Start with the obligation
Compliance by regulation
Most buyers do not start with a service name — they start with the standard a customer, insurer or board has asked them to meet. Each obligation below is broken into what it actually demands and the work that answers it.
ISO/IEC 27001
International standard, certified by an accredited body
Who it applies to. Organisations that need a certifiable information security management system — usually because a customer, tender or insurer asks for it.
Certification turns on evidence: a defined scope, a risk assessment you can defend, documented controls from Annex A, and records that show the system is actually operating.
Scope, context and leadership commitment
Clauses 4 and 5 need a defined boundary, interested parties and accountable ownership.
Fractional CIO leadershipRisk assessment and treatment plan
Clause 6 needs a repeatable method, a risk register and a Statement of Applicability.
ISO 27001 consultingDocumented policies and control set
Annex A controls need written policy that matches how the organisation actually works.
ISO 27001 policy pack generatorSupplier and third-party assurance
A.5.19–A.5.23 cover supplier relationships and cloud service security.
Third-party risk decisionsIncident management and readiness
A.5.24–A.5.28 require a planned, rehearsed response with retained evidence.
Incident response planningACSC Essential Eight
Australian Signals Directorate / ACSC
Who it applies to. Commonwealth entities under the PSPF, and any Australian business asked to demonstrate a baseline maturity level by a customer, insurer or board.
Eight mitigation strategies, each scored from Maturity Level 0 to 3. Progress is measured per strategy, not as an average — so the honest question is which strategy is holding the target level back.
Know your current maturity level
A baseline score for all eight strategies before committing budget.
Essential Eight assessment toolA prioritised uplift sequence
Patching, application control and admin privileges usually carry the most risk per dollar.
Cyber maturity assessmentOwnership and delivery capacity
Maturity slips without someone accountable for the roadmap between audits.
Fractional CIO leadershipBoard reporting that lands
Directors need the residual risk and the cost of closing it, not a control tally.
Board cyber risk decision supportISO/IEC 42001
International standard for AI management systems
Who it applies to. Organisations deploying or building AI who need governance that stands up to customer and regulator scrutiny.
The AI equivalent of 27001: defined AI scope, impact assessment, lifecycle controls and evidence that human oversight is real.
AI inventory and impact assessment
You cannot govern the AI you have not catalogued — including tools staff adopted themselves.
AI governance and ISO 42001 decisionsAI management system policy set
Acceptable use, data handling, model change control and human oversight, written down.
ISO 42001 AI management policy packAligning AI and security controls
Most of the evidence overlaps with 27001; running them separately doubles the work.
ISO 27001 + 42001 bundleAPRA CPS 234 and CPS 230
Australian Prudential Regulation Authority
Who it applies to. APRA-regulated entities and the service providers they rely on.
Information security capability commensurate with the threat, clear accountability, and tested controls — plus operational resilience obligations under CPS 230.
Accountability and capability
The board remains accountable; the capability has to be demonstrable, not asserted.
CPS 230 compliance decision supportMaterial service provider assurance
Third parties handling information assets must be assessed and monitored.
Third-party risk decisionsTested incident response
Response plans must be reviewed, tested and able to notify APRA within 72 hours.
Incident response planningDealing with a live incident right now?
Suspected breach, ransomware note, business email compromise or a notifiable data breach clock already running — say so and your enquiry is triaged ahead of the queue.
Not sure which obligation actually binds you?
Thirty minutes with a senior advisor is usually enough to separate the contractual requirement from the nice-to-have, and to sequence the work.