Independent public Guidelines referenceNot an Australian Government serviceHow ServiceCite worksAbout
ServiceCite
Part A: Universal Guidelines

DEWR source chapter · ServiceCite reference page

Chapter 4. External Systems Assurance Framework (ESAF)

Department wording for Chapter 4, External Systems Assurance Framework (ESAF), from Part A: Universal Guidelines version 1.16.

Version and source status

Workforce Australia Services reference · Part A v1.16

File integrity checked by ServiceCite
Program status
Current service
Published
3 June 2026
Effective
1 July 2026
Source retrieved
6 August 2026
Official record modified
14 July 2026
Official location checked by ServiceCite
6 August 2026
Attribution, presentation changes and technical record

Source material: © Commonwealth of Australia. Australian Government Department of Employment and Workplace Relations, Workforce Australia Guidelines, Part A: Universal Guidelines, version 1.16, published 3 June 2026. Used under the Creative Commons Attribution 4.0 International licence, subject to the exclusions in the DEWR copyright notice.

ServiceCite split the Word document into chapter pages and reformatted it for web navigation and search. Source logos, authoring artefacts and duplicate navigation were removed. System step, documentary evidence and work health and safety markers were converted to visible text labels. ServiceCite navigation and notices are independently written. Compare this page with the official source before operational use. This reuse does not imply Australian Government or DEWR endorsement.

The SHA-256 and file size record the official Word file verified during corpus preparation. ServiceCite does not publish the source DOCX because it contains images excluded from DEWR's default Creative Commons licence.

Document ID
dewr-workforce-australia-guidelines-part-a
Version ID
dewr-wa-part-a-v1.16-effective-2026-07-01
SHA-256
c88ac5d339842ee1ca56694d66e154d61be21ea9bbcde33f1860e0c474be0757
FOI reference
D26/3084244
Recorded file size
269,995 bytes
MIME type
application/vnd.openxmlformats-officedocument.wordprocessingml.document
Department wording, reformatted for the web · ServiceCite coverage notes are labelled

4.1. Chapter Overview

This Chapter provides guidance for Providers in relation to:

  • meeting the Department’s security accreditation requirements,

  • obtaining accreditation, and

  • maintaining accreditation for the duration of their Deed

under the ESAF.

Providers are able to access sensitive client information via the Department’s online systems. This level of access requires appropriate levels of security.

The Department uses the ESAF to determine that Providers and their External IT appropriately manage the level of risk to the security of information they hold. As part of the ESAF, Right Fit for Risk (RFFR) provides a tailored assurance approach to inform the Department’s accreditation decision. The RFFR approach closely follows the ISO 27001 international standard that sets out the requirements for an Information Security Management System (ISMS).

Providers are required to undertake the accreditation process and be accredited to demonstrate their ability to meet the Department’s requirements for Provider information security in the manner and within the timeframes specified in this Chapter. Providers accredited under the ESAF must maintain their accreditation for the duration of their Employment Deed with the Department, or the period they retain access to personal information collected during delivery of employment services (whichever is later).

If a Provider does not obtain accreditation or reaccreditation within the timeframes specified in the ESAF, including the RFFR, or their Employment Deed, the Provider must immediately cease using, and ensure that any relevant Subcontractor ceases using, the relevant Provider IT System.

4.2. External Systems Assurance Framework

The ESAF provides assurance that the risks to the Department’s IT Systems and data, information and Records stored outside of the Department’s IT Systems environment are managed securely and appropriately.

This is consistent with the whole of government Protective Security Policy Framework (PSPF). As part of the PSPF, the Department is accountable for ensuring that all contracted Providers used in the delivery of its programs also comply with PSPF requirements.

The ESAF covers External IT Systems associated with:

  • the delivery of the Services, including storage, processing or communication of data related to delivering the Services,

  • Accessing the Department's IT Systems, and

  • data, information and Records supporting the program.

The areas of assurance covered in the ESAF are Provider IT Systems and Third Party Employment Systems (TPES).

4.2.1. Providers’ IT Systems

Provider accreditation under the ESAF provides assurance that the Department’s IT Systems and data are safeguarded when accessed by Providers and Subcontractors. The accreditation of Provider IT Systems provides assurance to the Department that sufficient security measures are in place to manage Provider and Subcontractor security risks.

4.2.2. Third Party Employment Systems (TPES)

TPES are any Third Party IT systems used in association with the delivery of the Services, whether or not that Third Party IT system accesses the Department's IT Systems, and where that Third Party IT system:

  • contains program specific functionality or modules; or

  • is used, in any way, for the analysis of Records relating to the Services, or any derivative thereof.

TPES are specialised and Department accredited systems that may interface with the Department’s IT Systems and make employment industry-specific functionality available to licensed users.

