to update both documents to match its present context. Agilient had prepared earlier assessments for the agency, and feedback from that work pointed to areas where the documents could be clearer and more self-contained.
OUR APPROACH
Agilient followed a five-stage process of project initiation, risk identification, threat and vulnerability assessment, development of the revised Security Risk Assessment, and finalisation of the updated Security Plan. Site visits, stakeholder interviews and document reviews grounded the findings and recommendations in how the agency actually operates. The team refreshed the agency’s Critical Asset List and List of Threat Actors and prepared a new Security Threat Assessment, which together informed the revised risk assessment. The methodology was also updated in response to feedback from the previous assessment. The revised documents set out the agency’s risk tolerances more clearly, explained how security objectives connect with broader agency goals, and embedded key content within the core documents rather than relying on external references. Updated PSPF requirements, including arrangements for responding to security directions, were incorporated into the plan.
THE OUTCOME
The agency received updated, standards-aligned documents and a roadmap for strengthening its protective security capability across its people, information and physical assets.
- A revised Security Risk Assessment and updated Security Plan reflecting the agency’s current operating environment
- A refreshed Critical Asset List, List of Threat Actors and Security Threat Assessment
- Clearer risk tolerances and self-contained documentation that links security objectives to agency goals
Related services: protective security and PSPF consulting, the Protective Security Policy Framework (PSPF), security risk assessment consultants. Sector experience: government security consultant. To discuss a similar project, contact Agilient.