DSPF Principle 16 / Control 16.1 / Annex A
DSPF Principle 16 — Defence Industry Security Program (Control 16.1 + Annex A DISP Membership Level Requirements)
- Requirements
- 60
- Last reviewed
- 15/04/2026
- Next review
- 15/04/2027
- Source
- Principle 16 version 8 (29 January 2026); Control 16.1 version 10 (29 January 2026); Annex A version 7 (29 January 2026)
Reconciliation notes
DSPF compliance library is curated (not auto-extracted) because the source is a markdown compendium with bullet-list requirements organised by Principle/Control/Annex sections rather than 'shall'-numbered EPUB clauses. Westlink is an Entry Level DISP member — Level 1/2/3 Annex A rows are marked applicability=Not Applicable with rationale. Total requirements: 60; Entry Level applicable: 45. Coverage on Applicable rows (recomputed 11/06/2026): Full=10, Partial=28, Gap=6. Gap severities: {'Low': 0, 'Medium': 3, 'High': 3, 'Critical': 0}. Substantial gap cluster reflects that DISP-specific evidence (SGR, SPP, SRA, ASR records, CSO/SO acknowledgement letters, AE250 application) is carried in the DISP project folder rather than the controlled WMS document corpus — bringing DEF-POL-001 Defence Security Policy and related documents into the WMS would close most Partial/Gap rows.
Requirements
Showing 60 of 60 requirements
| ID | Clause | Requirement | Applicability | Coverage | Evidence | Gap |
|---|---|---|---|---|---|---|
| DSPF-C16.1-elig-01 | C16.1-elig-01 | Be registered as a legal business entity in Australia (ABN or ACN). | Applicable | Full |
| |
| DSPF-C16.1-elig-02 | C16.1-elig-02 | Be financially solvent (not under administration or receivership). | Applicable | Not Applicable |
| Solvency attestation is carried in ASIC extracts (DISP project reference/) rather than in the controlled WMS document corpus. Add annual solvency attestation to Security Governance Register (SGR) or equivalent controlled document. |
| DSPF-C16.1-elig-03 | C16.1-elig-03 | Have a director/senior executive able to obtain an Australian Personnel Security Clearance and fulfil the CSO role. | Not Applicable | Not Applicable | — | |
| DSPF-C16.1-elig-04 | C16.1-elig-04 | Have a staff member able to obtain a clearance and fulfil the SO role (CSO and SO can be the same individual). | Not Applicable | Not Applicable | — | |
| DSPF-C16.1-elig-05 | C16.1-elig-05 | Establish and maintain security standards for the membership level (per Annex A). | Applicable | Partial |
| Aggregate requirement — coverage depends on per-domain Entry Level rows (A16.1-entry-gov-*, A16.1-entry-pers-*, A16.1-entry-phys-*, A16.1-entry-cyber-*) below. |
| DSPF-C16.1-app-01 | C16.1-app-01 | DISP applicants and members must have a centralised email (DISP@companydomain format), hosted in Australia, not web-based mail. | Applicable | Gap | — | Medium Operational practice exists (DISP@ mailbox on Australian-hosted tenancy) but not documented in controlled WMS documents. Add to TEC-POL-001 or Information Security Standard. |
| DSPF-C16.1-ongoing-01 | C16.1-ongoing-01 | DISP members must comply with contemporary Australian Government and Defence security legislation and policies (DSPF, PSPF, ISM). | Applicable | Partial |
| Compliance commitment present in Manual §11.3; specific mechanism for tracking DSPF / PSPF / ISM updates and flowing into WMS procedures not documented beyond the general legal-register process in §6.1.3. |
| DSPF-C16.1-ongoing-02 | C16.1-ongoing-02 | DISP members must report all security and cyber security incidents per Control 77.1 and Control 24.1. | Applicable | Partial |
| Security incident reporting pathway (internal reporting → SO → DISB via DISP Member Portal; timeframes per DSPF Control 77.1) not documented in a controlled WMS document. DEF-POL-001 likely covers this but is not in the WMS corpus. |
