In a joint Australian Signals Directorate (ASD) and Digital Transformation Agency (DTA) Public Statement on Independent Review of CSCP and IRAP, the ASD has announced it will crease the CSCP, as of 2 March 2020. ASD will no longer be the Certification Authority and will not be progressing certification activities. This includes re-certification activities.
All services listed on the Certified Cloud Services List (CCSL) will remain ASD certified until 30 June 2020. All ASD certifications and re-certification letters will be void from this date and the Australian Government Information Security Manual (ISM) will be updated to remove the requirement to select cloud services from the CCSL.
The cessation of the CSCP will open up the Australian cloud market to allow for more home-grown Australian providers to operate. This will also give government customers a greater range of secure and cost effective cloud services.
In late July 2019, the Australian Signals Directorate (ASD) commissioned an independent review of its Cloud Services Certification Program (CSCP) and Information Security Registered Assessors Program (IRAP).
The Review considered the perspectives of industry and government stakeholders to ensure the proposed recommendations support Commonwealth entities, Australian businesses and the community while maximising cyber security and resilience to protect against evolving cyber threats.
The review made the following recommendations:
- Close the CSCP and create new co-designed cloud security guidelines with industry
- Grow and enhance IRAP
- Establish Government and Industry Consultative Forums for cyber security
- Update incentives in Procurement and Administrative Instructions and Guidance to reflect the cessation of the CSCP.
Information Security Registered Assessors Program (IRAP)
ASD will enhance its support and delivery of IRAP. Now that the review has concluded, ASD will be accepting applications for new IRAP Assessors and will restart IRAP training sessions.
The boost to the IRAP community will deliver greater resources and higher standards to support government in maintaining its assurance and risk management activities.
ASD will improve the training and assessment of IRAP assessors to bring a greater consistency of skills within the IRAP community.
For the full statement, visit here