Skip to main content

ACSC Essential 8

We have implemented the full suite of controls as defined by ACSC Essential 8 at Maturity Level 2. Our security posture is continuously monitored and optimised to ensure consistent risk management and proactive defence against emerging threats.

ASD ISM Controls

Our practices meet and exceed the requirements of ASD’s ISM Controls. This robust approach underlines our commitment to implementing effective and secure information management and communications practices across the organisation.

DISP (Defence Industry Security Program)

We have successfully filed for the Defence Industry Security Program (DISP). This process reflects our dedication to operating within robust and verified security frameworks that meet defence industry standards.

NIST Cryptographic Compliance

We employ cryptographic algorithms that align with NIST’s standardised Post Quantum Cryptography (PQC) standards [FIPS 204]. This ensures that our systems are ready for the evolving challenges in cybersecurity.

Upcoming Roadmap

ISO 27001 – Our processes are designed in line with ISO 27001 standards, and while our formal audit is still pending, we adhere to these rigorous controls. In addition, our systems (including code warehousing and license management) operate in a secure cloud environment that is accredited to ISO 27001, ensuring robust protection for our data and applications.

ISO 9001 – Our operational processes align with ISO 9001 standards. Although our formal audit and certification are pending, our quality management systems are fully designed to meet international requirements. Our continued investment in agility and excellence remains our priority.

FIPS-Compliant Modules – For organisations requiring specific cryptographic product implementations, we can provide FIPS-compliant modules built on either OpenSSL or WolfSSL. Note that while we can currently build in non-post-quantum functionality, the incorporation of post-quantum cryptographic (PQC) standards into FIPS ratings is pending. We are actively working towards integrating these enhancements in line with future requirements.