| DSPF-C16.1-ongoing-03 | C16.1-ongoing-03 | DISP members must complete an Annual Security Report (ASR). | Applicable | Full |
| |
| DSPF-C16.1-ongoing-04 | C16.1-ongoing-04 | DISP members must report to DISB all changes that might impact membership (eligibility changes, ownership/control changes, contact details, CSO/SO changes). | Applicable | Partial |
| Change-in-circumstance notification to DISB (14 business days for CSO/SO changes, otherwise as they occur) not documented in a controlled WMS document. Add trigger to Management of Change or Security Governance procedure. |
| DSPF-C16.1-ongoing-05 | C16.1-ongoing-05 | DISP members must engage with uplift, remediation and assurance activities. | Applicable | Partial |
| Engagement with DISP assurance is operational but not tied to the WMS management review cycle or a controlled procedure. |
| DSPF-C16.1-ongoing-06 | C16.1-ongoing-06 | DISP members must implement recommendations within agreed timeframes. | Applicable | Partial |
| Recommendation tracking path from DISB assurance → corrective action register not documented. |
| DSPF-C16.1-cso-01 | C16.1-cso-01 | CSO must be a director or senior executive able to implement policy and direct resources. | Applicable | Full |
| |
| DSPF-C16.1-cso-02 | C16.1-cso-02 | CSO must complete DISP Security Officer Training course as part of application and every three years thereafter. | Applicable | Partial |
| Three-yearly DISP SO training cycle for CSO not tracked in controlled WMS document. Add to training register and/or Security Governance procedure. |
| DSPF-C16.1-cso-03 | C16.1-cso-03 | CSO is accountable for membership obligations, risk oversight, reporting, protection of materials, ASR completion, and reporting changes to Defence. | Applicable | Partial |
| CSO accountabilities not captured in a controlled WMS document. disp_cso-so-responsibilities.md exists in DISP project but is not in WMS corpus. |
| DSPF-C16.1-so-01 | C16.1-so-01 | SO must obtain and maintain a Personnel Security Clearance commensurate with membership level. | Applicable | Partial |
| Personnel Security Clearance maintenance for SO not documented in WMS corpus. Entry Level requires Baseline minimum (per Annex A). |
| DSPF-C16.1-so-02 | C16.1-so-02 | To sponsor/manage clearances, SO must hold minimum NV1 clearance (cannot sponsor clearances above own level). | Not Applicable | Not Applicable | — | Entry Level SO cannot sponsor clearances (per Annex A Entry Level Personnel Security). Requirement applies when SO level upgrades to Level 1 or above. |
| DSPF-C16.1-so-03 | C16.1-so-03 | SO must complete DISP Security Officer Training and additional required training every three years. | Applicable | Partial |
| SO training cycle not documented in WMS controlled document. |
| DSPF-C16.1-so-04 | C16.1-so-04 | SO is responsible for security policies/plans, protection of materials, security education, insider threat arrangements, incident/contact reporting, DSAP list maintenance, clearance management. | Applicable | Partial |
| SO duties distributed across multiple DISP-project documents (SGR, SPP, SRA) but not in WMS corpus. |
| DSPF-C16.1-so-05 | C16.1-so-05 | Changes to CSO or SO must be notified to Defence within 14 business days. | Applicable | Partial |
| Specific 14-day notification timeframe not tracked as a WMS trigger. |
| DSPF-A16.1-all-01 | A16.1-all-01 | All Industry Entities must meet and maintain requirements in Control 16.1. | Applicable | Partial |
| Medium Section 11.3 names DISP/ISM/PSPF/JOSCAR as references but aggregate satisfaction of Control 16.1 is not demonstrated; the individual A16.1 rows are mostly Partial. |