Vendors of accredited TPES have demonstrated their implementation of an information security management system covering the TPES which meets RFFR requirements. The status of all existing accredited TPES is outlined on the Department’s Digital Information Assurance and IT Security Compliance website.

If a Provider uses a TPES, the Provider must ensure that they:

  • have accessed the relevant TPES accreditation letter

  • understand the scope of the TPES accreditation

  • identify if the Provider’s system configuration matches the accredited TPES configuration, and

  • identify risks associated with use of unaccredited TPES functionality and implements appropriate mitigation strategies.

Providers wishing to use unaccredited software or services must assess risks, conduct their own evaluations, and ensure appropriate controls are in place.

Providers must obtain written approval from the Department to use or change a TPES.

4.3. Right Fit for Risk approach

The RFFR approach includes requirements in relation to Provider accreditation based on the:

  • International Standard ISO/IEC 27001:2022 Information technology – Security techniques – Information security management systems – Requirements (ISO 27001) – the international standard outlining the core requirements of an Information Security Management System.

  • Australian Government Information Security Manual (ISM) – the Australian Government’s cyber security framework to protect systems and data from cyber threats.

The RFFR approach includes a requirement that Providers design and implement an Information Security Management System (ISMS) that is consistent with the requirements of ISO 27001. An ISMS is a systematic approach to managing business information so that it remains secure and available when staff need it. It secures people, premises, IT systems and information by applying a risk management process to information security.

The RFFR program extends ISO 27001 in 2 key areas:

  • ISO 27001 requires organisations to consider the set of security controls presented in Annex A to the standard and identify which are applicable to mitigating their security risks. RFFR extends this requirement by asking Providers to also consider the set of security controls presented in the ISM that are relevant to securing OFFICIAL classified information.

  • The Department has identified core expectation areas that are particularly important to the security posture at all organisations. All Providers are expected to include security controls that support the core expectation areas under the RFFR when identifying applicable controls for inclusion in their ISMS.

4.4. Guidelines for accreditation and maintenance of accreditation

The Department is the accrediting authority for Providers. To accredit Providers, the Department seeks assurance that the Provider has implemented an appropriate standard of security over their information and their IT environment. The accreditation process for each Provider depends on their size and risk profile.

To demonstrate that Provider IT Systems meet RFFR requirements, the Department requires Providers to follow the RFFR approach. The RFFR approach requires Providers to complete a set of milestones within a prescribed time period. At each milestone, Providers check in with the Department to review progress, assess risk and provide guidance on meeting the RFFR requirements.

The milestones are designed to allow Providers to assess their organisation’s level of cyber security measures in place and implement any improvements identified at the same time as gaining a customised ISMS that conforms with ISO 27001.

4.5. Provider classification for accreditation

The RFFR approach classifies Providers into a category to obtain accreditation.

  • Category 1: Providers delivering Services to 2,000 or more individuals per annum as a result of all of their Deeds (including individuals serviced by Subcontractors)

  • Category 2: Providers delivering Services to fewer than 2,000 individuals per annum as a result of all of their Deeds (including individuals serviced by Subcontractors). This category includes two sub-categories referred to as “Category 2A” and “Category 2B” below.

When determining whether a Provider is in Category 2A or 2B, the Department will consider a range of risk factors including the:

  • IT environment

  • level of outsourcing

  • subcontracting arrangements

  • organisational structure

  • level of security maturity

  • the extent of sensitive information held and level of access to departmental systems

  • other relevant factors.

The Department considers the number of individuals receiving services from the Provider and any Subcontractors ("caseload volume") in the aggregate across all Deeds. Should the Provider enter into new Deeds with the Department that alters the caseload volume, the Department will reassess their categorisation and may require the accreditation to be updated if the categorisation changes.

Each of the Provider categories is associated with its own assurance pathway under the RFFR approach.

The Department will categorise a Provider based on their RFFR questionnaire submission (or equivalent) and additional information obtained through an interview with the Provider. Completion of this interview and categorisation activity marks Milestone 1 in the RFFR process.

Table 4‑A provides guidance to Providers on the basis of accreditation and accreditation maintenance activities required for each category.

Table 4‑A: Provider Classification

Table 4-A: Provider Classification
CategoryCategory 1Category 2
Sub-categoryNil2A2B
Annual Case load2,000 or moreUnder 2,000Under 2,000
Risk profileGreater riskMedium RiskLow risk
Basis of accreditationISO 27001 conforming ISMS - independently certifiedISO 27001 conforming ISMS - self-assessedManagement Assertion Letter
Accreditation maintenanceAnnual surveillance audit and triennial recertificationAnnual self-assessmentAnnual management assertion letter
Milestones to complete1, 2 and 31,2 and 31 and 3

4.6. Milestones for completing the accreditation process

4.6.1. Milestone 1

Respondents to relevant Requests for Proposal or Tender (RFP or RFT) are required to submit a completed RFFR questionnaire to the Department on how they use information and manage security. The completed questionnaire provides the Department with information regarding the respondent’s business, IT security posture, subcontracting arrangements, and readiness to meet RFFR requirements.

