The Defence Industry Security Program, managed by the Defence Industry Security Branch, is a multilevel membership based program underpinned by the Defence Security Principles Framework.
The Defence Industry Security Program, managed by the Defence Industry Security Branch, is a multilevel membership based program underpinned by the Defence Security Principles Framework.
Its purpose is to:
Ensure industry has the right security in place for Defence tenders and contracts.
Provide industry with access to security advice and support services.
Help industry to understand and manage security risks.
Provide confidence and assurance to Defence and other government entities when procuring goods and services from industry members.
Membership to DISP provides entities with:
The timeframe between submitting an application and receiving DISP membership will vary with each entity and depend upon:
DISP membership is open to any Australian entities (with an ABN or ACN) looking to become part of the Defence industry supply chain.
DISP membership is open to Australian entities looking to become part of the Defence industry supply chain. To become a DISP member an industry entity needs to meet base eligibility criteria. There are also additional criteria based on the level of membership required.
Depending on the type of work an entity undertakes with Defence, or any contractual requirements, DISP membership may be mandated. Membership is not mandated in all circumstances. However, it is highly recommended for any entity currently working on Defence projects or for those seeking to partner with Defence
DISP has four membership levels within each security domain:
Entry :Official / Official: Sensitive
One: Protected
Two: Secret
Three: Top Secret
These levels reflect the security obligations that align with the Australian Classification System, applicants can selfnominate the membership levels they wish to apply for.
Nominations must reflect the level of security required to meet current and/or likely Defence security obligations. Membership levels 1-3 require a supporting business case.
Entities that are entering new contracts, tenders or projects, may require a higher membership level. The Defence Security Principles Framework (DSPF) can assist in determining what level of membership is required based on business needs or contractual requirements.
DISP membership comes with ongoing responsibilities at every level.
These include but are not limited to:
The safeguard of Defence and industry’s people, information and assets.
Appointing and retaining a CSO and SO.
Reporting changes that may affect DISP membership.
Submitting an Annual Security Report (ASR) every 12 months from the start date of DISP membership.
Regular security training of staff including induction training.
Ongoing employment screening and suitability checks.
Maintaining a classified document register if accessing information at Official Sensitive or higher.
Adhering to mandatory requirements regarding personnel access to Defence buildings and systems.
In the event of any security incidents, submit an XP188 Security Report form and notify your Security Officer. The Security Incident Coordination Centre will ensure the security incident is effectively managed. In accordance with DSPF Control 77.1, persons engaged under a contract
must also report the incident to their contract manager.
The foundation of ZERO TRUST security is identities. Both human and non-human identities need strong authorisation, connecting from either personal or corporate endpoints with compliant devices, requesting access based on strong policies grounded in ZERO TRUST principles of explicit verification, least-privilege access, and assumed breach.
As a unified policy enforcement, the ZERO TRUST policy intercepts the request, explicitly verifies signals from all six foundational elements based on policy configuration and enforces least-privilege access. Signals include the role of the user, location, device compliance, data sensitivity, and application sensitivity.
This policy is further enhanced by policy optimisation. Governance and compliance are critical to a strong ZERO TRUST implementation. Security posture assessment and productivity optimisation are necessary to measure the telemetry throughout the services and systems.
Traffic filtering and segmentation is applied to the evaluation and enforcement of the ZERO TRUST POLICY before access is granted to any public or private network.
The telemetry and analytics feed into the threat-protection system. Large amounts of telemetry and analytics enriched by threat intelligence generate high-quality risk assessments that can be either manually investigated or automated. Attacks happen at cloud speed, and because humans can’t react quickly enough or sift through all the risks, your defence systems must also act at cloud speed.
DISP membership requirements are articulated across four security domains. These security pillars provide the foundation to safeguard you, your company or business and the integrity of Defence’s information, assets and people.
SECURITY GOVERNANCE
Security governance refers to an entity’s accountability and responsibility for ensuring suitable plans, processes and people are in place to maintain the relevant levels of security.
It is having appropriate practices across physical security, personnel security, information and cyber security. This includes appropriate security education and training, and security incident response and reporting.
Security governance reflects an entity’s ability to safeguard people, information and assets.
There are a number of specific documents required to support the entity’s DISP application.
Ongoing security governance obligations for DISP membership also include regular reporting documents that are self-managed and submitted for ongoing membership management.