| DSPF-A16.1-all-02 | A16.1-all-02 | All Industry Entities must demonstrate they have met and can maintain Annex A requirements. | Applicable | Partial |
| Demonstration evidence mostly carried in DISP project folder (SGR, SPP, SRA, ASR records) rather than WMS corpus. |
| DSPF-A16.1-all-03 | A16.1-all-03 | All Industry Entities must ensure Security Governance domain matches or exceeds highest level across other domains. | Applicable | Full |
| |
| DSPF-A16.1-all-04 | A16.1-all-04 | All Industry Entities must engage with audit and uplift activities conducted by Defence or nominated third party. | Applicable | Partial |
| DISP audit engagement not documented in WMS controlled document beyond internal audit reference. |
| DSPF-A16.1-entry-gov-01 | A16.1-entry-gov-01 | Appoint and retain a CSO and at least one SO (can be same individual). | Applicable | Full |
| |
| DSPF-A16.1-entry-gov-02 | A16.1-entry-gov-02 | Establish and maintain policies and procedures covering security governance arrangements including designated security positions and contacts. | Applicable | Partial |
| Security governance arrangement coverage weak in WMS corpus. Primary evidence (SGR) is in DISP project. Bring DEF-POL-001 (Defence Security Policy) into WMS corpus to close. |
| DSPF-A16.1-entry-gov-03 | A16.1-entry-gov-03 | Establish and maintain policies and procedures covering risk management inclusive of security considerations and business security risk assessments. | Applicable | Partial |
| Security risk management (SRA) not integrated into controlled WMS corpus. QHSE-PRO-002 Risk Management Procedure (not yet in corpus) could consolidate. |
| DSPF-A16.1-entry-gov-04 | A16.1-entry-gov-04 | Establish and maintain policies and procedures covering security training arrangements for all personnel. | Applicable | Full |
| |
| DSPF-A16.1-entry-gov-05 | A16.1-entry-gov-05 | Establish and maintain a security incidents register covering all types (personnel, physical, information, cyber). | Applicable | Gap | — | High WMS has QHSE-PRO-001 (Hazard and Incident — WHS/environmental) and isCompliant incident module. Security-specific incident register covering personnel/physical/information/cyber not established as a controlled-document register. DISB reporting requires this register. Severity High — direct DISP audit-finding risk. |
| DSPF-A16.1-entry-gov-06 | A16.1-entry-gov-06 | Establish and maintain security reporting arrangements and register of contacts with foreign persons/entities. | Applicable | Gap | — | High Contact reporting obligations under DSPF Principle 45 apply; no controlled WMS document captures foreign contact reporting procedure or register. DISP DSAP list maintained informally in DISP project. Severity High. |
| DSPF-A16.1-entry-gov-07 | A16.1-entry-gov-07 | Establish and maintain a register of overseas travel with completed travel forms and travel briefing records for cleared personnel. | Not Applicable | Not Applicable | — | |
| DSPF-A16.1-entry-gov-08 | A16.1-entry-gov-08 | Establish and maintain insider threat identification, reporting and management arrangements. | Applicable | Partial |
| Insider threat training (def-pre-002-insider-threat-training.pptx) exists in DISP project but not as a controlled WMS programme. Add explicit insider threat procedure to WMS. |
| DSPF-A16.1-entry-gov-09 | A16.1-entry-gov-09 | Engage in all annual DISP assurance activities (reporting, training, uplift programs). | Applicable | Partial |
| Annual DISP assurance cadence not tied to WMS management review or internal audit programme. |