Milestone 1 is initiated through the submission of a RFFR questionnaire required as part of a Provider’s RFP/RFT response. The Department will review the RFFR questionnaire, assess risk and provide guidance to Providers on completing subsequent Milestones of the RFFR accreditation process as relevant. On the execution of an Employment Deed, the Department will engage with the Provider to discuss their IT security posture and next steps toward RFFR accreditation.

Table 4‑B sets out the requirements for Milestone 1 for Providers who are already accredited or already in the process of being accredited.

Table 4‑B: Requirements for the Milestone 1 process

Table 4-B: Requirements for the Milestone 1 process

Assessment method

Review of submitted RFFR questionnaire and discussion.

Submission deliverables

RFFR questionnaire submitted by the Provider as part of their RFP/RFT response.

Key actions and outcomes

The Provider and Department representatives will discuss the Provider’s business, stakeholders, contractual obligations, information, systems and practices to assist the Provider to determine the scope of their Information Security Management System.

Unaccredited Providers: The Department will confirm the Provider’s categorisation and the associated RFFR assurance requirements for completing Milestone 2 and 3. Providers intending to deliver Services to fewer than 2,000 individuals will review additional risk factors with the Department to determine whether the Provider should be classified into Category 2A or 2B.

Providers part way through an existing accreditation process: Existing Providers who are part way through an accreditation process for delivering Services under an existing Employment Deed should take steps as advised in the purchasing documentation.

Accredited Providers with new Deeds: The Department will review the extent of changes to the Provider’s scope of Services and determine if the Provider should be in a different category as a result of the new Deeds. In accordance with the terms of their accreditation, the Provider should consider whether their Information Security Management System requires review and update to ensure that people, locations, systems and information associated with services under the new Deeds are appropriately secured; and notify the Department. If no significant changes have occurred, accredited Providers do not need to complete Milestones 2 and 3 and need only maintain their RFFR accreditation.

Next steps

For large organisations it is recommended Providers appoint a champion within the organisation to ensure compliance with the RFFR

Commence development of documentation required by the Provider’s category (see Table 4‑C below)

Identify where existing security controls meet RFFR requirements, and where there are gaps requiring that additional controls be implemented.

Due dates

Completed within one month of Deed execution by the Department.

4.6.2. Milestone 2

Milestone 2 requires Providers to demonstrate their ISMS has been designed to reflect RFFR requirements applicable for their Category (as advised at Milestone 1). Providers are required to demonstrate that appropriate security controls are planned to be implemented within the organisation through submission of required documentation.

The process for completing Milestone 2 depends on the Provider’s category. This Milestone does not apply to Category 2B Providers who instead proceed directly to Milestone 3.

Reference guides, materials and templates to support Milestone 2 written submissions are available from the Department’s website. It is not mandatory to use the Department’s templates.

Table 4‑C lists the requirements for Providers to achieve Milestone 2.

Table 4‑C: Milestone 2 requirements

Table 4-C: Milestone 2 requirements

Category 1 Provider

Category 2A Provider

Category 2B Provider

Submission deliverables

  • ISMS scope

  • Statement of Applicability (SoA) reflecting RFFR requirements

  • Independent assessor’s Stage 1 report

  • ISMS scope

  • SoA reflecting RFFR requirements

  • ISMS Self-assessment report (conformance)

Not applicable

Implementation status

Provider’s ISMS is expected to substantially conform with ISO 27001 requirements, however applicable controls sourced from ISO 27001 Annex A and from the Australian Government Information Security Manual are not expected to be implemented at this stage

Assessment method

Independently issued assessed by a JAS-ANZ accredited ISO 27001 conformance assessment body

Self-assessed by business owners

Outcomes to progress to Milestone 3

Department acceptance of submission deliverables.

Department acceptance of submission deliverables.

Next steps

Implement the ISMS in accordance with its design

Due dates

To be completed within 3 months from the Deed Commencement Date

4.6.3. Milestone 3

Milestone 3 emphasises the Provider’s progress to conforming with ISO 27001 and implementing the controls applicable to the organisation. While all applicable controls are important, priority should be on ensuring conformance with controls that support the RFFR core expectations.

If not fully implemented at the point of the Milestone 3 submission, Providers are required to inform the Department of their expectation as to when each applicable control will be fully in place and when any remaining areas of non-conformance will be addressed.

