Resources

The following is a list of all the resources that are associated with Right Fit For Risk.

RFFR Provider Security Plan (PSP) Template

Created:

The Provider Security Plan (PSP) provides the Department with an overview of the applicable entity's operating environment, service delivery context, and security program supporting the delivery of Departmental services.

RFFR Provider Security Plan Annex (PSP-A) Template

Created:

The Provider Security Plan Annex (PSP-A) complements the Provider Security Plan (PSP) by describing the security controls implemented to support the secure delivery of those services and the protection of relevant information.

RFFR Security Assessment Questionnaire (SAQ) Template

Created:

The objective of the Security Assessment Questionnaire (SAQ) is to demonstrate to the Department that the applicable entity has implemented appropriate information security controls to support the secure delivery of Departmental programs.

External Systems Assurance Framework

Created:

This framework sets out the External Systems Assurance Framework (ESAF) under which the Department gains assurance over External IT Systems, and provides information for Providers.

External Systems Assurance Framework.pdf

Change of Circumstances Form

Created:

This form is to be completed by Service Providers and Third-Party Employment and Skills (TPES) system vendors to notify the Department of any change in circumstances that may alter the organisation’s risk profile.

DEWR ISMS Scheme

Created:

Outlines what the DEWR ISMS Scheme is, who it is for, and key considerations for all applicable stakeholders.

DEWR ISMS Scheme - Issue 3.pdf

Third-Party IT Vendor Deed Guidelines

Created:

Provides Third-Party IT Vendor Deed Guidelines that form part of the Deed and provides information for Vendors on their continuing obligations.

TPIT Vendor Guidelines v1.0.pdf

ReadyTech's Esher House Cortex Accreditation Report

Created:
Modified:

Refresh of the existing publication as a result of recent accreditation of TPES system Esher House

RFFR Accreditation for ReadyTech Esher House.pdf

ReadyTech's JobReady Accreditation Report

Created:
Modified:

Refresh of the existing publication as a result of recent accreditation of TPES system Job Ready.

RFFR Accreditation for ReadyTech Job Ready.pdf

ReadyTech's Ready Apprentice Accreditation Report

Created:
Modified:

Refresh of the existing publication as a result of recent accreditation of TPES system Ready Apprentice

RFFR Accreditation for ReadyTech Ready Apprentice.pdf

ReadyTech's Ready Recruit Accreditation Report

Created:
Modified:

Refresh of the existing publication as a result of recent accreditation of TPES system Ready Recruit.

RFFR Accreditation for ReadyTech Ready Recruit.pdf

RFFR Statement of Applicability (SoA) Template

Created:
Modified:

The Statement of Applicability (SoA) template includes controls from contractual obligations, Australian Government Information Security Manual (ISM) and ISO/IEC 27001 Annex A.

Right Fit For Risk (RFFR) Categorisation Questionnaire

Created:
Modified:

The Categorisation Questionnaire helps the department understand how each Provider handles participant data and delivers services. This information is used to determine the Provider’s assurance category, which then sets the level of assurance they need to meet to achieve RFFR accreditation.

right fit for risk form

Scope template

Created:
Modified:

Provides example headings and guidance for documenting the ISMS Scope in accordance with ISO27001 clause 4, while also communicating key elements of the business, systems and information associated with delivering the Services and describing the provider’s implementation of the RFFR Core Expectation areas.

Right Fit For Risk (RFFR) Scope Template.pdf

JobReady Live Accreditation letter

Created:

This is an accreditation letter to a third party employment system provider outlining their requirements and responsibilities for accreditation.