| DSPF-A16.1-entry-gov-10 | A16.1-entry-gov-10 | Notify Defence of changes affecting membership (ownership, financial position, supply chain, criminal exposure). | Applicable | Gap | — | Medium Change-in-circumstance notification requirements not documented in any controlled WMS document. Similar to C16.1-ongoing-04 but here specifically covering ownership/financial/supply-chain/criminal-exposure triggers. |
| DSPF-A16.1-entry-gov-cso-so-01 | A16.1-entry-gov-cso-so-01 | CSO and SO must complete DISP Security Officer Training (initial and every three years). | Applicable | Partial |
| Duplicate of C16.1-cso-02 and C16.1-so-03 — kept here for Annex A traceability. |
| DSPF-A16.1-entry-gov-cso-so-02 | A16.1-entry-gov-cso-so-02 | CSO and SO must demonstrate ability to manage security up to and including OFFICIAL/OFFICIAL: Sensitive level. | Applicable | Partial |
| Competency demonstration typically via DISP Security Officer Training completion + ASR; not in WMS corpus. |
| DSPF-A16.1-entry-pers-01 | A16.1-entry-pers-01 | Establish and maintain policies/procedures per AS 4811-2022 (Workforce Screening). | Applicable | Full |
| |
| DSPF-A16.1-entry-pers-02 | A16.1-entry-pers-02 | Establish and maintain procedures for on-boarding, ongoing assessment, and separating personnel. | Applicable | Partial |
| HR procedures for on-boarding/ongoing/separation not in WMS corpus as controlled documents. |
| DSPF-A16.1-entry-pers-03 | A16.1-entry-pers-03 | Establish and maintain a DSAP register (available to Defence on request). | Applicable | Gap | — | High DSAP (Designated Security Assessed Positions) register not established as a controlled WMS document. Personnel file content is in HR system; DISP-specific DSAP categorisation not applied. Severity High — DISB may request. |
| DSPF-A16.1-entry-pers-04 | A16.1-entry-pers-04 | Report engagement of foreign nationals and other disclosures of interest to Defence. | Applicable | Gap | — | Medium Foreign national engagement reporting procedure not documented in WMS corpus. |
| DSPF-A16.1-entry-pers-05 | A16.1-entry-pers-05 | Provide Defence a copy of workforce screening and management processes. | Applicable | Partial |
| Deliverable to DISB is typically the workforce screening procedure (HR-PRO-001, now live). A copy is not yet recorded as having been provided to Defence; coverage remains Partial pending evidence of provision. |
| DSPF-A16.1-entry-pers-cso-so-01 | A16.1-entry-pers-cso-so-01 | CSO and/or SO must be Australian citizens. | Applicable | Full |
| |
| DSPF-A16.1-entry-pers-cso-so-02 | A16.1-entry-pers-cso-so-02 | CSO and/or SO must be able to obtain and maintain a minimum Baseline security clearance per AGSVA policy. | Applicable | Partial |
| Clearance status carried in DISP project (CSO/SO acknowledgement letters); not in WMS controlled document. |
| DSPF-A16.1-entry-phys-01 | A16.1-entry-phys-01 | Establish and maintain policies/procedures covering physical security and access controls at each accredited facility. | Applicable | Partial |
| Physical Security Policy not in WMS corpus. DISP SPP (Security Policies and Procedures) exists in DISP project. |
| DSPF-A16.1-entry-phys-02 | A16.1-entry-phys-02 | Provide facility ownership and leasing arrangement details to Defence as required. | Applicable | Partial |
| Facility ownership/lease register not maintained in WMS controlled document. |
| DSPF-A16.1-entry-cyber-01 | A16.1-entry-cyber-01 | Meet or exceed ASD's Essential Eight (E8) at Maturity Level 2 across all of the Entity's ICT corporate systems used to correspond with Defence. | Applicable | Partial |
| E8 ML2 maturity posture documented in DISP project (e8_westlink-current-posture.md, e8_test_plan_ml2.md); DISP Cyber Security Questionnaire evidence not in WMS corpus. E8 vertical slice (deferred to ~22 Dec 2026 pre-ASR window per S1 plan) will provide row-level coverage. |
