{"module":"pspf-requirements-list","request":{"country":"au","standard":"pspf","release":"2024-10","publication":"au-pspf"},"response":{"result":{"pspf-0001":{"index":"0001.0","identifier":"pspf-0001","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["DOS"],"applicability_string":"DOS","content":"The Department of State supports portfolio entities to achieve and maintain an acceptable level of protective security through advice and guidance on government security."},"pspf-0002":{"index":"0002.0","identifier":"pspf-0002","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority complies with all Protective Security Directions."},"pspf-0003":{"index":"0003.0","identifier":"pspf-0003","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE"],"applicability_string":"TAE","content":"The Technical Authority Entity provides technical advice and guidance to support entities to achieve and maintain an acceptable level of protective security."},"pspf-0004":{"index":"0004.0","identifier":"pspf-0004","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["SSPE"],"applicability_string":"SSPE","content":"The Shared Service Provider Entity supplies security services that help relevant entities achieve and maintain an acceptable level of security."},"pspf-0005":{"index":"0005.0","identifier":"pspf-0005","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["SSPE"],"applicability_string":"SSPE","content":"The Shared Service Provider Entity develops, implements and maintains documented responsibilities and accountabilities for partnerships or security service arrangements with other entities."},"pspf-0006":{"index":"0006.0","identifier":"pspf-0006","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority is answerable to their minister for the entity's protective security."},"pspf-0007":{"index":"0007.0","identifier":"pspf-0007","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority is responsible for managing the security risks of their entity."},"pspf-0008":{"index":"0008.0","identifier":"pspf-0008","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A Chief Security Officer is appointed and empowered to oversee the entity's protective security arrangements."},"pspf-0009":{"index":"0009.0","identifier":"pspf-0009","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Chief Security Officer is a Senior Executive Service officer and holds a minimum security clearance of Negative Vetting 1."},"pspf-0010":{"index":"0010.0","identifier":"pspf-0010","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Chief Security Officer is accountable to the Accountable Authority for protective security matters."},"pspf-0011":{"index":"0011.0","identifier":"pspf-0011","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A Chief Information Security Officer is appointed to oversee the entity's cyber security program, including information technology and operational technology."},"pspf-0012":{"index":"0012.0","identifier":"pspf-0012","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Chief Information Security Officer has the appropriate capability and experience and holds a minimum security clearance of Negative Vetting 1."},"pspf-0013":{"index":"0013.0","identifier":"pspf-0013","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Chief Information Security Officer is accountable to the Accountable Authority for cyber security."},"pspf-0014":{"index":"0014.0","identifier":"pspf-0014","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Where appointed, security practitioners are appropriately skilled, empowered and resourced to perform their designated functions."},"pspf-0015":{"index":"0015.0","identifier":"pspf-0015","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Where appointed, security practitioners have access to training across government to maintain and upskill on new and emerging security issues."},"pspf-0016":{"index":"0016.0","identifier":"pspf-0016","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority approves security governance arrangements that are tailored to the entity's size, complexity and risk environment."},"pspf-0017":{"index":"0017.0","identifier":"pspf-0017","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A dedicated security email address is established and monitored as the central conduit for distribution of protective security-related information across the entity."},"pspf-0018":{"index":"0018.0","identifier":"pspf-0018","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A security plan is developed, implemented and maintained to address the mandatory elements of the plan."},"pspf-0019":{"index":"0019.0","identifier":"pspf-0019","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority approves the entity's security plan."},"pspf-0020":{"index":"0020.0","identifier":"pspf-0020","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The security plan is considered annually and reviewed at least every two years to confirm its adequacy and ability to adapt to shifts in the entity's risk, threat or operating environment."},"pspf-0021":{"index":"0021.0","identifier":"pspf-0021","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procedures are developed, implemented and maintained to ensure all elements of the entity's security plan are achieved."},"pspf-0022":{"index":"0022.0","identifier":"pspf-0022","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Develop, establish and implement security monitoring arrangements to identify the effectiveness of the entity's security plan and establish a continuous cycle of improvement."},"pspf-0023":{"index":"0023.0","identifier":"pspf-0023","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority and Chief Security Officer develops, implements and maintains a program to foster a positive security culture in the entity and support the secure delivery of government business."},"pspf-0024":{"index":"0024.0","identifier":"pspf-0024","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security awareness training is provided to personnel, including contractors, at engagement and annually thereafter."},"pspf-0025":{"index":"0025.0","identifier":"pspf-0025","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Targeted security training is provided to personnel, including contractors, in specialist or high-risk positions."},"pspf-0026":{"index":"0026.0","identifier":"pspf-0026","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procedures are developed, implemented and maintained to ensure security incidents are managed and responded to."},"pspf-0027":{"index":"0027.0","identifier":"pspf-0027","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security incident management and response plans are incorporated into the entity's business continuity arrangements."},"pspf-0028":{"index":"0028.0","identifier":"pspf-0028","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procedures are developed, implemented and maintained to ensure security incidents are managed and responded to."},"pspf-0029":{"index":"0029.0","identifier":"pspf-0029","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procedures are developed, implemented and maintained to investigate security incidents in accordance with the principles of the Australian Government Investigations Standards."},"pspf-0030":{"index":"0030.0","identifier":"pspf-0030","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The principles of procedural fairness are applied to all security investigations, with due regard to national security considerations."},"pspf-0031":{"index":"0031.0","identifier":"pspf-0031","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The annual protective security report is provided to the entity's Minister."},"pspf-0032":{"index":"0032.0","identifier":"pspf-0032","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The annual protective security report is submitted to the Department of Home Affairs."