Skip to main content
Westlink Intranet

Command Palette

Search for a command to run...

?
INTERNAL
Back to Compliance

DSPF Principle 16 / Control 16.1 / Annex A

DSPF Principle 16 — Defence Industry Security Program (Control 16.1 + Annex A DISP Membership Level Requirements)

Requirements
60
Last reviewed
15/04/2026
Next review
15/04/2027
Source
Principle 16 version 8 (29 January 2026); Control 16.1 version 10 (29 January 2026); Annex A version 7 (29 January 2026)

Reconciliation notes

DSPF compliance library is curated (not auto-extracted) because the source is a markdown compendium with bullet-list requirements organised by Principle/Control/Annex sections rather than 'shall'-numbered EPUB clauses. Westlink is an Entry Level DISP member — Level 1/2/3 Annex A rows are marked applicability=Not Applicable with rationale. Total requirements: 60; Entry Level applicable: 45. Coverage on Applicable rows (recomputed 11/06/2026): Full=10, Partial=28, Gap=6. Gap severities: {'Low': 0, 'Medium': 3, 'High': 3, 'Critical': 0}. Substantial gap cluster reflects that DISP-specific evidence (SGR, SPP, SRA, ASR records, CSO/SO acknowledgement letters, AE250 application) is carried in the DISP project folder rather than the controlled WMS document corpus — bringing DEF-POL-001 Defence Security Policy and related documents into the WMS would close most Partial/Gap rows.