| DSPF-A16.1-entry-cyber-02 | A16.1-entry-cyber-02 | Entities complying with international standards (ISO/IEC 27001:2022, NIST SP 800-171, Def Stan 5-138) can use documentation to demonstrate partial compliance, but these are not equivalent to E8 — full E8 mitigation strategies must still be demonstrated in the DISP Cyber Security Questionnaire. | Not Applicable | Not Applicable | — | Westlink does not currently hold ISO/IEC 27001, NIST SP 800-171, or Def Stan 5-138 certification. Requirement is a clarification, not a standalone obligation — marking Not Applicable. If Westlink later obtains ISO 27001, revisit. |
| DSPF-A16.1-L1-gov-01 | A16.1-L1-gov-01 | Level 1 Security Governance: maintain register of all personnel sponsored for a security clearance. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-gov-02 | A16.1-L1-gov-02 | Level 1 Security Governance: complete all annual assurance activities. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-gov-03 | A16.1-L1-gov-03 | Level 1 Security Governance: SO must maintain NV1 clearance and demonstrate ability to manage up to PROTECTED level. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-pers-01 | A16.1-L1-pers-01 | Level 1 Personnel Security: SO must actively monitor and manage ongoing suitability of sponsored security cleared personnel. | Not Applicable | Not Applicable |
| Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-pers-02 | A16.1-L1-pers-02 | Level 1 Personnel Security: SO eligible to sponsor clearances up to and including Baseline level. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-phys-01 | A16.1-L1-phys-01 | Level 1 Physical Security: at least one facility certified and accredited per DSPF Principle 72 / Control 72.1 to receive, handle, store and destroy PROTECTED information and material per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L1-cyber-01 | A16.1-L1-cyber-01 | Level 1 Information and Cyber Security: at least one system certified and accredited per DSPF Principle 23 / Control 23.1 to handle PROTECTED information per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L2-gov-01 | A16.1-L2-gov-01 | Level 2 Security Governance: SO must demonstrate ability to manage up to SECRET level. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L2-phys-01 | A16.1-L2-phys-01 | Level 2 Physical Security: facility accredited to receive, handle, store and destroy SECRET information per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L2-cyber-01 | A16.1-L2-cyber-01 | Level 2 Information and Cyber Security: network accredited per DSPF Principle 23 / Control 23.1 to handle SECRET information per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L3-gov-01 | A16.1-L3-gov-01 | Level 3 Security Governance: documented SES Band 3 / ADF equivalent endorsement before obtaining PV clearance, certifying SCIF, or accrediting TOP SECRET network. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L3-phys-01 | A16.1-L3-phys-01 | Level 3 Physical Security: facility certified and accredited for TOP SECRET per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
| DSPF-A16.1-L3-cyber-01 | A16.1-L3-cyber-01 | Level 3 Information and Cyber Security: network certified and accredited for TOP SECRET per ISM/DSPF. | Not Applicable | Not Applicable | — | Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping. |
Source document
DSPF Principle 16 — Defence Industry Security Program (Control 16.1 + Annex A DISP Membership Level Requirements)
60 normative shall-statements extracted from DSPF Principle 16 / Control 16.1 / Annex A (source: ~/projects/DISP/disp_dspf-interim-public.md). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.
