Skip to main content
Image coming soon

SEC0769 Implementing the Australian Government Protective Security Policy Framework PSPF

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Implementing the Australian Government Protective Security Policy Framework PSPF

A practical, step-by-step guide to full PSPF compliance for business and technology leaders

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Control mappings that collapse under review cycles

The situation this course is for

Teams spend weeks assembling evidence only to face rework when auditors question interpretation, applicability, or completeness, draining bandwidth and eroding confidence.

Who this is for

Mid-to-senior business or technology professionals responsible for implementing or advising on Australian Government Protective Security Policy Framework (PSPF) requirements, often in consulting, compliance, risk, or security roles.

Who this is not for

Entry-level admins, pure policy writers without implementation responsibility, or vendors selling PSPF tools without execution experience.

What you walk away with

  • Produce PSPF control mappings that survive scrutiny without rework
  • Reduce evidence collection from 20+ hours to under 4 hours per domain
  • Respond confidently to assurance questions with source-backed rationale
  • Become the go-to interpreter of PSPF for cross-functional teams
  • Deliver implementation packs that close review cycles faster

The 12 modules (with all 144 chapters)

Module 1. Understanding PSPF’s core structure and intent
Break down the framework’s architecture, objectives, and how it aligns with broader government security expectations.
12 chapters in this module
  1. Mapping the PSPF lifecycle from policy to practice
  2. Identifying the eight core PSPF domains and their purpose
  3. How PSPF differs from ISO 27001 and other security standards
  4. The role of the PSPF in protecting classified and sensitive information
  5. Linking PSPF requirements to agency risk appetite statements
  6. Common misinterpretations of PSPF control language
  7. How to read PSPF clauses for implementation clarity
  8. The relationship between PSPF and the ISM (Information Security Manual)
  9. Key personnel roles defined in the PSPF framework
  10. How agencies are expected to self-assess compliance
  11. The evolution of PSPF from previous security directives
  12. Using PSPF as a foundation for broader governance programs
Module 2. Assessing current state against PSPF domains
Conduct a gap analysis that pinpoints exactly where your organisation stands today.
12 chapters in this module
  1. Building a cross-functional assessment team for PSPF readiness
  2. Creating a baseline inventory of existing security controls
  3. Mapping current policies to PSPF Domain 1: Governance
  4. Evaluating physical security practices against Domain 2
  5. Reviewing personnel security procedures for Domain 3 alignment
  6. Assessing asset management processes under Domain 4
  7. Testing ICT security configurations against Domain 5 expectations
  8. Validating security awareness programs for Domain 6
  9. Auditing supply chain risk controls in Domain 7
  10. Reviewing incident management plans per Domain 8
  11. Using weighted scoring to prioritise gaps by risk impact
  12. Documenting findings in a stakeholder-ready assessment report
Module 3. Defining scope and boundaries for PSPF implementation
Clarify what systems, locations, and teams the framework applies to , and why it matters.
12 chapters in this module
  1. Identifying all physical locations subject to PSPF requirements
  2. Determining which information systems handle protected data
  3. Classifying data flows across internal and external boundaries
  4. Establishing the perimeter for third-party vendor inclusion
  5. Defining roles for contractors and temporary staff
  6. Mapping cloud environments to PSPF jurisdictional rules
  7. Using system boundary diagrams for clarity in assurance reviews
  8. Handling shared services and inter-agency platforms
  9. Deciding when outsourced functions require PSPF coverage
  10. Documenting scope exclusions with justification
  11. Aligning scope decisions with agency mandate and function
  12. Getting early sign-off on boundaries from senior stakeholders
Module 4. Designing PSPF-compliant governance structures
Build oversight mechanisms that meet accountability expectations without creating bureaucracy.
12 chapters in this module
  1. Establishing a PSPF steering committee with clear mandates
  2. Assigning accountability for each of the eight domains
  3. Creating decision logs for control interpretation and waivers
  4. Designing escalation paths for unresolved compliance issues
  5. Integrating PSPF reporting into existing management routines
  6. Setting up quarterly review cycles for ongoing compliance
  7. Defining authority levels for control changes and exceptions
  8. Ensuring executive visibility without overloading leadership
  9. Linking PSPF performance to agency KPIs and OKRs
  10. Using dashboards to track progress across domains
  11. Conducting internal challenge sessions to test governance
  12. Maintaining governance records for assurance and audit
Module 5. Implementing physical security controls per Domain 2
Turn policy into actionable site-level protections.
12 chapters in this module
  1. Assessing facility layouts for access control efficiency
  2. Installing multi-layered entry systems with audit trails
  3. Securing storage areas for classified material and devices
  4. Managing visitor access with temporary credentials and logs
  5. Designing secure parking and delivery zones for high-risk sites
  6. Implementing CCTV systems with retention and privacy compliance
  7. Creating emergency lockdown procedures and testing schedules
  8. Controlling access to server rooms and network closets
  9. Using dual control mechanisms for high-security zones
  10. Maintaining physical security incident logs and reports
  11. Training custodians on secure handling of restricted areas
  12. Aligning physical upgrades with capital works planning cycles
Module 6. Strengthening personnel security under Domain 3
Ensure staff and contractors meet ongoing suitability requirements.
12 chapters in this module
  1. Screening new hires against security baseline requirements
  2. Managing security clearance applications and renewals
  3. Conducting pre-employment checks and reference validations
  4. Implementing role-based access provisioning workflows
  5. Tracking personnel security training completion rates
  6. Monitoring ongoing suitability through behavioural indicators
  7. Handling security breaches by personnel with due process
  8. Managing offboarding for staff with access to protected data
  9. Updating security acknowledgments annually or after incidents
  10. Auditing access rights against current job responsibilities
  11. Using automated tools to flag expired clearances or training