Requirements

Showing 60 of 60 requirements

IDClauseRequirementApplicabilityCoverageEvidenceGap
DSPF-C16.1-elig-01C16.1-elig-01Be registered as a legal business entity in Australia (ABN or ACN).ApplicableFull
  • QHSE-MAN-001 §1Manual §1 Purpose identifies Westlink Logistics Pty Ltd (ABN 25 058 919 305) as the legal entity.
DSPF-C16.1-elig-02C16.1-elig-02Be financially solvent (not under administration or receivership).ApplicableNot Applicable
  • QHSE-MAN-001 §1Manual does not attest solvency; ASIC extracts held in DISP project reference folder attest financial position. External-to-WMS evidence.
Solvency attestation is carried in ASIC extracts (DISP project reference/) rather than in the controlled WMS document corpus. Add annual solvency attestation to Security Governance Register (SGR) or equivalent controlled document.
DSPF-C16.1-elig-03C16.1-elig-03Have a director/senior executive able to obtain an Australian Personnel Security Clearance and fulfil the CSO role.Not ApplicableNot Applicable
DSPF-C16.1-elig-04C16.1-elig-04Have a staff member able to obtain a clearance and fulfil the SO role (CSO and SO can be the same individual).Not ApplicableNot Applicable
DSPF-C16.1-elig-05C16.1-elig-05Establish and maintain security standards for the membership level (per Annex A).ApplicablePartial
  • QHSE-MAN-001 §11.3Manual §11.3 Defence and Security references DISP, ISM, PSPF, JOSCAR. Specific Annex A Entry Level standards established across four domains — see individual A16.1-entry-* rows below.
Aggregate requirement — coverage depends on per-domain Entry Level rows (A16.1-entry-gov-*, A16.1-entry-pers-*, A16.1-entry-phys-*, A16.1-entry-cyber-*) below.
DSPF-C16.1-app-01C16.1-app-01DISP applicants and members must have a centralised email (DISP@companydomain format), hosted in Australia, not web-based mail.ApplicableGapMedium
Operational practice exists (DISP@ mailbox on Australian-hosted tenancy) but not documented in controlled WMS documents. Add to TEC-POL-001 or Information Security Standard.
DSPF-C16.1-ongoing-01C16.1-ongoing-01DISP members must comply with contemporary Australian Government and Defence security legislation and policies (DSPF, PSPF, ISM).ApplicablePartial
  • QHSE-MAN-001 §11.3Manual §11.3 lists DISP, ISM, PSPF, JOSCAR as applicable; §6.1.3 Legal and Other Requirements includes Defence industry notifications in monitoring.
  • TEC-POL-001Information Security Policy aligns with ISM.
Compliance commitment present in Manual §11.3; specific mechanism for tracking DSPF / PSPF / ISM updates and flowing into WMS procedures not documented beyond the general legal-register process in §6.1.3.
DSPF-C16.1-ongoing-02C16.1-ongoing-02DISP members must report all security and cyber security incidents per Control 77.1 and Control 24.1.ApplicablePartial
  • QHSE-MAN-001 §10.1Manual §10.1 Incident Investigation addresses WHS/environmental incidents; §11.3 references DISP/ISM/PSPF. Defence security incident reporting path not documented in the WMS.
  • QHSE-PRO-001Hazard and Incident Reporting and Investigation Procedure — covers WHS and environmental, not security.
  • TEC-POL-001 §Policy CommitmentsInformation Security Policy — commits to security incident response.
  • TEC-PRO-001 §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections.
Security incident reporting pathway (internal reporting → SO → DISB via DISP Member Portal; timeframes per DSPF Control 77.1) not documented in a controlled WMS document. DEF-POL-001 likely covers this but is not in the WMS corpus.
DSPF-C16.1-ongoing-03C16.1-ongoing-03DISP members must complete an Annual Security Report (ASR).ApplicableFull
DSPF-C16.1-ongoing-04C16.1-ongoing-04DISP members must report to DISB all changes that might impact membership (eligibility changes, ownership/control changes, contact details, CSO/SO changes).ApplicablePartial
  • QHSE-MAN-001 §6.3Manual §6.3 Management of Change addresses internal change process; explicit DISB notification trigger for change in circumstance not documented in WMS. DISP reference folder holds Completing-change-in-circumstance guide.
Change-in-circumstance notification to DISB (14 business days for CSO/SO changes, otherwise as they occur) not documented in a controlled WMS document. Add trigger to Management of Change or Security Governance procedure.
DSPF-C16.1-ongoing-05C16.1-ongoing-05DISP members must engage with uplift, remediation and assurance activities.ApplicablePartial
  • QHSE-MAN-001 §9.3Manual §9.3 Internal Audit establishes auditing culture at WMS level; DISP-specific assurance (OSA, DDA, ASR) not separately documented as a recurring process.
Engagement with DISP assurance is operational but not tied to the WMS management review cycle or a controlled procedure.
DSPF-C16.1-ongoing-06C16.1-ongoing-06DISP members must implement recommendations within agreed timeframes.ApplicablePartial
  • QHSE-MAN-001 §10.2Manual §10.2 Nonconformity and Corrective Action addresses corrective-action tracking generally; DISP-specific recommendation tracking not separately documented.
Recommendation tracking path from DISB assurance → corrective action register not documented.
DSPF-C16.1-cso-01C16.1-cso-01CSO must be a director or senior executive able to implement policy and direct resources.ApplicableFull
  • QHSE-MAN-001 §5.2Manual §5.2 organisational structure; CSO is an SES-level role per CEO direct reports.
  • TEC-PRO-001 §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role.
DSPF-C16.1-cso-02C16.1-cso-02CSO must complete DISP Security Officer Training course as part of application and every three years thereafter.ApplicablePartial