},"pspf-0033":{"index":"0033.0","identifier":"pspf-0033","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority approves the entity's annual protective security report and confirms that they have verified the report's content."},"pspf-0034":{"index":"0034.0","identifier":"pspf-0034","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entities cooperate with the Department of Home Affairs' assurance activities to review annual protective security reports."},"pspf-0035":{"index":"0035.0","identifier":"pspf-0035","revision":"0","date":1729838435,"updated":"Oct-24","domain":"GOV","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The annual Cyber Security Survey is submitted to the Australian Signals Directorate."},"pspf-0036":{"index":"0036.0","identifier":"pspf-0036","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority determines their entity's tolerance for security risks and documents in the security plan."},"pspf-0037":{"index":"0037.0","identifier":"pspf-0037","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A risk steward (or manager) is identified for each security risk or category of security risk, including shared risks."},"pspf-0038":{"index":"0038.0","identifier":"pspf-0038","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority considers the impact that their security risk management decisions could potentially have on other entities, and shares information on risks where appropriate."},"pspf-0039":{"index":"0039.0","identifier":"pspf-0039","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The entity is accountable for the management of security risks arising from procuring goods and services and ensures procurement and contract decisions do not expose the entity or the Australian Government to an unacceptable level of risk."},"pspf-0040":{"index":"0040.0","identifier":"pspf-0040","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procurement, contracts and third-party outsourced arrangements, contain proportionate security terms and conditions to ensure service providers, contractors and subcontractors comply with relevant PSPF Requirements and avoid exposing the entity or the Australian Government to an unacceptable level of risk."},"pspf-0041":{"index":"0041.0","identifier":"pspf-0041","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entity ensures service providers, contractors and subcontractors comply with relevant PSPF Requirements as detailed by the entity."},"pspf-0042":{"index":"0042.0","identifier":"pspf-0042","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Contractual security terms and conditions require service providers to report any actual or suspected security incidents to the entity, and follow reasonable direction from the entity arising from incident investigations."},"pspf-0043":{"index":"0043.0","identifier":"pspf-0043","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Government entities providing outsourced services provide IRAP assessment reports to the government entities consuming, or looking to consume, their services."},"pspf-0044":{"index":"0044.0","identifier":"pspf-0044","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Contract security terms and conditions are monitored and reviewed to ensure the specified security controls, terms and conditions are implemented, operated and maintained by the contracted provider, including any subcontractors, over the life of a contract."},"pspf-0045":{"index":"0045.0","identifier":"pspf-0045","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Contractual terms and conditions include appropriate security arrangements for the completion or termination of the contract."},"pspf-0046":{"index":"0046.0","identifier":"pspf-0046","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Procurement and contract decisions consider the security risks before engaging providers operating under foreign ownership, control or influence, and in response to any developments during the contract period that may give rise to foreign ownership, control or influence risks."},"pspf-0047":{"index":"0047.0","identifier":"pspf-0047","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security risks arising from contractual arrangements for the provision of goods and services are managed, reassessed and adjusted over the life of a contract."},"pspf-0048":{"index":"0048.0","identifier":"pspf-0048","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Secure and verifiable third-party vendors, providers, partners and associated services are used unless business operations require use, and the residual risks are managed and approved by the Chief Information Security Officer."},"pspf-0049":{"index":"0049.0","identifier":"pspf-0049","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entities manage the security risks associated with engaging with foreign partners."},"pspf-0050":{"index":"0050.0","identifier":"pspf-0050","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Personnel do not publicise their security clearance level on social media platforms, including employment focused platforms such as LinkedIn."},"pspf-0051":{"index":"0051.0","identifier":"pspf-0051","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"An insider threat program is implemented by entities that manage Baseline to Positive Vetting security clearance subjects to manage the risk of insider threat in the entity."},"pspf-0052":{"index":"0052.0","identifier":"pspf-0052","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Where exceptional circumstances prevent or affect an entity's capability to implement a PSPF requirement or standard, the Accountable Authority may vary application, for a limited period of time, consistent with the entity's risk tolerance."},"pspf-0053":{"index":"0053.0","identifier":"pspf-0053","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Decisions to vary implementation of a PSPF requirement or standard due to exceptional circumstances are documented in the entity's security plan."},"pspf-0054":{"index":"0054.0","identifier":"pspf-0054","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Decisions to implement an alternative mitigation measure that meets or exceeds a PSPF requirement or standard are reviewed and reported annually."},"pspf-0055":{"index":"0055.0","identifier":"pspf-0055","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A business continuity plan is developed, implemented and maintained to respond effectively and minimise the impacts of significant business disruptions to the entity's critical services and assets, and other services and assets when warranted by a threat and security risk assessment"},"pspf-0056":{"index":"0056.0","identifier":"pspf-0056","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Plans for managing a broad range of emergencies are integrated within the business continuity plan."},"pspf-0057":{"index":"0057.0","identifier":"pspf-0057","revision":"0","date":1729838435,"updated":"Oct-24","domain":"RISK","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Personnel who are likely to be impacted are notified if there is a heightened risk of an emergency."},"pspf-0058":{"index":"0058.0","identifier":"pspf-0058","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The originator remains responsible for controlling the sanitisation, reclassification or declassification of official and security classified information, and approves any changes to the information's security classification."},"pspf-0059":{"index":"0059.0","identifier":"pspf-0059","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The value, importance or sensitivity of official information (intended for use as an official record) is assessed by the originator by considering the potential damage to the government, the national interest, organisations or individuals that would arise if the information's confidentiality were compromised."},"pspf-0060":{"index":"0060.0","identifier":"pspf-0060","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The security classification is set at the lowest reasonable level."