PHYSICAL SECURITY
Physical security is the protection of people, property, and physical assets from actions and events that could result in damage or loss.
A secure physical environment helps to prevent or mitigate threats or attacks against Defence facilities, personnel, security protected information and assets. Physical security establishes the environment threat actors must work in, and is a building block of effective insider threat management and cyber security.
Physical security measures and procedures are continuously evolving as new threats emerge.
DISP membership requirements for physical security will depend on the level of security classification required for the receipt, handling, storage and destruction of information or physical assets that are being held at the facilities.
PERSONNEL SECURITY
Personnel security encompasses the suitability of an entity’s employees and contractors to access government information and assets. This involves ensuring personnel have an appropriate standard of security competence, integrity and honesty.
Employment screening applies to security cleared and non-security cleared personnel, contractors and others who will have access to Australian Government resources.
DISP members need to meet Australian Standard for Workforce Screening AS 4811:2022 standard.
INFORMATION AND CYBER SECURITY
The Information and Cyber Security domain relates to the protection of Defence Official Information. DISP members may hold on their corporate system while ensuring appropriate security controls are in place.
To meet the Information and Cyber Security DISP membership requirements, an entity will need to demonstrate how they meet or exceed the Australian Signals Directorate (ASD) Essential Eight (E8) Mitigation Strategies at Maturity Level 2 across its ICT systems used to correspond with Defence.
The foundation of ZERO TRUST security is identities. Both human and non-human identities need strong authorisation, connecting from either personal or corporate endpoints with compliant devices, requesting access based on strong policies grounded in ZERO TRUST principles of explicit verification, least-privilege access, and assumed breach.
As a unified policy enforcement, the ZERO TRUST policy intercepts the request, explicitly verifies signals from all six foundational elements based on policy configuration and enforces least-privilege access. Signals include the role of the user, location, device compliance, data sensitivity, and application sensitivity.
This policy is further enhanced by policy optimisation. Governance and compliance are critical to a strong ZERO TRUST implementation. Security posture assessment and productivity optimisation are necessary to measure the telemetry throughout the services and systems.
Traffic filtering and segmentation is applied to the evaluation and enforcement of the ZERO TRUST POLICY before access is granted to any public or private network.
The telemetry and analytics feed into the threat-protection system. Large amounts of telemetry and analytics enriched by threat intelligence generate high-quality risk assessments that can be either manually investigated or automated. Attacks happen at cloud speed, and because humans can’t react quickly enough or sift through all the risks, your defence systems must also act at cloud speed.
DISP is underpinned by an assurance framework to ensure members maintain an appropriate security posture. Where a DISP member demonstrates persistent disregard for DISP requirements or fails to undertake agreed corrective actions, Defence has scalable response options including downgrading, suspending or terminating their DISP membership – all impacting their ability to work with Defence and its supply chains. Layered Assurance measures include:
An Annual Security Report (ASR) is a self-attestation, completed by DISP members, of compliance with security obligations under DSPF which is due on the anniversary of the DISP membership certificate. An ASR is required to be tabled with the entity’s Board or Executive (or other equivalent Governance forum) prior to submission to DISP, to ensure that appropriate Executive oversight and action is taken in response to any security issues identified.
DISP members may be required to provide additional information to DISP regarding the ASR responses provided.
ASRs are submitted through the DISP Member Portal.
An Ongoing Suitability Assessment (OSA) is a desktop audit to ensure that members are continuing to meet Defence security obligations. OSA selection is an outcome of an internal risk-based framework. An OSA will assess DISP member’s compliance with a selection of security requirements across all 4 DISP security domains.
The OSA process includes a review of security documentation, a phone interview with security staff and the completion of a cyber-questionnaire. This activity assists DISP members to review, and where needed, improve their security policies, procedures, and risk management.
The DISP approach to deep dive audit (DDA) is one of collaboration.
The objective of a DDA is to ascertain the extent of DISP members’ compliance with requirements of DSPF Control 16.1 through a detailed assessment (including site visits) of the adequacy of Defence security processes and controls in place, and if needed help to uplift an entities security posture. DISP members are selected for inclusion in a DDA based on an internal risk-based selection framework.
All identified security uplift activities or opportunities for improvement are discussed, and a draft report for review and comment is provided prior to being finalised. The implementation of all DDA recommendations is monitored by the DISP audit team.
