Australian entities seeking to partner with Defence have an obligation to contribute to the security of Defence people, information and assets. These entities are required to meet the eligibility criteria defined in the Defence Security Principles Framework (DSPF) - Principle 16 Control 16.1. It provides principles, controls and instructions to support entities to understand and manage security risks when engaging with Defence. Membership is dependent on entities demonstrating appropriate security governance, personnel security, physical security and ICT and cyber security. In 2024 the DISP Cyber Security Standard uplifted from the Australian Signals Directorate (ASD) ‘Top 4’ of the Essential Eight Mitigation Strategies (at Maturity Level 1) to the full Essential Eight Mitigation Strategies at Maturity Level 2.
The Australian Cyber Security Centre's (ACSC) Essential Eight framework outlines baseline strategies to mitigate cyber security incidents that DISP requires organisations to meet. All DISP members must meet or exceed E8 ML2 controls across all ICT systems used in Defence communications. E8 ML2 is designed to counter more sophisticated adversaries who employ advanced techniques, such as credential theft through phishing and social engineering. For organisations engaged with the Australian Department of Defence, aligning with DISP requirements necessitates meeting or exceeding Essential Eight controls at ML2 across all ICT systems used in Defence communications come June 2025. Visit Defence to dive deeper into each eight strategies. (Link)
You may need help to make your hardware, operating systems and applications DISP compliant. x-RD offers:
By partnering with x-RD, organisations can confidently advance their cyber security maturity to Essential Eight Maturity Level 2, ensuring robust protection against sophisticated threats and seamless alignment with DISP standards.
To learn more about our solutions and services, or how we can help your business - get in touch with us.