Providers should be aware that applicable but unimplemented controls (and remaining areas of non-conformance) will impact the Department’s assessment of residual risk associated with the Provider, and the Department’s decision to accredit the Provider. The Department does not discourage any Category 2A and 2B Providers from seeking ISO 27001 certification as there may be significant perceived or actual benefits to other aspects of the Provider’s business.

Table 4‑D lists the requirements for Providers to achieve Milestone 3.

Table 4‑D: Milestone 3 requirements

Table 4-D: Milestone 3 requirements

Category 1 Provider

Category 2A Provider

Category 2B Provider

Submission deliverables

  • Updated Scope document describing any changes to the Provider's operating environment

  • Updated SoA identifying the current implementation status of applicable controls, and the applicability decision for new or changed controls published since the SoA’s last review

  • Independent assessor’s “Stage 2” report. This can be either an ISO27001 or DESE ISMS Scheme report. RFFR does not require a Provider to have both audits completed

  • ISO 27001 or DESE ISMS Certificate

  • U­pdated SoA identifying the current implementation status of applicable controls, and the applicability decision for new or changed controls published since the SoA’s last review

  • ISMS self-assessment report (implementation)

Management Assertion Letter

Implementation status

Provider’s ISMS conforms with ISO 27001 and controls applicable to the organisation have been implemented

Controls supporting specific security objectives have been implemented

Assessment method

Independently assessed

Self-assessed

Self-assessed

Outcomes to complete process

  • Department acceptance of submission deliverables

  • RFFR accreditation

Next steps

  • Address any remaining minor non-conformances

  • Implement remaining applicable controls (if any)

  • Monitor the ISMS

Monitor performance of security controls

Due dates

To be completed within 9 months from the Deed Commencement Date

To be completed within 9 months from the Deed Commencement Date

4.7. Submission deliverables

4.7.1. Submission milestones

Table 4‑E below provides a high-level description of the deliverables that need to be submitted to the Department as part of the accreditation process. The Department does not require the use of any specific template, except for the RFFR questionnaire completed for Milestone 1 as part of the Provider’s RFT/RFP response. Standard templates for each deliverable are available from the Department and may be optionally used as a basis for working through the accreditation process.

Each of the submission deliverables in Table 4‑E is described in more detail in Table 4‑F.

Table 4‑E: Provider Milestones Deliverables

Table 4-E: Provider Milestones Deliverables

Milestone 1

Milestone 2

Milestone 3

Category 1 Providers

  • RFFR questionnaire & Interview

  • ISMS Scope

  • SoA

  • Independent assessor’s “Stage 1” report

  • ISMS Scope

  • SoA

  • Independent assessor’s “Stage 2” report

  • ISO 27001 certificate or DESE ISMS certificate

Category 2A Providers

  • RFFR questionnaire & Interview

  • ISMS Scope

  • SoA

  • ISMS Self-assessment report (conformance)

  • ISMS Scope

  • SoA

  • ISMS Self-assessment report (implementation)

Category 2B Providers

  • RFFR questionnaire & Interview

  • Not applicable

  • Management Assertion Letter

4.7.2. Deliverable descriptions

Table 4‑F below provides a detailed description of, and criteria for completing, each deliverable of the RFFR process.

Table 4‑F: Deliverable descriptions

Table 4-F: Deliverable descriptions

Submission Document

Description

RFFR questionnaire

Submitted with the Provider’s RFT/RFP response where required, the questionnaire seeks information regarding the Provider’s business, their IT security posture and their readiness to meet RFFR requirements. Discussing the completed questionnaire with the Department marks completion of Milestone 1 and confirms the Provider’s category.

ISMS scope document

The purpose of this document is to clearly define the boundaries of the ISMS to provide the Department with an understanding of the Provider’s business and context, in conformance with ISO 27001 Clause 4. It should also provide a high-level description of how the Provider intends to meet RFFR core expectation areas. A template scope document is available from the Department.

Statement of Applicability (SoA)

The SoA demonstrates the Provider’s consideration of each of the security controls sourced from ISO 27001’s Annex A and ISM’s OFFICIAL security controls and the determination of which controls will form part of the Provider’s ISMS. It also communicates the rationale for determining that individual controls are “not applicable” to the Provider’s business.

For applicable controls, the SoA should indicate relevant policies/procedures or other documentation demonstrating that the control has been included in the Provider’s business and should indicate the current implementation status of each applicable control.

The SoA is a mandatory artefact required to conform with ISO 27001 Clause 6. An ISO to ISM controls mapping document is available from the Department to assist with developing the SoA.