To meet DISP membership requirements, an entity must comply with the E8 at ML2, which is derived from the the Australian Government Information Security Manual.
To complete the Cyber Security Questionnaire (CSQ), provide comprehensive responses and evidence to the questions in the DISP E8 CSQ. It is recommended the CSQ be completed by an authorised representative who has sufficient knowledge of your/the organisation’s corporate IT infrastructure. Incomplete answers or insufficient information will delay the application.
Within the CSQ, the ‘Tool Tips’ features relevant information on control implementation and acceptable evidence (in accordance with ASD’s guidance).
The foundation of ZERO TRUST security is identities. Both human and non-human identities need strong authorisation, connecting from either personal or corporate endpoints with compliant devices, requesting access based on strong policies grounded in ZERO TRUST principles of explicit verification, least-privilege access, and assumed breach.
As a unified policy enforcement, the ZERO TRUST policy intercepts the request, explicitly verifies signals from all six foundational elements based on policy configuration and enforces least-privilege access. Signals include the role of the user, location, device compliance, data sensitivity, and application sensitivity.
This policy is further enhanced by policy optimisation. Governance and compliance are critical to a strong ZERO TRUST implementation. Security posture assessment and productivity optimisation are necessary to measure the telemetry throughout the services and systems.
Traffic filtering and segmentation is applied to the evaluation and enforcement of the ZERO TRUST POLICY before access is granted to any public or private network.
The telemetry and analytics feed into the threat-protection system. Large amounts of telemetry and analytics enriched by threat intelligence generate high-quality risk assessments that can be either manually investigated or automated. Attacks happen at cloud speed, and because humans can’t react quickly enough or sift through all the risks, your defence systems must also act at cloud speed.
Application control
Checking programs against a pre-defined approved list and blocking all programs not on this list.
Patch applications
Apply security fixes/patches or mitigations (temporary workarounds) for programs within a timely manner (48 Hours for internet reachable applications). Do not use applications which are out-of-support and do not receive security fixes.
Restrict Microsoft Office Macros
Only allow Office macros (automated commands) where there is a business requirement and restrict the type of commands a macro can execute. Also monitor usage of Macros.
User application hardening
Configure key programs (web browsers, office, PDF software, etc.) to apply settings that will make it more difficult for an attacker to successfully run commands to install malware
Restrict administrative privileges
Limit how accounts with the ability to administer and alter key system and security settings can be accessed and used.
Patch operating systems
Apply security fixes/patches or temporary workarounds/mitigations for operating systems (e.g. Windows) within a timely manner (48 Hours for internet reachable applications). Do not use versions of an Operating system which are old and/or not
receiving security fixes.
Multi-factor authentication
A method of validating the user logging in by using additional checks separate to a password such as a code from an SMS/Mobile application or fingerprint scan.
Regular backups
Regular backups of important new or changed data, software and configuration settings, stored disconnected and retained for at least three months. Test the restoration process when the backup capability is initially implemented, annually and whenever IT infrastructure changes.
Malicious cyber activity continues to pose a risk to Australia’s security and prosperity. The Cyber Security Questionnaire through the ASR has been uplifted to encompass the full Essential Eight (E8). This will increase the cyber hygiene and resilience for DISP Members.
DISP will provide a maturity action plan for E8 uplift when required. There are grants available to help SME DISP members cover expenses required to become compliant with E8.
E8 – NOVEMBER 2023
ASD has developed prioritised mitigation strategies to assist organisations mitigate cyber security incidents caused by various cyber threats.
The most effective of the mitigation strategies are the E8, which outlines a minimum set of preventative measures at graduated levels of maturity.
The DISP cyber standards are uplifting to assess against all the Mitigation Strategies that constitute the E8 at Maturity Level 2 (ML2)
Under the 2023 version at ML2, there are 107 security controls to be assessed.
Essential Eight Maturity Level 2 (ML2) is a mandatory cyber security requirement for organisations participating in the Defence Industry Security Program (DISP).
CISO Online™ can assist your organisation in preparing for DISP requirements by assessing your current Essential Eight maturity level, identifying compliance gaps, and implementing the technical and governance controls required to achieve and maintain Essential Eight Maturity Level 2 (ML2).
Our services help ensure your environment is aligned with DISP cyber
security obligations and industry best practices.
We are backed by leading security vendors and reputable associations to strengthen your cyber security. Our team of experts shares their knowledge and experience to provide you with the best solutions.