},"pspf-0061":{"index":"0061.0","identifier":"pspf-0061","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security classified information is clearly marked with the applicable security classification, and when relevant, security caveat, by using text-based markings, unless impractical for operational reasons."},"pspf-0062":{"index":"0062.0","identifier":"pspf-0062","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The minimum protections and handling requirements are applied to protect OFFICIAL and security classified information."},"pspf-0063":{"index":"0063.0","identifier":"pspf-0063","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Government Security Caveat Standard and special handling requirements imposed by the controlling authority are applied to protect security caveated information."},"pspf-0064":{"index":"0064.0","identifier":"pspf-0064","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security caveats are clearly marked as text and only appear in conjunction with a security classification of PROTECTED or higher."},"pspf-0065":{"index":"0065.0","identifier":"pspf-0065","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Accountable material has page and reference numbering."},"pspf-0066":{"index":"0066.0","identifier":"pspf-0066","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Accountable material is handled in accordance with any special handling requirements imposed by the originator and security caveat owner detailed in the Australian Government Security Caveat Standard."},"pspf-0067":{"index":"0067.0","identifier":"pspf-0067","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Government Email Protective Marking Standard is applied to protect OFFICIAL and security classified information exchanged by email in and between Australian Government entities, including other authorised parties."},"pspf-0068":{"index":"0068.0","identifier":"pspf-0068","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Government Recordkeeping Metadata Standard's 'Security Classification' property (and where relevant, the 'Security Caveat' property) is applied to protectively mark information on technology systems that store, process or communicate security classified information."},"pspf-0069":{"index":"0069.0","identifier":"pspf-0069","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Apply the Australian Government Recordkeeping Metadata Standard's 'Rights' property where the entity wishes to categorise information content by the type of restrictions on access."},"pspf-0070":{"index":"0070.0","identifier":"pspf-0070","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security classified discussions and dissemination of security classified information are only held in approved locations."},"pspf-0071":{"index":"0071.0","identifier":"pspf-0071","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entity implements operational controls for its information holdings that are proportional to their value, importance and sensitivity."},"pspf-0072":{"index":"0072.0","identifier":"pspf-0072","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"An auditable register is maintained for TOP SECRET information and accountable material."},"pspf-0073":{"index":"0073.0","identifier":"pspf-0073","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"OFFICIAL and security classified information is disposed of securely in accordance with the Minimum Protections and Handling Requirements, Information Security Manual, the Records Authorities, a Normal Administrative Practice and the Archives Act 1983."},"pspf-0074":{"index":"0074.0","identifier":"pspf-0074","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security classified information is appropriately destroyed in accordance with the Minimum Protections and Handling Requirements when it has passed the minimum retention requirements or reaches authorised destruction dates."},"pspf-0075":{"index":"0075.0","identifier":"pspf-0075","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Access to security classified information or resources is only provided to people outside the entity with the appropriate security clearance (where required) and a need-to-know, and is transferred in accordance with the Minimum Protections and Handling Requirements."},"pspf-0076":{"index":"0076.0","identifier":"pspf-0076","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Memorandum of Understanding between the Commonwealth, States and Territories is applied when sharing information with state and territory government agencies."},"pspf-0077":{"index":"0077.0","identifier":"pspf-0077","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"An agreement or arrangement, such as a contract or deed, that establishes handling requirements and protections, is in place before security classified information or resources are disclosed or shared with a person or organisation outside of government."},"pspf-0078":{"index":"0078.0","identifier":"pspf-0078","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Provisions are met concerning the security of people, information and resources contained in international agreements and arrangements to which Australia is a party."},"pspf-0079":{"index":"0079.0","identifier":"pspf-0079","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Australian Government security classified information or resources shared with a foreign entity is protected by an explicit legislative provision, international agreement or international arrangement."},"pspf-0080":{"index":"0080.0","identifier":"pspf-0080","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Australian Government security classified information or resources bearing the Australian Eyes Only (AUSTEO) caveat is never shared with a person who is not an Australian citizen, even when an international agreement or international arrangement is in place"},"pspf-0081":{"index":"0081.0","identifier":"pspf-0081","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Australian Government security classified information or resources bearing the Australian Government Access Only (AGAO) caveat is not shared with a person who is not an Australia citizen, even when an international agreement or international arrangement is in place, unless they are working for, or seconded to, an entity that is a member of National Intelligence Community, the Department of Defence or the Australian Submarine Agency."},"pspf-0082":{"index":"0082.0","identifier":"pspf-0082","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Where an international agreement or international arrangement is in place, security classified foreign entity information or resources are safeguarded in accordance with the provisions set out in the agreement or arrangement."},"pspf-0083":{"index":"0083.0","identifier":"pspf-0083","revision":"0","date":1729838435,"updated":"Oct-24","domain":"INFO","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Australian Government security classified information or resources shared with a foreign non-government stakeholder is protected by an explicit legislative provision, international agreement or international arrangement."},"pspf-0084":{"index":"0084.0","identifier":"pspf-0084","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Signals Directorate's Information Security Manual cyber security principles are applied during all stages of the lifecycle of each system."},"pspf-0085":{"index":"0085.0","identifier":"pspf-0085","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Signals Directorate's Information Security Manual controls and cyber security guidelines are applied on a risk-based approach."},"pspf-0086":{"index":"0086.0","identifier":"pspf-0086","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Authorising Officer authorises each technology system to operate based on the acceptance of the residual security risks associated with its operation before that system processes, stores or communicates government information or data."