Independent assessor’s “stage 1” report

For Category 1 Providers (or other Providers who see benefit in obtaining an industry certification). This is the first of 2 independent assessments required to achieve ISO 27001 or DESE ISMS Scheme certification. Performed by a JAS-ANZ registered certification assessment body, the stage 1 report verifies the extent to which the Provider’s ISMS has been designed to conform with the requirements of ISO 27001 and identifies design gaps to be addressed prior to commencing the stage 2 assessment. Because RFFR requires a customised SoA it is critical that the report states that the assessment was performed over the ISMS as described by that customised SoA – with a clear report reference to the SoA by version/ date.

Independent assessor’s “stage 2” report

For Category 1 Providers (or other Providers who see benefit in obtaining an industry certification). This is the second of 2 independent assessments required to achieve ISO 27001 or DESE ISMS Scheme certification and is a key source of assurance that the Provider has implemented the controls identified as applicable in the SoA. Performed by a JAS-ANZ registered certification assessment body, the stage 2 report validates that the implemented ISMS conforms with the requirements of ISO 27001 and that applicable controls are in place and operating.

Because RFFR requires a customised SoA it is critical that the report states that the assessment was performed over the ISMS as described by that customised SoA – with a clear report reference to the SoA by version/ date - and that the report provides information regarding the status of both Annex A- and ISM-sourced applicable controls (particularly applicable controls that support RFFR core expectation areas - see section 4.9).

ISO 27001 certificate or DESE ISMS Scheme certificate

Issued after the Provider has demonstrated plans to address any non-conformances identified in the stage 2 report and the independent assessor has recommended the Provider for certification. The DESE ISMS Scheme certificate is an adaptation of the ISO 27001 certificate.

ISMS Self-Assessment report

For Category 2A Providers only, the self-assessment report is the Department’s source of assurance that the ISMS described by the Provider’s SoA has been designed (for Milestone 2) and implemented (for Milestone 3) in accordance with ISO 27001 and RFFR requirements.

It is critical that the self-assessment report be signed off by a person/s with appropriate authority to make declarations on behalf of the Provider, that it attest to the Provider’s ISMS conformance with ISO 27001 requirements, and (for Milestone 3) that it attest to the implementation status of controls identified as applicable in the Provider’s SoA. A template self-assessment report is available from the Department.

Management Assertion Letter

For Category 2B Providers only, the Management Assertion Letter is the Department’s source of assurance that the Provider represents minimal risk and has implemented security controls that respond to relevant security objectives. The letter covers a description of the Provider’s systems and controls, attests that the description is accurate and that the described controls are appropriate to meet specific security objectives.

4.7.3. Considerations for accreditation commencement

Table 4‑G provides guidance to Category 1, 2A and 2B Providers on areas of focus to consider before commencing the RFFR accreditation process.

Table 4‑G: Considerations for accreditation commencement

Table 4-G: Considerations for accreditation commencement
AreaDescription
SponsorIdentify a sponsor within the organisation to support the RFFR certification process. The sponsor will help guide and support the accreditation process, including ensuring that appropriate resources are available to complete RFFR accreditation.
ScopeDetermine the scope of the ISMS. Consider the organisational context and business activities performed at each site, stakeholders and their needs, physical boundaries, legal and contractual requirements, and logical boundaries (systems and data). The scope should communicate key aspects of the Provider’s business, the importance of security and state what the ISMS will be protecting.
Gap AnalysisBefore the Milestone 2 submission, Providers should perform an initial review and gap assessment to identify areas of current conformance with ISO 27001 and areas requiring future focus. The gap assessment should also identify if the Provider already has some applicable controls in place and which require action to implement. As a management review of the ISMS, this assessment is itself a requirement of ISO 27001. Performing the gap assessment prior to Milestone 2 will ensure time to address non-conformances and to plan improvements before the Provider’s final submission.
Certifying Assessment BodyFor Category 1 Providers (or other Providers who see benefit in obtaining an industry certification), identify a suitable Certifying Assessment Body (CAB) to work with your organisation to provide the independent assessments required under the ISO 27001 requirements (see 4.7.4 below).

4.7.4. Certifying Assessment Bodies

To seek certification under the RFFR program, the Department requires Category 1 Providers to be independently certified by a CAB/assessor. Providers are required to engage a CAB that is accredited or otherwise recognised by JAS-ANZ to issue ISO 27001 or DESE ISMS Scheme assessment reports and certificates in Australia.

JAS-ANZ is the accreditation authority for CABs in Australia and New Zealand. A list of certifiers who can issue an ISO 27001 or DESE ISMS Scheme assessment reports and certificates can be found at JAS-ANZ's website.

Category 2 Providers are not required to be independently certified by a CAB auditor. Category 2A Providers can self-assess and declare their conformance with ISO 27001 and the implementation status of applicable controls. Category 2B providers can provide a description of their business, systems and information and attest to their implementation of required security controls in the form of a management assertion letter.