  • QHSE-MAN-001 §7.2Manual §7.2 Competence covers training generally; DISP-specific training cadence (every three years) not documented as a trigger in WMS.
Three-yearly DISP SO training cycle for CSO not tracked in controlled WMS document. Add to training register and/or Security Governance procedure.
DSPF-C16.1-cso-03C16.1-cso-03CSO is accountable for membership obligations, risk oversight, reporting, protection of materials, ASR completion, and reporting changes to Defence.ApplicablePartial
  • QHSE-MAN-001 §5.1Manual §5.1 Leadership and Commitment assigns CEO accountability for WMS; CSO-specific accountabilities (distinct from CEO) not enumerated in Manual or WMS policy suite.
CSO accountabilities not captured in a controlled WMS document. disp_cso-so-responsibilities.md exists in DISP project but is not in WMS corpus.
DSPF-C16.1-so-01C16.1-so-01SO must obtain and maintain a Personnel Security Clearance commensurate with membership level.ApplicablePartial
  • QHSE-MAN-001 §7.2.1Manual §7.2.1 Restricted Operations covers licences and certifications generally; Personnel Security Clearances for SO not separately documented.
  • TEC-PRO-001 §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role.
Personnel Security Clearance maintenance for SO not documented in WMS corpus. Entry Level requires Baseline minimum (per Annex A).
DSPF-C16.1-so-02C16.1-so-02To sponsor/manage clearances, SO must hold minimum NV1 clearance (cannot sponsor clearances above own level).Not ApplicableNot Applicable
Entry Level SO cannot sponsor clearances (per Annex A Entry Level Personnel Security). Requirement applies when SO level upgrades to Level 1 or above.
DSPF-C16.1-so-03C16.1-so-03SO must complete DISP Security Officer Training and additional required training every three years.ApplicablePartial
  • QHSE-MAN-001 §7.2Manual §7.2 Competence covers training; DISP-specific SO training cadence not separately tracked.
SO training cycle not documented in WMS controlled document.
DSPF-C16.1-so-04C16.1-so-04SO is responsible for security policies/plans, protection of materials, security education, insider threat arrangements, incident/contact reporting, DSAP list maintenance, clearance management.ApplicablePartial
  • QHSE-MAN-001 §5.2Manual §5.2 organisational responsibilities; SO-specific responsibilities not enumerated in WMS.
SO duties distributed across multiple DISP-project documents (SGR, SPP, SRA) but not in WMS corpus.
DSPF-C16.1-so-05C16.1-so-05Changes to CSO or SO must be notified to Defence within 14 business days.ApplicablePartial
  • QHSE-MAN-001 §6.3Manual §6.3 Management of Change addresses internal changes; DISP-specific 14-business-day CSO/SO change notification not documented as a trigger.
Specific 14-day notification timeframe not tracked as a WMS trigger.
DSPF-A16.1-all-01A16.1-all-01All Industry Entities must meet and maintain requirements in Control 16.1.ApplicablePartial
  • QHSE-MAN-001 §11.3Manual §11.3 references DISP; aggregate requirement served by individual C16.1-* rows above.
Medium
Section 11.3 names DISP/ISM/PSPF/JOSCAR as references but aggregate satisfaction of Control 16.1 is not demonstrated; the individual A16.1 rows are mostly Partial.
DSPF-A16.1-all-02A16.1-all-02All Industry Entities must demonstrate they have met and can maintain Annex A requirements.ApplicablePartial
  • QHSE-MAN-001 §11.3Manual §11.3 references DISP; demonstration via ASR and DISP documentation held in DISP project folder.
Demonstration evidence mostly carried in DISP project folder (SGR, SPP, SRA, ASR records) rather than WMS corpus.
DSPF-A16.1-all-03A16.1-all-03All Industry Entities must ensure Security Governance domain matches or exceeds highest level across other domains.ApplicableFull
  • QHSE-MAN-001 §11.3Westlink holds Entry Level across all four domains — Governance ≥ max(other domains) satisfied.
DSPF-A16.1-all-04A16.1-all-04All Industry Entities must engage with audit and uplift activities conducted by Defence or nominated third party.ApplicablePartial
  • QHSE-MAN-001 §9.3Manual §9.3 Internal Audit establishes auditing discipline; DISP DDA/OSA engagement not documented as a commitment.
DISP audit engagement not documented in WMS controlled document beyond internal audit reference.
DSPF-A16.1-entry-gov-01A16.1-entry-gov-01Appoint and retain a CSO and at least one SO (can be same individual).ApplicableFull
  • QHSE-MAN-001 §5.2Manual §5.2 organisational structure identifies both CSO and SO positions; acknowledgement letters on file.
DSPF-A16.1-entry-gov-02A16.1-entry-gov-02Establish and maintain policies and procedures covering security governance arrangements including designated security positions and contacts.ApplicablePartial
  • QHSE-MAN-001 §5.2Manual §5.2 organisational structure covers roles generally; DISP-specific security position designations not documented in WMS. DISP SGR in DISP project folder.
Security governance arrangement coverage weak in WMS corpus. Primary evidence (SGR) is in DISP project. Bring DEF-POL-001 (Defence Security Policy) into WMS corpus to close.
DSPF-A16.1-entry-gov-03A16.1-entry-gov-03Establish and maintain policies and procedures covering risk management inclusive of security considerations and business security risk assessments.ApplicablePartial
  • QHSE-MAN-001 §6.1Manual §6.1 Risk-Based Approach covers WHS/quality/environmental risk; security-specific risk treatment not separately documented. DISP SRA exists in DISP project folder.
Security risk management (SRA) not integrated into controlled WMS corpus. QHSE-PRO-002 Risk Management Procedure (not yet in corpus) could consolidate.