},"pspf-0087":{"index":"0087.0","identifier":"pspf-0087","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Decisions to authorise (or reauthorise) a new technology system or make changes to an existing technology system are based on the Information Security Manual's risk-based approach to cyber security."},"pspf-0088":{"index":"0088.0","identifier":"pspf-0088","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The technology system is authorised to the highest security classification of the information and data it will process, store or communication."},"pspf-0089":{"index":"0089.0","identifier":"pspf-0089","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A register of the entity's authorised technology systems is developed, implemented and maintained and includes the name and position of the Authorising Officer, system owner, date of authorisation, and any decisions to accept residual security risks."},"pspf-0090":{"index":"0090.0","identifier":"pspf-0090","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Each technology system's suitability to be authorised to operate is reassessed when it undergoes significant functionality or architectural change, or where the system's security environment has changed considerably."},"pspf-0091":{"index":"0091.0","identifier":"pspf-0091","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The TikTok application is prevented from being installed, and existing instances are removed, on government devices, unless a legitimate business reason exists which necessitates the installation or ongoing presence of the application."},"pspf-0092":{"index":"0092.0","identifier":"pspf-0092","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"[lt]The Chief Security Officer or Chief Information Security Officer approves any legitimate business reason for the use of the TikTok application on government devices and ensures the following mitigations are in place to manage security risks:[\/lt][ul][li]Ensure the TikTok application is installed and accessed only on a separate, standalone device without access to services that process or access official and classified information.[\/li][li]Ensure the separate, standalone device is appropriately stored and secured when not in use. This includes the isolation of these devices from sensitive conversations and information.[\/li][li]Ensure metadata has been removed from photos, videos and documents when uploading any content to TikTok.[\/li][li]Minimise, where possible, the sharing of personal identifying content on the TikTok application.[\/li][li]Use an official generic email address (for example, a group mailbox) for each TikTok account.[\/li][li]Use multi-factor authentication and unique passphrases for each TikTok account.[\/li][li]Ensure that devices that access the TikTok application are using the latest available operating system in order to control individual mobile application permissions. Regularly check for and update the application to ensure the latest version is used.[\/li][li]Only install the TikTok application from trusted stores such as Microsoft Store, Google Play Store and the Apple App Store.[\/li][li]Ensure only authorised users have access to corporate TikTok accounts and that access (either direct or delegated) is revoked immediately when there is no longer a requirement for that access.[\/li][li]Carefully and regularly review the terms and conditions, as well as application permissions with each update, to ensure appropriate risk management controls can be put in place or adjusted as required.[\/li][li]Delete the TikTok application from devices when access is no longer needed.[\/li][\/ul]"},"pspf-0093":{"index":"0093.0","identifier":"pspf-0093","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Signals Directorate's are applied to manage legacy information technology that cannot yet be replaced."},"pspf-0094":{"index":"0094.0","identifier":"pspf-0094","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Technology assets and their components, classified as SECRET or below are stored in the appropriate Security Zone based on their aggregated security classification or business impact level."},"pspf-0095":{"index":"0095.0","identifier":"pspf-0095","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Technology assets and their components classified as TOP SECRET are stored in suitable SCEC-endorsed racks or compartments within an accredited Security Zone Five area meeting ASIO Technical Note 5\/12 - Compartments within Zone Five areas requirements."},"pspf-0096":{"index":"0096.0","identifier":"pspf-0096","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Outsourced facilities that house technology assets and their components with a catastrophic business impact level are certified by ASIO-T4 physical security and accredited by ASD before they are used operationally."},"pspf-0097":{"index":"0097.0","identifier":"pspf-0097","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Technology assets are disposed of securely in accordance with the Information Security Manual."},"pspf-0098":{"index":"0098.0","identifier":"pspf-0098","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A cyber security strategy and uplift plan is developed, implemented and maintained to manage the entity's cyber security risks in accordance with the Information Security Manual."},"pspf-0099":{"index":"0099.0","identifier":"pspf-0099","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Patch applications mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0100":{"index":"0100.0","identifier":"pspf-0100","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Patch operating systems mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0101":{"index":"0101.0","identifier":"pspf-0101","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Multi-factor authentication mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0102":{"index":"0102.0","identifier":"pspf-0102","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Restrict administrative privileges mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model"},"pspf-0103":{"index":"0103.0","identifier":"pspf-0103","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Application control mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0104":{"index":"0104.0","identifier":"pspf-0104","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Restrict Microsoft Office macros mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0105":{"index":"0105.0","identifier":"pspf-0105","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"User application hardening mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0106":{"index":"0106.0","identifier":"pspf-0106","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Regular back-ups mitigation strategy is implemented to Maturity Level Two under ASD's Essential Eight Maturity Model."},"pspf-0107":{"index":"0107.0","identifier":"pspf-0107","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The remaining mitigation strategies from the Strategies to Mitigate Cyber Security Incidents are considered and, where required, implemented to achieve an acceptable level of residual risk for their entity."},"pspf-0108":{"index":"0108.0","identifier":"pspf-0108","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A Protective Domain Name System service or other security mechanisms is used to prevent connections to and from known malicious endpoints."},"pspf-0109":{"index":"0109.0","identifier":"pspf-0109","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Cloud Service Providers that have completed an IRAP assessment against the current version of ASD's Information Security Manual within the previous 24 months are used."},"pspf-0110":{"index":"0110.0","identifier":"pspf-0110","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entities consider IRAP assessment recommendations and findings and implement on a risk-based approach."