Coverage summary
| Coverage | Count |
|---|---|
| ✅ Full | 8 |
| 🟡 Partial | 27 |
| 🟠 Ref-only | 0 |
| 🔴 Gap | 6 |
| — N/A | 19 |
Gap severity distribution
| Severity | Count |
|---|---|
| 🔴 Critical | 0 |
| 🟠 High | 3 |
| 🟡 Medium | 4 |
| 🟢 Low | 0 |
Requirements
Clause A16
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| DSPF-A16.1-all-01 | 🟡 Partial | QHSE-MAN-001 §‘11.3’ | 🟡 Medium | Section 11.3 names DISP/ISM/PSPF/JOSCAR as references but aggregate satisfaction of Control 16.1 is not demonstrated; the individual A16.1 rows are mostly Partial. |
| DSPF-A16.1-all-02 | 🟡 Partial | QHSE-MAN-001 §‘11.3’ | Demonstration evidence mostly carried in DISP project folder (SGR, SPP, SRA, ASR records) rather than WMS corpus. | |
| DSPF-A16.1-all-03 | ✅ Full | QHSE-MAN-001 §‘11.3’ | ||
| DSPF-A16.1-all-04 | 🟡 Partial | QHSE-MAN-001 §‘9.3’ | DISP audit engagement not documented in WMS controlled document beyond internal audit reference. | |
| DSPF-A16.1-entry-gov-01 | ✅ Full | QHSE-MAN-001 §‘5.2’ | ||
| DSPF-A16.1-entry-gov-02 | 🟡 Partial | QHSE-MAN-001 §‘5.2’ | Security governance arrangement coverage weak in WMS corpus. Primary evidence (SGR) is in DISP project. Bring DEF-POL-001 (Defence Security Policy) into WMS corpus to close. | |
| DSPF-A16.1-entry-gov-03 | 🟡 Partial | QHSE-MAN-001 §‘6.1’ | Security risk management (SRA) not integrated into controlled WMS corpus. QHSE-PRO-002 Risk Management Procedure (not yet in corpus) could consolidate. | |
| DSPF-A16.1-entry-gov-04 | ✅ Full | QHSE-MAN-001 §‘7.2’ QHSE-MAN-001 §‘7.3’ [GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments) TEC-POL-001 §Responsibilities TEC-PRO-001 §‘Responsibilities’ | ||
| DSPF-A16.1-entry-gov-05 | 🔴 Gap | — | 🟠 High | WMS has QHSE-PRO-001 (Hazard and Incident — WHS/environmental) and isCompliant incident module. Security-specific incident register covering personnel/physical/information/cyber not established as a controlled-document register. DISB reporting requires this register. Severity High — direct DISP audit-finding risk. |
| DSPF-A16.1-entry-gov-06 | 🔴 Gap | — | 🟠 High | Contact reporting obligations under DSPF Principle 45 apply; no controlled WMS document captures foreign contact reporting procedure or register. DISP DSAP list maintained informally in DISP project. Severity High. |
| DSPF-A16.1-entry-gov-07 | — N/A | — | N/A — Overseas Travel Register and pre/post-travel briefing records for cleared personnel are maintained in the DISP program (Overseas Travel Register SGR C3, AB644 forms, DISO G9; DSPF Control 16.1 para 71(f)) — not a WMS-library obligation. | |
| DSPF-A16.1-entry-gov-08 | 🟡 Partial | GOV-POL-018 GOV-POL-006 [GOV-POL-016 §Organisational Context](/wms/GOV-POL-016#sOrganisational Context) | Insider threat training (def-pre-002-insider-threat-training.pptx) exists in DISP project but not as a controlled WMS programme. Add explicit insider threat procedure to WMS. | |
| DSPF-A16.1-entry-gov-09 | 🟡 Partial | QHSE-MAN-001 §‘9.3’ | Annual DISP assurance cadence not tied to WMS management review or internal audit programme. | |
| DSPF-A16.1-entry-gov-10 | 🔴 Gap | — | 🟡 Medium | Change-in-circumstance notification requirements not documented in any controlled WMS document. Similar to C16.1-ongoing-04 but here specifically covering ownership/financial/supply-chain/criminal-exposure triggers. |
| DSPF-A16.1-entry-gov-cso-so-01 | 🟡 Partial | QHSE-MAN-001 §‘7.2’ | Duplicate of C16.1-cso-02 and C16.1-so-03 — kept here for Annex A traceability. | |
| DSPF-A16.1-entry-gov-cso-so-02 | 🟡 Partial | QHSE-MAN-001 §‘5.2’ | Competency demonstration typically via DISP Security Officer Training completion + ASR; not in WMS corpus. | |
| DSPF-A16.1-entry-pers-01 | ✅ Full | HR-PRO-001 QHSE-MAN-001 §‘7.2’ [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) | ||
| DSPF-A16.1-entry-pers-02 | 🟡 Partial | QHSE-MAN-001 §‘7.2’ | HR procedures for on-boarding/ongoing/separation not in WMS corpus as controlled documents. | |
| DSPF-A16.1-entry-pers-03 | 🔴 Gap | — | 🟠 High | DSAP (Designated Security Assessed Positions) register not established as a controlled WMS document. Personnel file content is in HR system; DISP-specific DSAP categorisation not applied. Severity High — DISB may request. |
| DSPF-A16.1-entry-pers-04 | 🔴 Gap | — | 🟡 Medium | Foreign national engagement reporting procedure not documented in WMS corpus. |
| DSPF-A16.1-entry-pers-05 | 🟡 Partial | QHSE-MAN-001 §‘7.2’ | Deliverable to DISB is typically the workforce screening procedure (HR-PRO-001, now live). A copy is not yet recorded as having been provided to Defence; coverage remains Partial pending evidence of provision. | |
| DSPF-A16.1-entry-pers-cso-so-01 | ✅ Full | QHSE-MAN-001 §‘5.2’ | ||
| DSPF-A16.1-entry-pers-cso-so-02 | 🟡 Partial | QHSE-MAN-001 §7.2.1 | Clearance status carried in DISP project (CSO/SO acknowledgement letters); not in WMS controlled document. | |
| DSPF-A16.1-entry-phys-01 | 🟡 Partial | QHSE-MAN-001 §‘7.1’ | Physical Security Policy not in WMS corpus. DISP SPP (Security Policies and Procedures) exists in DISP project. | |
| DSPF-A16.1-entry-phys-02 | 🟡 Partial | QHSE-MAN-001 §‘2.3’ | Facility ownership/lease register not maintained in WMS controlled document. | |
| DSPF-A16.1-entry-cyber-01 | 🟡 Partial | TEC-POL-001 TEC-POL-002 | E8 ML2 maturity posture documented in DISP project (e8_westlink-current-posture.md, e8_test_plan_ml2.md); DISP Cyber Security Questionnaire evidence not in WMS corpus. E8 vertical slice (deferred to ~22 Dec 2026 pre-ASR window per S1 plan) will provide row-level coverage. | |
| DSPF-A16.1-entry-cyber-02 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-gov-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-gov-02 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-gov-03 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-pers-01 | — N/A | [GOV-POL-016 §Organisational Context](/wms/GOV-POL-016#sOrganisational Context) | N/A — | |
| DSPF-A16.1-L1-pers-02 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-phys-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L1-cyber-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L2-gov-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L2-phys-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L2-cyber-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L3-gov-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L3-phys-01 | — N/A | — | N/A — | |
| DSPF-A16.1-L3-cyber-01 | — N/A | — | N/A — |
Clause C16
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| DSPF-C16.1-elig-01 | ✅ Full | QHSE-MAN-001 §‘1’ | ||
| DSPF-C16.1-elig-02 | — N/A | QHSE-MAN-001 §‘1’ | Solvency attestation is carried in ASIC extracts (DISP project reference/) rather than in the controlled WMS document corpus. Add annual solvency attestation to Security Governance Register (SGR) or equivalent controlled document. | |