DSPF-A16.1-entry-gov-04A16.1-entry-gov-04Establish and maintain policies and procedures covering security training arrangements for all personnel.ApplicableFull
DSPF-A16.1-entry-gov-05A16.1-entry-gov-05Establish and maintain a security incidents register covering all types (personnel, physical, information, cyber).ApplicableGapHigh
WMS has QHSE-PRO-001 (Hazard and Incident — WHS/environmental) and isCompliant incident module. Security-specific incident register covering personnel/physical/information/cyber not established as a controlled-document register. DISB reporting requires this register. Severity High — direct DISP audit-finding risk.
DSPF-A16.1-entry-gov-06A16.1-entry-gov-06Establish and maintain security reporting arrangements and register of contacts with foreign persons/entities.ApplicableGapHigh
Contact reporting obligations under DSPF Principle 45 apply; no controlled WMS document captures foreign contact reporting procedure or register. DISP DSAP list maintained informally in DISP project. Severity High.
DSPF-A16.1-entry-gov-07A16.1-entry-gov-07Establish and maintain a register of overseas travel with completed travel forms and travel briefing records for cleared personnel.Not ApplicableNot Applicable
DSPF-A16.1-entry-gov-08A16.1-entry-gov-08Establish and maintain insider threat identification, reporting and management arrangements.ApplicablePartial
  • GOV-POL-018Whistleblower Policy covers some insider reporting; DISP-specific insider threat programme not separately documented.
  • GOV-POL-006Workplace Behaviour Policy addresses psychosocial/behavioural concerns adjacent to insider threat indicators.
  • GOV-POL-016 §Organisational ContextSocial Media Usage Policy — commits to classified information risk.
Insider threat training (def-pre-002-insider-threat-training.pptx) exists in DISP project but not as a controlled WMS programme. Add explicit insider threat procedure to WMS.
DSPF-A16.1-entry-gov-09A16.1-entry-gov-09Engage in all annual DISP assurance activities (reporting, training, uplift programs).ApplicablePartial
  • QHSE-MAN-001 §9.3Manual §9.3 Internal Audit culture supports engagement; DISP assurance activities (ASR, training cadence, uplift) not separately tracked.
Annual DISP assurance cadence not tied to WMS management review or internal audit programme.
DSPF-A16.1-entry-gov-10A16.1-entry-gov-10Notify Defence of changes affecting membership (ownership, financial position, supply chain, criminal exposure).ApplicableGapMedium
Change-in-circumstance notification requirements not documented in any controlled WMS document. Similar to C16.1-ongoing-04 but here specifically covering ownership/financial/supply-chain/criminal-exposure triggers.
DSPF-A16.1-entry-gov-cso-so-01A16.1-entry-gov-cso-so-01CSO and SO must complete DISP Security Officer Training (initial and every three years).ApplicablePartial
  • QHSE-MAN-001 §7.2Manual §7.2 Competence covers training cadence generally; DISP SO training specifics not tracked as a controlled WMS training requirement.
Duplicate of C16.1-cso-02 and C16.1-so-03 — kept here for Annex A traceability.
DSPF-A16.1-entry-gov-cso-so-02A16.1-entry-gov-cso-so-02CSO and SO must demonstrate ability to manage security up to and including OFFICIAL/OFFICIAL: Sensitive level.ApplicablePartial
  • QHSE-MAN-001 §5.2Manual §5.2 organisational structure; specific OFFICIAL/OFFICIAL:Sensitive handling competency for CSO/SO not demonstrated via controlled WMS document.
Competency demonstration typically via DISP Security Officer Training completion + ASR; not in WMS corpus.
DSPF-A16.1-entry-pers-01A16.1-entry-pers-01Establish and maintain policies/procedures per AS 4811-2022 (Workforce Screening).ApplicableFull
  • HR-PRO-001Workforce Screening Procedure per AS 4811-2022 — identity verification (100-point formula), integrity and credentials screening, screening tiers, records management, right of review. Live in the WMS library 09/06/2026 (consolidates the DISP-originated DEF-POL-002, removed from SP 11/06/2026).
  • QHSE-MAN-001 §7.2Manual §7.2 Competence covers pre-employment verification (CV, references, interview, qualification verification, pre-employment medical, right to work).
  • TEC-POL-001 §Policy CommitmentsInformation Security Policy — commits to personnel security and clearances.
DSPF-A16.1-entry-pers-02A16.1-entry-pers-02Establish and maintain procedures for on-boarding, ongoing assessment, and separating personnel.ApplicablePartial
  • QHSE-MAN-001 §7.2Manual §7.2 covers pre-employment, induction, ongoing development; separation procedures not explicitly documented.
HR procedures for on-boarding/ongoing/separation not in WMS corpus as controlled documents.
DSPF-A16.1-entry-pers-03A16.1-entry-pers-03Establish and maintain a DSAP register (available to Defence on request).ApplicableGapHigh
DSAP (Designated Security Assessed Positions) register not established as a controlled WMS document. Personnel file content is in HR system; DISP-specific DSAP categorisation not applied. Severity High — DISB may request.
DSPF-A16.1-entry-pers-04A16.1-entry-pers-04Report engagement of foreign nationals and other disclosures of interest to Defence.ApplicableGapMedium
Foreign national engagement reporting procedure not documented in WMS corpus.
DSPF-A16.1-entry-pers-05A16.1-entry-pers-05Provide Defence a copy of workforce screening and management processes.ApplicablePartial
  • QHSE-MAN-001 §7.2Manual §7.2 covers workforce screening; HR-PRO-001 (live 09/06/2026) formalises the screening process for DISB provision.
Deliverable to DISB is typically the workforce screening procedure (HR-PRO-001, now live). A copy is not yet recorded as having been provided to Defence; coverage remains Partial pending evidence of provision.