  12. Coordinating with HR and payroll systems for seamless updates
Module 7. Securing digital assets under Domain 4
Apply classification, handling, and disposal rules to information and devices.
12 chapters in this module
  1. Classifying data according to PSPF protection levels
  2. Labeling documents and files with correct security markings
  3. Encrypting data at rest and in transit for protected categories
  4. Implementing secure printing and release workflows
  5. Tracking asset ownership and location for laptops and mobile devices
  6. Enforcing secure disposal of storage media and paper records
  7. Using digital rights management for sensitive file sharing
  8. Controlling USB and external device usage with policy and tech
  9. Monitoring unauthorised data transfers and exfiltration attempts
  10. Creating asset registers with lifecycle tracking
  11. Integrating asset management with service desk and ITSM tools
  12. Reporting asset-related incidents within required timeframes
Module 8. Hardening ICT security controls in Domain 5
Configure systems and networks to meet technical baselines.
12 chapters in this module
  1. Applying ACSC hardening guidelines to operating systems
  2. Implementing multi-factor authentication across all privileged accounts
  3. Configuring firewalls and network segmentation for least privilege
  4. Patching systems on a defined and enforced schedule
  5. Monitoring for unauthorised configuration changes
  6. Enabling comprehensive logging and centralised SIEM integration
  7. Conducting regular vulnerability scans and remediation cycles
  8. Securing wireless networks with government-grade encryption
  9. Managing privileged access with PAM solutions
  10. Implementing email security controls to prevent phishing attacks
  11. Testing disaster recovery and backup integrity regularly
  12. Documenting ICT control configurations for assurance reviews
Module 9. Building effective security awareness programs for Domain 6
Drive behavioural change through targeted, measurable education.
12 chapters in this module
  1. Designing annual security awareness campaigns with clear objectives
  2. Creating role-specific training content for different user groups
  3. Delivering modules through blended learning formats
  4. Using phishing simulations to test and reinforce learning
  5. Tracking completion rates and knowledge retention metrics
  6. Incorporating real-world incident examples into training
  7. Engaging leadership to model secure behaviours
  8. Measuring reduction in human-driven security incidents
  9. Updating content annually or after major threats emerge
  10. Gathering feedback to improve program relevance
  11. Linking awareness outcomes to broader compliance goals
  12. Reporting program effectiveness to governance committees
Module 10. Managing supply chain risks as per Domain 7
Extend security expectations to vendors and partners.
12 chapters in this module
  1. Assessing supplier risk based on data access and service criticality
  2. Requiring PSPF alignment in procurement and contract templates
  3. Conducting pre-contract security assessments of vendors
  4. Performing regular reviews of third-party compliance status
  5. Including audit rights and data protection clauses in agreements
  6. Monitoring supplier security incidents and response times
  7. Managing onboarding and offboarding of vendor personnel
  8. Ensuring cloud providers meet PSPF hosting requirements
  9. Requiring evidence of cyber insurance and incident response plans
  10. Using SIG templates and assessment portals efficiently
  11. Reporting supply chain risks in assurance packages
  12. Updating vendor inventories and risk ratings quarterly
Module 11. Establishing incident response capabilities under Domain 8
Prepare for and respond to security events with discipline.
12 chapters in this module
  1. Defining what constitutes a reportable security incident
  2. Creating an incident response team with clear roles
  3. Developing playbooks for common attack scenarios
  4. Establishing communication protocols for internal and external reporting
  5. Meeting mandatory 72-hour reporting windows for significant events
  6. Conducting post-incident reviews and implementing improvements
  7. Preserving forensic evidence for investigation and prosecution
  8. Coordinating with ACSC and other government agencies during incidents
  9. Testing response plans through tabletop exercises
  10. Maintaining an incident register with root cause analysis
  11. Using lessons learned to update policies and controls
  12. Reporting incident trends and response effectiveness annually
Module 12. Sustaining compliance through review and assurance
Turn one-time implementation into lasting operational practice.
12 chapters in this module
  1. Scheduling internal reviews to test ongoing compliance
  2. Preparing for external assessments by IGIS or auditors
  3. Using checklists and evidence templates to streamline assurance
  4. Conducting control testing with sample-based validation
  5. Addressing findings with corrective action plans
  6. Maintaining a central repository for all compliance evidence
  7. Automating evidence collection where possible
  8. Training team members to support assurance processes
  9. Updating documentation after framework revisions or system changes
  10. Reporting compliance status to executive leadership
  11. Benchmarking maturity across the eight domains
  12. Planning continuous improvement cycles based on performance data

How this maps to your situation

  • When starting a new PSPF implementation
  • After completing an initial gap analysis
  • Before an internal or external assurance review
  • When onboarding new vendors or systems

Before vs. after

Before
Spending weeks assembling inconsistent evidence, reworking control mappings, and reacting to review findings.
After
Producing consistent, scrutiny-ready implementation packs in days , becoming the trusted internal reference.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, designed for completion over 12 weeks with real-world application.

If nothing changes
Without a structured approach, teams face repeated rework, delayed approvals, and missed opportunities to lead on high-visibility security initiatives.

How this compares to the alternatives

Unlike generic compliance guides, this course provides implementation-grade detail tailored to the Australian Government context, with templates and examples you can use immediately.

Frequently asked

Is this course suitable for non-government professionals?
Yes, especially for consultants, contractors, or technology providers supporting government clients.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Are there video lessons or live sessions?
No, the course is text-based with downloadable resources to support hands-on learning.
$199 one-time. Approximately 90 minutes per module, designed for completion over 12 weeks with real-world application..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours