AUSTRALIAN CYBERSECURITY & RISK ADVISORY Clarity. Control. Resilience.
RASPTECHNOLOGIES spider and silver web logo

RESOURCES / CHECKED 11 OCTOBER 2026

Better decisions
begin with good sources.

Authoritative guidance for planning and governance. Check the latest requirements before relying on them.

Australian guidance library

ASD / ACSC — Essential Eight ↗

Use the current maturity model and assessment guidance for an evidence-based uplift programme. It is a baseline, not a complete security programme.

Checked 11 October 2026 · Source: ASD / ACSC

OAIC — Australian Privacy Principles ↗

The APPs govern information handling for entities within their scope. Review security, disposal and overseas disclosure requirements relevant to your data.

Checked 11 October 2026 · Source: OAIC

OAIC — Notifiable Data Breaches ↗

Covered entities must assess suspected eligible breaches and notify where required. Serious harm, remedial action and exceptions matter.

Checked 11 October 2026 · Source: OAIC

APRA — CPS 234 ↗

Review information security capability, testing and notification duties for APRA-regulated entities.

Checked 11 October 2026 · Source: APRA

Practical starting points.

Plan an Essential Eight uplift

Agree an assessment boundary and target maturity. Record control evidence, distinguish exceptions from gaps and sequence dependencies. Review the ASD model before reassessment.

Review cloud sharing

Find externally shared repositories, review guests and link expiry, confirm audit retention and test revocation. Check overseas disclosure and provider terms where relevant.

Exercise incident decisions

Choose a realistic compromise scenario. Test authority, evidence preservation, communications and restoration. Identify notification questions for legal review.

A CLEARER NEXT STEP

Start with the risk.
Build the right response.

Discuss your priorities ↗