DSPF-A16.1-entry-pers-cso-so-01A16.1-entry-pers-cso-so-01CSO and/or SO must be Australian citizens.ApplicableFull
  • QHSE-MAN-001 §5.2CSO/SO citizenship attested in disp-cso-acknowledgement-letter and disp-so-acknowledgement-letter (DISP project).
DSPF-A16.1-entry-pers-cso-so-02A16.1-entry-pers-cso-so-02CSO and/or SO must be able to obtain and maintain a minimum Baseline security clearance per AGSVA policy.ApplicablePartial
  • QHSE-MAN-001 §7.2.1Restricted Operations section addresses licences/certifications; AGSVA Baseline clearance not separately documented in WMS.
Clearance status carried in DISP project (CSO/SO acknowledgement letters); not in WMS controlled document.
DSPF-A16.1-entry-phys-01A16.1-entry-phys-01Establish and maintain policies/procedures covering physical security and access controls at each accredited facility.ApplicablePartial
  • QHSE-MAN-001 §7.1Manual §7.1 Resources mentions infrastructure; physical security + access controls at facility level not separately documented in WMS controlled documents.
Physical Security Policy not in WMS corpus. DISP SPP (Security Policies and Procedures) exists in DISP project.
DSPF-A16.1-entry-phys-02A16.1-entry-phys-02Provide facility ownership and leasing arrangement details to Defence as required.ApplicablePartial
  • QHSE-MAN-001 §2.3Manual §2.3 Sites and Operations identifies principal and regional sites; ownership/lease details not included in Manual.
Facility ownership/lease register not maintained in WMS controlled document.
DSPF-A16.1-entry-cyber-01A16.1-entry-cyber-01Meet or exceed ASD's Essential Eight (E8) at Maturity Level 2 across all of the Entity's ICT corporate systems used to correspond with Defence.ApplicablePartial
  • TEC-POL-001Information Security Policy references ISM/E8 alignment at policy level.
  • TEC-POL-002User Access Management Policy addresses E8 mitigation strategy 6 (Restrict admin privileges) and strategy 5 (User application hardening — partial).
E8 ML2 maturity posture documented in DISP project (e8_westlink-current-posture.md, e8_test_plan_ml2.md); DISP Cyber Security Questionnaire evidence not in WMS corpus. E8 vertical slice (deferred to ~22 Dec 2026 pre-ASR window per S1 plan) will provide row-level coverage.
DSPF-A16.1-entry-cyber-02A16.1-entry-cyber-02Entities complying with international standards (ISO/IEC 27001:2022, NIST SP 800-171, Def Stan 5-138) can use documentation to demonstrate partial compliance, but these are not equivalent to E8 — full E8 mitigation strategies must still be demonstrated in the DISP Cyber Security Questionnaire.Not ApplicableNot Applicable
Westlink does not currently hold ISO/IEC 27001, NIST SP 800-171, or Def Stan 5-138 certification. Requirement is a clarification, not a standalone obligation — marking Not Applicable. If Westlink later obtains ISO 27001, revisit.
DSPF-A16.1-L1-gov-01A16.1-L1-gov-01Level 1 Security Governance: maintain register of all personnel sponsored for a security clearance.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-gov-02A16.1-L1-gov-02Level 1 Security Governance: complete all annual assurance activities.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-gov-03A16.1-L1-gov-03Level 1 Security Governance: SO must maintain NV1 clearance and demonstrate ability to manage up to PROTECTED level.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-pers-01A16.1-L1-pers-01Level 1 Personnel Security: SO must actively monitor and manage ongoing suitability of sponsored security cleared personnel.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-pers-02A16.1-L1-pers-02Level 1 Personnel Security: SO eligible to sponsor clearances up to and including Baseline level.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-phys-01A16.1-L1-phys-01Level 1 Physical Security: at least one facility certified and accredited per DSPF Principle 72 / Control 72.1 to receive, handle, store and destroy PROTECTED information and material per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L1-cyber-01A16.1-L1-cyber-01Level 1 Information and Cyber Security: at least one system certified and accredited per DSPF Principle 23 / Control 23.1 to handle PROTECTED information per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L2-gov-01A16.1-L2-gov-01Level 2 Security Governance: SO must demonstrate ability to manage up to SECRET level.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L2-phys-01A16.1-L2-phys-01Level 2 Physical Security: facility accredited to receive, handle, store and destroy SECRET information per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L2-cyber-01A16.1-L2-cyber-01Level 2 Information and Cyber Security: network accredited per DSPF Principle 23 / Control 23.1 to handle SECRET information per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L3-gov-01A16.1-L3-gov-01Level 3 Security Governance: documented SES Band 3 / ADF equivalent endorsement before obtaining PV clearance, certifying SCIF, or accrediting TOP SECRET network.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L3-phys-01A16.1-L3-phys-01Level 3 Physical Security: facility certified and accredited for TOP SECRET per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
DSPF-A16.1-L3-cyber-01A16.1-L3-cyber-01Level 3 Information and Cyber Security: network certified and accredited for TOP SECRET per ISM/DSPF.Not ApplicableNot Applicable
Westlink is an Entry Level DISP member (CSO acknowledgement letter on file). Level 1/2/3 Annex A requirements are not applicable unless the membership level is upgraded — document here for future upgrade scoping.
Source document