4.8. Accreditation maintenance

During the lifespan of their Employment Deed/s, Providers are required to maintain their RFFR accreditation status through annual reporting (each financial year) and surveillance audits to ensure compliance to the standards (see Table 4‑H below). Providers with an existing accreditation will need to complete the annual and 3 yearly audits based on the dates when the accreditation was granted.

If, at any time during the accreditation maintenance period, a change to a Provider’s or Subcontractor’s circumstances alters the risk profile of the organisation, the Department will reassess the Provider’s accreditation status. This includes when the Provider or Subcontractor:

  • enters a new Deed with the Department

  • changes its subcontracting arrangements (from one Subcontractor to another, or introduces a new Subcontractor)

  • changes its Third Party IT Vendors who are supporting their IT environments

  • has a change in classification from Category 2 to Category 1

The Provider must notify the Department within 5 Business Days of a change in circumstance.

ISM controls are regularly added and changed. Providers should regularly review these to consider whether the controls are applicable to their business and whether any of the controls should form part of their accredited ISMS. The SoA should be regularly revised to demonstrate the Provider's consideration of new or changed ISM controls. Where a new or changed control is determined to be applicable but has not been fully implemented by the time of the Provider's annual submission, Providers should ensure their SoA also includes details of their planned actions to address these matters and an expected completion date for each.

Table 4‑H details the requirements for Providers to maintain their accreditation once accreditation has been granted. Note the timing of the annual and 3 yearly audits applies from the date of accreditation.

Table 4‑H: Ongoing accreditation requirements

Table 4-H: Ongoing accreditation requirements

Accreditation type

Annually

Every 3 years

Certified ISMS (Category 1 Providers)

  • Surveillance audit by CAB covering the Provider’s updated SoA

  • Recertification by CAB

  • Reaccreditation by DEWR

Self-assessed ISMS

(Category 2A Providers)

  • Self-assessment report (incl. description of changes since last report) covering the Provider’s updated SoA

  • DEWR determines whether need to upscale to a Certified ISMS

  • Self-assessment report

  • Reaccreditation by DEWR

Management attestation

(Category 2B Providers)

  • Annual attestation & description (incl. description of changes since last attestation)

  • DEWR determines whether need to upscale to a self-assessed ISMS

  • Attestation & description

  • Reaccreditation by DEWR

4.9. Core expectations of Providers under the RFFR

Providers must, as a minimum, implement and manage the following core expectations to maintain and enhance their security posture:

  • Personnel security - implement security control measures including mature Personnel onboarding practices.

  • Physical security - implement appropriate physical security measures over IT equipment and storage media.

  • Essential Eight - identify a target level of maturity in each of the Essential Eight cyber security strategies published by the Australian Cyber Security Centre, develop a plan to achieve target maturity, and achieve a base level maturity in the first instance.

Providers should implement controls for:

  • Information Security Monitoring – to manage vulnerabilities in their IT systems, and to manage changes to their IT systems.

  • Incident management – designed to detect and respond to cyber security incidents, to report incidents internally and to external stakeholders (including the Department) as appropriate, and to keep appropriate Records of security incidents. As a key element of security incident detection, Providers should implement controls to log security-related events occurring in their IT systems and to audit these logs on a regular basis.

  • Restricted access controls – to enable strong user identification and authentication practices for privileged accounts, user accounts, and service accounts.

Providers should implement security controls that are responsive to:

  • Specific Deed obligations - such as data sovereignty

  • Specific or unique Provider security risks

  • Continual improvement - Commit to continual improvement as Cyber risks change and develop.

Providers are expected to demonstrate their responses to these core expectations through the submission of documentation at each RFFR milestone as detailed.

4.9.1. RFFR Core Expectations: Personnel security

As part of processes to bring new people into the organisation, Providers must

  • identify the individual and positively confirm the individual’s identity

  • verify the competency of the individual by verifying qualifications, certifications and experience provided on their CV

  • obtain a satisfactory police check for the individual

  • satisfactorily complete Working with Vulnerable People checks as required by individual states / territories

  • confirm the individual has a valid right to work in Australia – a person who is not an Australian citizen must hold appropriate work entitlements

  • verify that the individual has successfully completed initial and ongoing security awareness training programs with content and timing tailored to their role

  • execute employment contracts which state that responsibilities for information security and non-disclosure requirements continue post termination

  • implement higher levels of assurance for individuals that have privileged or administrative level access. The additional Personnel expectations include that individuals must be Australian citizens or permanent residents to give them sufficient connection with Australia and be willing and able to undertake a suitability background check.

4.9.2. RFFR Core Expectations: Physical security

Providers are required to implement physical security measures that minimise the risk of information and physical assets being:

  • made inoperable or inaccessible, or

  • accessed, used or removed without appropriate authorisation.

