Skip to main content

IRAP Training

Hands-on, scenario-based training delivered by active IRAP assessors through the Australian Information Security Academy.

GOVERNMENT SECURITY

Through the Australian Information Security Academy (AusISA) — an ASD-endorsed IRAP training provider and founding initiative of Malware Security and Redacted Information Security — we deliver hands-on, scenario-based IRAP assessor training. The flagship course is aligned to the IRAP Common Assessment Framework, ISM, and PSPF, and is delivered by active IRAP assessors with current government assessment experience.

When To Engage Us

  • Practitioners preparing for the IRAP assessor pathway
  • Security professionals moving into government assurance work
  • Organisations building deeper internal assessment capability

What We Cover

  • IRAP Common Assessment Framework
  • Information Security Manual and PSPF context
  • Evidence collection and assessment reasoning
  • Scenario-based reporting and stakeholder communication

Clear Outputs

Typical Engagement Outputs

Final outputs are agreed during scoping so they support the decisions your team needs to make.

  • Instructor-led practical training
  • Applied assessment scenarios
  • Feedback from active practitioners
  • Clear next steps for continued development

Define The Right Boundary

How We Scope It

A useful engagement begins with a clear assurance question. For this service, scoping normally considers:

  • Participant experience with the ISM, PSPF, technical controls, and assurance work
  • Individual enrolment, organisational cohort, or tailored capability-development needs
  • Preferred in-person or online delivery format and suitable course dates
  • Any accessibility, travel, or organisational requirements that affect delivery

From Question To Uplift

How We Work

The approach is adapted to your environment, while keeping communication, evidence handling, and decision points clear.

01

Prepare

Set expectations, confirm prerequisite knowledge, and provide the context participants need before the course.

02

Learn The Framework

Work through IRAP governance, the Common Assessment Framework, the ISM, PSPF, evidence, and assessor obligations.

03

Apply It

Assess a simulated government environment, gather evidence, determine control effectiveness, and justify conclusions.

04

Report & Assess

Develop an IRAP-style report extract and complete the course assessment with feedback from active practitioners.

Common Questions

Before You Engage

Does completing the course make someone an IRAP assessor?

No. The course prepares eligible practitioners for the IRAP assessor pathway, examination, and ASD endorsement process. Endorsement decisions remain with ASD.

Who delivers the training?

AusISA training is delivered by active IRAP assessors and experienced practitioners from Malware Security, Redacted Information Security, and the wider facilitator group.

Is training available online and outside Canberra?

Yes. AusISA offers in-person and online delivery, with courses available across Canberra, Sydney, Melbourne, Brisbane, and Adelaide according to the published schedule.

Related Insights

Explore Related Services

Start With A Conversation

Need help defining the right scope?

Tell us what you are trying to protect or validate. We will help shape an engagement around the outcome you need.

> TALK TO OUR TEAM_