| DSPF-C16.1-elig-03 | — N/A | — | N/A — Personnel clearance eligibility is managed in the DISP program (DSAP register + Baseline clearances for the CSO and 2 Security Officers + AGSVA myClearance verification) — not a WMS-library obligation. | |
| DSPF-C16.1-elig-04 | — N/A | — | N/A — Personnel clearance eligibility is managed in the DISP program (DSAP register + Baseline clearances + AGSVA myClearance verification) — not a WMS-library obligation. | |
| DSPF-C16.1-elig-05 | 🟡 Partial | QHSE-MAN-001 §‘11.3’ | Aggregate requirement — coverage depends on per-domain Entry Level rows (A16.1-entry-gov-, A16.1-entry-pers-, A16.1-entry-phys-, A16.1-entry-cyber-) below. | |
| DSPF-C16.1-app-01 | 🔴 Gap | — | 🟡 Medium | Operational practice exists (DISP@ mailbox on Australian-hosted tenancy) but not documented in controlled WMS documents. Add to TEC-POL-001 or Information Security Standard. |
| DSPF-C16.1-ongoing-01 | 🟡 Partial | QHSE-MAN-001 §‘11.3’ TEC-POL-001 | Compliance commitment present in Manual §11.3; specific mechanism for tracking DSPF / PSPF / ISM updates and flowing into WMS procedures not documented beyond the general legal-register process in §6.1.3. | |
| DSPF-C16.1-ongoing-02 | 🟡 Partial | QHSE-MAN-001 §‘10.1’ QHSE-PRO-001 [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | Security incident reporting pathway (internal reporting → SO → DISB via DISP Member Portal; timeframes per DSPF Control 77.1) not documented in a controlled WMS document. DEF-POL-001 likely covers this but is not in the WMS corpus. | |
| DSPF-C16.1-ongoing-03 | ✅ Full | QHSE-MAN-001 §‘11.3’ | ||
| DSPF-C16.1-ongoing-04 | 🟡 Partial | QHSE-MAN-001 §‘6.3’ | Change-in-circumstance notification to DISB (14 business days for CSO/SO changes, otherwise as they occur) not documented in a controlled WMS document. Add trigger to Management of Change or Security Governance procedure. | |
| DSPF-C16.1-ongoing-05 | 🟡 Partial | QHSE-MAN-001 §‘9.3’ | Engagement with DISP assurance is operational but not tied to the WMS management review cycle or a controlled procedure. | |
| DSPF-C16.1-ongoing-06 | 🟡 Partial | QHSE-MAN-001 §‘10.2’ | Recommendation tracking path from DISB assurance → corrective action register not documented. | |
| DSPF-C16.1-cso-01 | ✅ Full | QHSE-MAN-001 §‘5.2’ TEC-PRO-001 §‘Responsibilities’ | ||
| DSPF-C16.1-cso-02 | 🟡 Partial | QHSE-MAN-001 §‘7.2’ | Three-yearly DISP SO training cycle for CSO not tracked in controlled WMS document. Add to training register and/or Security Governance procedure. | |
| DSPF-C16.1-cso-03 | 🟡 Partial | QHSE-MAN-001 §‘5.1’ | CSO accountabilities not captured in a controlled WMS document. disp_cso-so-responsibilities.md exists in DISP project but is not in WMS corpus. | |
| DSPF-C16.1-so-01 | 🟡 Partial | QHSE-MAN-001 §7.2.1 TEC-PRO-001 §‘Responsibilities’ | Personnel Security Clearance maintenance for SO not documented in WMS corpus. Entry Level requires Baseline minimum (per Annex A). | |
| DSPF-C16.1-so-02 | — N/A | — | N/A — | |
| DSPF-C16.1-so-03 | 🟡 Partial | QHSE-MAN-001 §‘7.2’ | SO training cycle not documented in WMS controlled document. | |
| DSPF-C16.1-so-04 | 🟡 Partial | QHSE-MAN-001 §‘5.2’ | SO duties distributed across multiple DISP-project documents (SGR, SPP, SRA) but not in WMS corpus. | |
| DSPF-C16.1-so-05 | 🟡 Partial | QHSE-MAN-001 §‘6.3’ | Specific 14-day notification timeframe not tracked as a WMS trigger. |
Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.