},"pspf-0111":{"index":"0111.0","identifier":"pspf-0111","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"OFFICIAL: Sensitive and PROTECTED government information and data is securely hosted using a Cloud Service Provider and Data Centre Provider that has been certified against the Australian Government Hosting Certification Framework."},"pspf-0112":{"index":"0112.0","identifier":"pspf-0112","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Data Centre Facilities Supplies Panel is used when procuring certified data centre space and services."},"pspf-0113":{"index":"0113.0","identifier":"pspf-0113","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Internet-connected technology systems, and the data they process, store or communicate, are protected by a gateway in accordance with the Information Security Manual and the Gateways Policy"},"pspf-0114":{"index":"0114.0","identifier":"pspf-0114","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Gateways that have completed an IRAP assessment against ASD's Information Security Manual within the previous 24 months are used."},"pspf-0115":{"index":"0115.0","identifier":"pspf-0115","revision":"0","date":1729838435,"updated":"Oct-24","domain":"TECH","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A vulnerability disclosure program and supporting processes and procedures are established to receive, verify, resolve and report on vulnerabilities disclosed by both internal and external sources"},"pspf-0116":{"index":"0116.0","identifier":"pspf-0116","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The eligibility and suitability of personnel who have access to Australian Government people and resources is ensured."},"pspf-0117":{"index":"0117.0","identifier":"pspf-0117","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The pre-employment screening identity check is conducted for all personnel, to verify identity to at least Level 3 (High) of Assurance of the National Identity Proofing Guidelines."},"pspf-0118":{"index":"0118.0","identifier":"pspf-0118","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Biographic information in identity documents is verified to ensure the information matches the original record."},"pspf-0119":{"index":"0119.0","identifier":"pspf-0119","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The pre-employment screening eligibility check is conducted for all personnel, to confirm their eligibility to work in Australia and for the Australian Government."},"pspf-0120":{"index":"0120.0","identifier":"pspf-0120","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The entity obtains assurance of each person's suitability to access Australian Government resources, including their agreement to comply with the government's policies, standards, protocols and guidelines that safeguard resources from harm, during pre-employment screening."},"pspf-0121":{"index":"0121.0","identifier":"pspf-0121","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Prior to granting temporary access to security classified information or resources, pre-employment checks are completed, and an existing Negative Vetting 1 security clearance is confirmed prior to granting temporary access to TOP SECRET information data or resources."},"pspf-0122":{"index":"0122.0","identifier":"pspf-0122","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A risk assessment determines whether a person is granted temporary access to security classified information or resources."},"pspf-0123":{"index":"0123.0","identifier":"pspf-0123","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Temporary access to security classified information, resources and activities is supervised."},"pspf-0124":{"index":"0124.0","identifier":"pspf-0124","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Short-term temporary access to security classified information, resources and activities is limited to the period in which an application for a security clearance is being processed for the particular person, or up to a total combined maximum of three months in a 12-month period for all entities."},"pspf-0125":{"index":"0125.0","identifier":"pspf-0125","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Authorised Vetting Agency confirms that the completed security clearance pack has been received and that no initial concerns have been identified for the clearance subject, before short-term temporary access is changed to provisional temporary access."},"pspf-0126":{"index":"0126.0","identifier":"pspf-0126","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Temporary access to classified caveated information, resources or activities is not granted, other than in exceptional circumstances, and only with the approval of the caveat controlling authority"},"pspf-0127":{"index":"0127.0","identifier":"pspf-0127","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Prior to granting temporary access, the entity obtains an undertaking from the person to protect the security classified information, resources and activities they will access."},"pspf-0128":{"index":"0128.0","identifier":"pspf-0128","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Prior to granting temporary access, the entity obtains agreement from any other entity (or third party) whose security classified information, resources and activities will be accessed by the person during the temporary access period."},"pspf-0129":{"index":"0129.0","identifier":"pspf-0129","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Access to official information is facilitated for entity personnel and other relevant stakeholders."},"pspf-0130":{"index":"0130.0","identifier":"pspf-0130","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Appropriate access to official information is enabled, including controlling access (including remote access) to supporting technology systems, networks, infrastructure, devices and applications."},"pspf-0131":{"index":"0131.0","identifier":"pspf-0131","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Access to security classified information or resources is only given to entity personnel with a need-to-know that information."},"pspf-0132":{"index":"0132.0","identifier":"pspf-0132","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Personnel requiring ongoing access to security classified information or resources are security cleared to the appropriate level."},"pspf-0133":{"index":"0133.0","identifier":"pspf-0133","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Personnel requiring access to caveated information meet any clearance and suitability requirements imposed by the originator and caveat controlling authority."},"pspf-0134":{"index":"0134.0","identifier":"pspf-0134","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A unique user identification, authentication and authorisation practice is implemented on each occasion where system access is granted, to manage access to systems holding security classified information."},"pspf-0135":{"index":"0135.0","identifier":"pspf-0135","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A security risk assessment of the proposed location and work environment informs decisions by the Chief Security Officer to allow personnel to work in another government entity's facilities in Australia."},"pspf-0136":{"index":"0136.0","identifier":"pspf-0136","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"An agreement is in place to manage the security risks associated with personnel working in another government entity's facilities in Australia."},"pspf-0137":{"index":"0137.0","identifier":"pspf-0137","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Approval for remote access to TOP SECRET information, data or systems in international locations outside of facilities meeting PSPF requirements, is only granted if approved by the Australian Signals Directorate."