All Providers are expected to meet physical security expectations. Permanent facilities are to be commercial-grade facilities located within Australia. A facility is any physical space where business is performed to support the provision of government services. For example, a facility can be a building, a floor of a building or a designated space on the floor of a building. Providers allowing staff to work from home need to consider how the home environment can be configured to protect staff, program data and IT physical assets in the same manner as in the office environment. Personnel are to be aware of their environment when they transport or store their devices, and when they use mobile devices to access and communicate program data, especially in public areas. In such locations Personnel are to take extra care to ensure conversations are not overheard and data is not observed.

4.9.3. Essential Eight cyber security strategies

The Australian Cyber Security Centre (ACSC) has developed the Essential Eight strategies to mitigate cyber security threats.

Providers must determine a target maturity level for the Essential Eight cyber security strategies that reflects the organisation’s risk profile and develop plans to achieve target levels over time. The Department requires that Providers initially implement controls supporting the Essential Eight cyber security strategies to achieve Maturity Level One on the ACSC’s published maturity model.

Detailed implementation guidance is also available from the ACSC's website.

Table 4‑I: Essential Eight cyber security strategies

Table 4-I: Essential Eight cyber security strategies
ControlDescription
Application Controlto control the execution of unauthorised software. This prevents unknown and potentially malicious programs executing in your environment.
Patch Applicationsto remediate known security vulnerabilities in application software. Security vulnerabilities in applications can be used to execute malicious code. Using the latest version of applications and promptly applying patches when vulnerabilities have been identified will keep your environment robust.
Configure Microsoft Office macro settingsto block untrusted macros. Microsoft Office macros can be used to deliver and execute malicious code. This strategy will only allow macros from trusted locations with limited write access, or those digitally signed with a trusted certificate, to run.
Application Hardeningto protect against vulnerable functionality. Flash, ads and Java on the internet are popular ways to deliver and execute malicious code. This strategy requires the removal of unneeded features in Microsoft Office, web browsers and PDF viewers.
Restrict Administrative Privilegesto limit powerful access to systems. The access required by administrator accounts means they hold the keys to your IT kingdom. When compromised, adversaries use these accounts to gain full access to information and systems and move around Provider networks. Reduce this risk by minimising the number of these accounts and the level of privileges assigned to each account. Do not allow these accounts to be used to read email or web browsing.
Patch Operating Systemsto remediate known security vulnerabilities. Security vulnerabilities in operating systems can be used to further the compromise of systems. Do not use unsupported versions. Using the latest version of operating systems and promptly applying patches when vulnerabilities have been identified will limit the extent of cyber security incidents.
Multi-Factor Authenticationto protect against user accounts being inappropriately accessed. Stronger user authentication makes it harder for adversaries to access information and systems. This is particularly important when users perform higher risk activities such as gaining access remotely, performing administrative functions or when accessing sensitive data. Providers should note that multiple password challenges in series do not constitute multi-factor authentication (MFA) – MFA requires a combination of 2 or more factors made up of secret information (such as an ID/password combination); data uniquely bound to a physical device (such as an authenticator app on a registered smartphone or a one-time SMS code), and data uniquely bound to a physical person (a biometric measure such as facial recognition or a fingerprint).
Regular Backupsto maintain the availability of critical data and systems. This strategy assists with accessing information following a cyber security incident. Backups of data, software and configuration settings, stored disconnected from your main environment, can be used to recover from an incident. Regular testing of backups ensure it can be recovered, and that all critical data is covered by the backup regimen.

4.10. General requirements

4.10.1. Security Contact

Providers are required to nominate one or more Security Contact officers who will act as point of contact during the term of their Employment Deed. Providers are required to ensure that the contact information for Security Contact officers remains current and if there is a relevant change of Personnel that Providers update the Department within 5 Business Days of the change.

4.10.2. Subcontractor and Third Party IT Vendor requirements

Providers are responsible for ensuring that any Subcontractors used in the provision of the Services and any Third Party IT Vendors supporting the Provider's Services also comply with the security, privacy and data sovereignty requirements of their Employment Deed.

The Provider must:

  • ensure that its Subcontractors successfully complete the required Personnel vetting processes, and bear any costs associated with doing so.

  • ensure that its Subcontractors and its Third Party IT Vendors are aware of, and comply with, the same security requirements that are placed on the Provider by the Department. This includes consideration and implementation of ISM OFFICIAL controls that are relevant to the scope of services provided by the Subcontractor or Third Party IT service provider.

