The objective of the External Systems Assurance Framework (ESAF) is to ensure that External IT Systems and supporting processes used in the delivery of Services comply with Australian Government security and privacy requirements.
On this page:
The ESAF provides a structured assurance framework for External IT Systems used by Providers or Subcontractors that:
- Support the delivery of Services.
- Are used to access the department’s IT Systems.
Overview
The ESAF outlines how the department gains assurance over External IT Systems and provides information for Providers about:
- The security and assurance requirements that Providers must meet under the ESAF.
- How Providers must meet these requirements, including achieving and maintaining Right Fit For Risk (RFFR) Accreditation for any Provider IT System, and meeting requirements relating to Third Party IT accreditation.
Developed in alignment with the Protective Security Policy Framework (PSPF), the ESAF ensures the RFFR accreditation approach reflects whole of government security requirements, as well as relevant legislative and regulatory obligations.
Download the External Systems Assurance Framework (ESAF)
Right Fit For Risk
The department’s RFFR assurance approach operationalises the ESAF by defining the processes through which the department obtains assurance over External IT Systems.
RFFR applies a risk-based methodology to ensure requirements are proportionate to the department’s risk exposure. RFFR also establishes the Assurance Lifecycle through which Providers achieve and maintain RFFR Accreditation.