},"pspf-0138":{"index":"0138.0","identifier":"pspf-0138","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A security risk assessment of the proposed location and work environment informs decisions to allow personnel to work remotely in international locations."},"pspf-0139":{"index":"0139.0","identifier":"pspf-0139","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Personnel are not granted approval to work remotely in locations where Australian Government information, or resources are exposed to extrajudicial directions from a foreign government that conflict with Australian law, unless operationally required, and the residual risks are managed and approved by the Chief Security Officer."},"pspf-0140":{"index":"0140.0","identifier":"pspf-0140","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Australian Government Security Vetting Agency (AGSVA) or the TOP SECRET-Privileged Access Vetting Authority is used to conduct security vetting, or where authorised, the entity conducts security vetting in a manner consistent with the Personnel Security Vetting Process and Australian Government Personnel Security Adjudicative Standard."},"pspf-0141":{"index":"0141.0","identifier":"pspf-0141","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"All vetting personnel attain and maintain the required skills and competencies for their role."},"pspf-0142":{"index":"0142.0","identifier":"pspf-0142","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The gaining sponsoring entity establishes new clearance conditions before assuming sponsorship of an existing security clearance that is subject to clearance conditions."},"pspf-0143":{"index":"0143.0","identifier":"pspf-0143","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The gaining sponsoring entity undertakes the exceptional business requirement and risk assessment provisions prior to requesting transfer of sponsorship of an existing security clearance that is subject to an eligibility waiver."},"pspf-0144":{"index":"0144.0","identifier":"pspf-0144","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Authorised Vetting Agency only issues a security clearance where the clearance is sponsored by an Australian Government entity or otherwise authorised by the Australian Government."},"pspf-0145":{"index":"0145.0","identifier":"pspf-0145","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Positions that require a security clearance are identified and the level of clearance required is documented."},"pspf-0146":{"index":"0146.0","identifier":"pspf-0146","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Each person working in an identified position has a valid security clearance issued by the relevant Authorised Vetting Agency."},"pspf-0147":{"index":"0147.0","identifier":"pspf-0147","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Australian citizenship is confirmed and pre-employment screening is completed before the entity seeks a security clearance for a person in a position identified as requiring a security clearance."},"pspf-0148":{"index":"0148.0","identifier":"pspf-0148","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity establishes an exceptional business need and conducts a risk assessment before a citizenship eligibility waiver is considered for a non-Australian citizen who has a valid visa and work rights to work in an identified position."},"pspf-0149":{"index":"0149.0","identifier":"pspf-0149","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Accountable Authority (or the Chief Security Officer if delegated) approves a citizenship eligibility waiver only after accepting the residual risk of waiving the citizenship requirement for that person, and maintains a record of all citizenship eligibility waivers approved."},"pspf-0150":{"index":"0150.0","identifier":"pspf-0150","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity establishes an exceptional business need and conducts a risk assessment (including seeking advice from the Authorised Vetting Agency), before a checkable background eligibility waiver is considered for a clearance subject assessed as having an uncheckable background."},"pspf-0151":{"index":"0151.0","identifier":"pspf-0151","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity's Accountable Authority (or the Chief Security Officer if delegated) approves checkable background eligibility waivers only after accepting the residual risk of waiving the checkable background requirement for each person, and maintains a record of all checkable background eligibility waivers approved."},"pspf-0152":{"index":"0152.0","identifier":"pspf-0152","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency provides the Sponsoring Entity with information to inform a risk assessment if a clearance subject has an uncheckable background and only issues a clearance if the Accountable Authority waives the checkable background requirement and provides the Authorised Vetting Agency with a copy of the waiver."},"pspf-0153":{"index":"0153.0","identifier":"pspf-0153","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The clearance subject's informed consent is given to collect, use and disclose their personal information for the purposes of assessing and managing their eligibility and suitability to hold a security clearance."},"pspf-0154":{"index":"0154.0","identifier":"pspf-0154","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by considering their integrity (i.e. the character traits of maturity, trustworthiness, honesty, resilience, tolerance and loyalty) in accordance with the Australian Government Personnel Security Adjudicative Standard."},"pspf-0155":{"index":"0155.0","identifier":"pspf-0155","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The clearance subject's eligibility and suitability to hold a TOP SECRET-Privileged Access security clearance is assessed in accordance with the TOP SECRET-Privileged Access Standard."},"pspf-0156":{"index":"0156.0","identifier":"pspf-0156","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by conducting the minimum personnel security checks for the commensurate security clearance level."},"pspf-0157":{"index":"0157.0","identifier":"pspf-0157","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The clearance subject's eligibility and suitability to hold a Baseline, Negative Vetting 1, Negative Vetting 2 or Positive Vetting security clearance is assessed by resolving any doubt in the national interest."},"pspf-0158":{"index":"0158.0","identifier":"pspf-0158","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"[lt]Concerns that are identified during the vetting or security clearance suitability assessment process, that are not sufficient to deny a security clearance and where the related risks can be managed through conditions attached to the security clearance, the Authorised Vetting Agency must:[\/lt][ul][li]identify the clearance conditions[\/li][li]provide the sponsoring entity with information about the concerns to inform a risk assessment[\/li][li]only issue a conditional security clearance if the Accountable Authority and the clearance subject accept the clearance conditions. The Accountable Authority may delegate this decision to the Chief Security Officer, however the Chief Security Officer is required to notify the Accountable Authority of the clearance conditions.[\/li][\/ul]"},"pspf-0159":{"index":"0159.0","identifier":"pspf-0159","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency provides the sponsoring entity with any other relevant information of concern that is identified during the vetting process when advising them of the outcome of the security vetting process, to inform the sponsoring entity's risk assessment."},"pspf-0160":{"index":"0160.0","identifier":"pspf-0160","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency applies the rules of procedural fairness to security clearance decisions that are adverse to a clearance subject, including decisions to deny a security clearance (including grant lower level) or grant a conditional security clearance, without compromising the national interest."