4.10.3. Access and information security assurance for External IT Systems

Providers (including any Subcontractors) who use an External IT System in association with the delivery of the Services must ensure that any External IT System used:

  • does not negatively impact the performance, availability or data integrity of the Department’s IT Systems

  • does not breach Employment Deed requirements relating to security, privacy and data sovereignty

  • meets the relevant requirements of the ESAF

  • does not introduce or permit the introduction of Malicious Code into the Department’s IT Systems

  • has secure log ons for each operator such that each operator’s logon is uniquely identifiable to the Department and entries are traceable, and have date and time stamps, and

  • does not default answers to questions or input fields where the Department’s IT Systems has no default setting

  • is not used to Access the Department’s IT Systems without the Department’s written approval.

4.10.4. Cloud Services Providers

In November 2021, the Digital Transformation Agency (DTA) released the Hosting Certification Framework. This Framework states that all information defined as government information must be hosted with the appropriate level of privacy, sovereignty and security controls.

The DTA maintains a list of Certified Cloud Hosting Services. The Department will provide advice to Providers on what this will mean towards achieving RFFR accreditation. However, it is important to note that Providers remain responsible for protecting the confidentiality, integrity, and availability of data through their own assurance and risk management activities.

4.10.5. Breaches of security requirements

Where the Department considers that the Provider has breached their Employment Deed, including RFFR or security requirements, or there is a risk of such a breach, the Department may immediately suspend Access, or require the Provider to cease all Access, to the Department’s IT Systems. Where the Department determines that the Provider is in breach of, or has previously breached, relevant requirements, the Department may immediately take action including any one or more of the following:

  • suspending, terminating, or requiring the cessation of all access to the Department’s IT Systems for any Provider Personnel, Subcontractor, Third Party IT Vendor, External IT System or the Provider

  • requiring the Provider to obtain new logon IDs for any Provider Personnel, Subcontractor or Third Party IT Vendor and, if so required, the Provider must promptly obtain such new logons; or

  • requiring the Provider to prepare and implement an IT security plan to the Department’s satisfaction, and if so required, the Provider must do so within the timeframe required by the Department.

4.11. Use of Artificial Intelligence in delivering employment services

This section sets out Providers’ obligations relating to the use of Artificial Intelligence (AI) in the delivery of employment services. The requirements in this section will help maintain the integrity, security, and ethical standards of employment services delivery. The requirements are intended to ensure that Providers’ use of AI is consistent with the Digital Transformation Agency’s Policy for the responsible use of AI in government and the Department’s privacy and information security requirements.

Providers’ compliance with this section will help maintain public trust and ensure the effective and responsible delivery of employment services.

In this section, ‘AI Technologies’ means a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments and may vary in their levels of autonomy and adaptiveness after deployment. This may include AI technologies such as machine learning, natural language processing, and generative AI tools.

4.11.1. Providers' requirements relating to the use of AI

The Department is committed to realise the benefits of AI by engaging with AI confidently, safely, and responsibly. As such, the Department will permit the use of AI by Providers in the delivery of employment services only where the Department gives its explicit approval to the AI Technology being used in the delivery of employment services and the following conditions are met:

  1. The AI Technology is not banned by the Australian Government.
  • The Australian Government or the Department may from time-to-time advise or Notify Providers of AI Technologies that are banned.

  • The Department considers the following as banned Technologies:

  • products and web services from DeepSeek and Kaspersky Lab, Inc. This is consistent with the Department of Home Affairs’ guidance to Commonwealth Agencies (see Direction 001-2025 and Direction 002-2025).

  • AI bots for the purposes of recording meetings with the Department, Participants or members of the public.

  1. Providers must ensure the AI Technology upholds ethical principles, privacy and data protection laws, and contractual requirements with respect to information management (including in relation to Intellectual Property, confidentiality and Records management).
  • This includes ensuring that AI Technologies:

  • safeguard personal, sensitive and protected information,

  • do not compromise the privacy of individuals,

  • are not used to automate decision-making, and

  • can keep detailed records

  • Providers are responsible for managing these principles, laws and contractual requirements in implementing and maintaining the AI Technology and for otherwise meeting their contractual obligations.

  1. Providers must ensure that any AI Technology implemented within their External IT Systems adheres to the cybersecurity requirements outlined in the Australian Government Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF) to ensure the secure operation of all systems.

A process for requesting approval of an AI Technology has been established through RFFR accreditation. For Providers who would like to request to use AI Technology in delivering employment services, refer to the Third-Party AI Assessment Framework and Application Form. Please email the completed application form to securitycompliancesupport@dewr.gov.au, copying in your Provider Lead. Any request must address in detail that the conditions above have been satisfied by the Provider.

Providers may utilise AI for functions not directly related to the delivery of employment services without approval from the Department. Providers are responsible for ensuring any AI Technology being used for such purposes is isolated from all aspects of employment services delivery. If isolation cannot be ensured, the AI Technology must not be used.

On this page