Closed
Invited
APSC2699 - Delivery of cyber-security assessment and development of security artefacts to achieve an Authority to Operate for a SaaS solution
Tender ID: 626550
Tender Details
Organisation:
Tender #:
PCS-04662
Status:
Closed
Publish Date:
24 September 2026
Closing Date:
29 September 2026
Closing Time:
11:59 PM (Australia/ACT)
Tender Description
This Tender is invited by the Issuer.
Overview
The Australian Public Service Commission (APSC) is seeking an experienced vendor to establish an Authority to Operate (ATO) for its Case Management System, a SaaS solution. This requires the completion of security governance, risk assessment, control implementation, and assurance activities necessary to enable the APSC's Chief Security Officer to make an informed risk-based decision around the operation of the system.
Scope
The scope includes:
- Delivering a complete ATO artefact suite
- Providing specialist advice to support accreditation decision-making
- Assessing and assuring that controls are implemented and operating as intended, using the IRAP assessment already undertaken by the system vendor, which will be shared with the successful candidate
- Preparation of a Security Risk Management Plan (SRMP), Cyber Incident Response Plan, and System Security Plan as required under PSPF requirements
- An assessment of control effectiveness mapped to applicable ISM controls within the system boundary
- Identification of residual risks and recommended treatments
- Any additional documentation or artefacts required to support the ATO
Contractor Requirements
- The assessment must be conducted by an ACSC-certified IRAP assessor
- The assessment must be sufficient to support security authorisation at the PROTECTED level
Enquiries
Buyer contact: tenders@apsc.gov.au
Location
Similar Tenders
Active opportunities matching this tender's categories and regions.