},"pspf-0161":{"index":"0161.0","identifier":"pspf-0161","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency reviews the conditions of conditional security clearances annually."},"pspf-0162":{"index":"0162.0","identifier":"pspf-0162","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency reviews the clearance holder's eligibility and suitability to hold a security clearance, where concerns are identified (review for cause)."},"pspf-0163":{"index":"0163.0","identifier":"pspf-0163","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised TOP SECRET-Privileged Access Vetting Agency implements the TOP SECRET-Privileged Access Standard in relation to the ongoing assessment and management of personnel with TOP SECRET-Privileged Access security clearances."},"pspf-0164":{"index":"0164.0","identifier":"pspf-0164","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Sponsoring Entity actively assesses, monitors and manages the ongoing suitability of personnel."},"pspf-0165":{"index":"0165.0","identifier":"pspf-0165","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Sponsoring Entity monitors and manages compliance with any conditional security clearance requirements and reports any non-compliance to the Authorised Vetting Agency."},"pspf-0166":{"index":"0166.0","identifier":"pspf-0166","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Sponsoring Entity monitors and manages compliance with security clearance maintenance obligations for the clearance holders they sponsor."},"pspf-0167":{"index":"0167.0","identifier":"pspf-0167","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity shares relevant information of concern, where appropriate."},"pspf-0168":{"index":"0168.0","identifier":"pspf-0168","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity conducts an annual security check with all security cleared personnel."},"pspf-0169":{"index":"0169.0","identifier":"pspf-0169","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity reviews eligibility waivers at least annually, before revalidation of a security clearance, and prior to any proposed position transfer."},"pspf-0170":{"index":"0170.0","identifier":"pspf-0170","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity monitors, assesses and manages personnel with TOP SECRET-Privileged access security clearances in accordance with the TOP SECRET-Privileged Access Standard."},"pspf-0171":{"index":"0171.0","identifier":"pspf-0171","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency reassesses a clearance holder's eligibility and suitability to hold a security clearance by revalidating minimum personnel security checks for a security clearance"},"pspf-0172":{"index":"0172.0","identifier":"pspf-0172","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency reassesses a clearance holder's eligibility and suitability to hold a Baseline, Negative vetting 1, Negative Vetting 2 or Positive Vetting security clearance, by considering their integrity in accordance with the Australian Government Personnel Security Adjudicative Standard."},"pspf-0173":{"index":"0173.0","identifier":"pspf-0173","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The TOP SECRET-Privileged Access Vetting Authority reassesses a clearance holder's eligibility and suitability to hold a TOP SECRET-Privileged Access security clearance, by, assessing their trustworthiness in accordance with the TOP SECRET-Privileged Access Standard."},"pspf-0174":{"index":"0174.0","identifier":"pspf-0174","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency reassess a clearance holder's eligibility and suitability to hold a security clearance by resolving any doubt in the national interest."},"pspf-0175":{"index":"0175.0","identifier":"pspf-0175","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency commences the security clearance revalidation process in sufficient time to complete the revalidation before the due date so that the security clearance does not lapse."},"pspf-0176":{"index":"0176.0","identifier":"pspf-0176","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency shares information of concern about security clearance holders with the Sponsoring Entity so they can decide whether to suspend or limit the clearance holder's access to Australian Government classified information, resources or activities until the concerns are resolved."},"pspf-0177":{"index":"0177.0","identifier":"pspf-0177","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Sponsoring Entity shares relevant information of security concern, where appropriate with the Authorised Vetting Agency."},"pspf-0178":{"index":"0178.0","identifier":"pspf-0178","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency shares information of security concern about security clearance holders with the Sponsoring Entity."},"pspf-0179":{"index":"0179.0","identifier":"pspf-0179","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency assesses and responds to information of security concern about security clearance holders, including reports from Sponsoring Entities."},"pspf-0180":{"index":"0180.0","identifier":"pspf-0180","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Negative Vetting 2 and higher clearance holders receive appropriate departmental travel briefings when undertaking international personal and work travel."},"pspf-0181":{"index":"0181.0","identifier":"pspf-0181","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Chief Security Officer, Chief Information Security Officer (or other relevant security practitioner) is advised prior to separation or transfer of any proposed cessation of employment resulting from misconduct or other adverse reasons."},"pspf-0182":{"index":"0182.0","identifier":"pspf-0182","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Separating personnel are informed of any ongoing security obligations under the Commonwealth Criminal Code and other relevant legislation and those holding a security clearance or access security classified information are debriefed prior to separation from the entity."},"pspf-0183":{"index":"0183.0","identifier":"pspf-0183","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Separating personnel transferring to another Australian Government entity, the entity, when requested, provides the receiving entity with relevant security information, including the outcome of pre-employment screening checks and any periodic employment suitability checks."},"pspf-0184":{"index":"0184.0","identifier":"pspf-0184","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Separating personnel transferring to another Australian Government entity, the entity reports any security concerns (as defined in the in the Australian Security Intelligence Organisation Act 1979) to the Australian Security Intelligence Organisation."},"pspf-0185":{"index":"0185.0","identifier":"pspf-0185","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A risk assessment is completed to identify any security implications in situations where it is not possible to undertake the required separation procedures."},"pspf-0186":{"index":"0186.0","identifier":"pspf-0186","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Separating personnel have their access to Australian Government resources withdrawn upon separation or transfer from the entity, including information, technology systems, and resources."},"pspf-0187":{"index":"0187.0","identifier":"pspf-0187","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The Sponsoring Entity advises the relevant Authorised Vetting Agency of the separation of a clearance holder, including any relevant circumstances (e.g. termination for cause) and any details, if known, of another entity or contracted service provider the clearance holder is transferring to, along with any identified risks or security concerns associated with the separation."},"pspf-0188":{"index":"0188.0","identifier":"pspf-0188","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PER","applicability":["AVA"],"applicability_string":"AVA","content":"The Authorised Vetting Agency manages and records changes in the security clearance status of separating personnel, including a change of Sponsoring Entity, and transfer personal security files where a clearance subject transfers to an entity covered by a different Authorised Vetting Agency, to the extent that their enabling legislation allows."},"pspf-0189":{"index":"0189.0","identifier":"pspf-0189","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Protective security is integrated in the process of planning, selecting, designing and modifying entity facilities for the protection of people, information and resources."},"pspf-0190":{"index":"0190.0","identifier":"pspf-0190","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"A facility security plan is developed for new facilities, facilities under construction or major refurbishments of existing facilities."},"pspf-0191":{"index":"0191.0","identifier":"pspf-0191","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Decisions on entity facility locations are informed by considering the site selection factors for Australian Government facilities."},"pspf-0192":{"index":"0192.0","identifier":"pspf-0192","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"When designing or modifying facilities, the entity secures and controls access to facilities to meet the highest risk level to entity resources in accordance with Security Zone restricted access definitions."},"pspf-0193":{"index":"0193.0","identifier":"pspf-0193","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"[lt]Facilities are constructed in accordance the applicable ASIO Technical Notes to protect against the highest risk level in accordance with the entity security risk assessment in areas:[\/lt][ul][li]accessed by the public and authorised personnel, and[\/li][li]where physical resources and technical assets, other than security classified resources and technology, are stored.[\/li][\/ul]"},"pspf-0194":{"index":"0194.0","identifier":"pspf-0194","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Facilities for Security Zones Two to Five that process, store or communicate security classified information and resources are constructed in accordance with the applicable sections of ASIO Technical Note 1\/15 - Physical Security Zones, and ASIO Technical Note 5\/12 - Physical Security Zones (TOP SECRET) areas."},"pspf-0195":{"index":"0195.0","identifier":"pspf-0195","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Entity facilities are operated and maintained in accordance with Security Zones and Physical Security Measures and Controls."},"pspf-0196":{"index":"0196.0","identifier":"pspf-0196","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security Zones One to Four are certified by the Certification Authority in accordance with the PSPF and applicable ASIO Technical Notes before they are used operationally"},"pspf-0197":{"index":"0197.0","identifier":"pspf-0197","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security Zone Five areas that contain TOP SECRET security classified information or aggregated information where the compromise of confidentiality, loss of integrity or unavailability of that information may have a catastrophic business impact level, are certified by ASIO-T4 before they are used operationally"},"pspf-0198":{"index":"0198.0","identifier":"pspf-0198","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security Zones One to Five are accredited by the Accreditation Authority before they are used operationally, on the basis that the required security controls are certified and the entity determines and accepts the residual risks."},"pspf-0199":{"index":"0199.0","identifier":"pspf-0199","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Sensitive Compartmented Information Facility areas used to secure and access TOP SECRET systems and security classified compartmented information are accredited by the Australian Signals Directorate before they are used operationally"},"pspf-0200":{"index":"0200.0","identifier":"pspf-0200","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Physical security measures are implemented to minimise or remove the risk of information and physical asset resources being made inoperable or inaccessible, or being accessed, used or removed without appropriate authorisation."},"pspf-0201":{"index":"0201.0","identifier":"pspf-0201","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Physical security measures are implemented to protect entity resources, commensurate with the assessed business impact level of their compromise, loss or damage."},"pspf-0202":{"index":"0202.0","identifier":"pspf-0202","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Physical security measures are implemented to minimise or remove the risk of harm to people."},"pspf-0203":{"index":"0203.0","identifier":"pspf-0203","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"The appropriate container, safe, vault, cabinet, secure room or strong rooms is used to protect entity information and resources based on the applicable Security Zone and business impact level of the compromise, loss or damage to information or physical resources."},"pspf-0204":{"index":"0204.0","identifier":"pspf-0204","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Perimeter doors and hardware in areas that process, store communicate security classified information or resources are constructed and secured in accordance with the physical security measures and controls for perimeter doors and hardware."},"pspf-0205":{"index":"0205.0","identifier":"pspf-0205","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Access by authorised personnel, vehicles and equipment to Security Zones One to Five is controlled in accordance with the physical security measures and controls for access control for authorised personnel."},"pspf-0206":{"index":"0206.0","identifier":"pspf-0206","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Access by visitors to Security Zones One to Five is controlled in accordance with the physical security measures and controls for access control for visitors."},"pspf-0207":{"index":"0207.0","identifier":"pspf-0207","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"[lt]The Accountable Authority or Chief Security Officer approves ongoing (or regular) access to entity facilities for people who are not directly engaged by the entity or covered by the terms of a contract or agreement, on the basis that the person:[\/lt][ul][li]has the required security clearance level for the Security Zone\/s, and[\/li][li]a business need supported by a business case and security risk assessment, which is reassessed at least every two years.[\/li][\/ul]"},"pspf-0208":{"index":"0208.0","identifier":"pspf-0208","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Unauthorised access to Security Zones One to Five is controlled in accordance with the physical security measures and controls for security alarm systems."},"pspf-0209":{"index":"0209.0","identifier":"pspf-0209","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Security guard arrangements in Security Zones One to Five are established in accordance with the physical security measures and controls for security guards."},"pspf-0210":{"index":"0210.0","identifier":"pspf-0210","revision":"0","date":1729838435,"updated":"Oct-24","domain":"PHYS","applicability":["TAE","DOS","AVA","SSPE","NCCE","CCE","CC","NGO"],"applicability_string":"ALL","content":"Technical surveillance countermeasures for Security Zones One to Five are established in accordance with the physical security measures and controls for technical surveillance countermeasures."}}},"count":210}