DSPF Principle 16 — Defence Industry Security Program (Control 16.1 + Annex A DISP Membership Level Requirements)

60 normative shall-statements extracted from DSPF Principle 16 / Control 16.1 / Annex A (source: ~/projects/DISP/disp_dspf-interim-public.md). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.

Coverage summary

CoverageCount
✅ Full8
🟡 Partial27
🟠 Ref-only0
🔴 Gap6
— N/A19

Gap severity distribution

SeverityCount
🔴 Critical0
🟠 High3
🟡 Medium4
🟢 Low0

Requirements

Clause A16

IDCoverageEvidenceGapNotes
DSPF-A16.1-all-01🟡 PartialQHSE-MAN-001 §‘11.3’🟡 MediumSection 11.3 names DISP/ISM/PSPF/JOSCAR as references but aggregate satisfaction of Control 16.1 is not demonstrated; the individual A16.1 rows are mostly Partial.
DSPF-A16.1-all-02🟡 PartialQHSE-MAN-001 §‘11.3’Demonstration evidence mostly carried in DISP project folder (SGR, SPP, SRA, ASR records) rather than WMS corpus.
DSPF-A16.1-all-03✅ FullQHSE-MAN-001 §‘11.3’
DSPF-A16.1-all-04🟡 PartialQHSE-MAN-001 §‘9.3’DISP audit engagement not documented in WMS controlled document beyond internal audit reference.
DSPF-A16.1-entry-gov-01✅ FullQHSE-MAN-001 §‘5.2’
DSPF-A16.1-entry-gov-02🟡 PartialQHSE-MAN-001 §‘5.2’Security governance arrangement coverage weak in WMS corpus. Primary evidence (SGR) is in DISP project. Bring DEF-POL-001 (Defence Security Policy) into WMS corpus to close.
DSPF-A16.1-entry-gov-03🟡 PartialQHSE-MAN-001 §‘6.1’Security risk management (SRA) not integrated into controlled WMS corpus. QHSE-PRO-002 Risk Management Procedure (not yet in corpus) could consolidate.
DSPF-A16.1-entry-gov-04✅ FullQHSE-MAN-001 §‘7.2’
QHSE-MAN-001 §‘7.3’
[GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments)
TEC-POL-001 §Responsibilities
TEC-PRO-001 §‘Responsibilities’
DSPF-A16.1-entry-gov-05🔴 Gap🟠 HighWMS has QHSE-PRO-001 (Hazard and Incident — WHS/environmental) and isCompliant incident module. Security-specific incident register covering personnel/physical/information/cyber not established as a controlled-document register. DISB reporting requires this register. Severity High — direct DISP audit-finding risk.
DSPF-A16.1-entry-gov-06🔴 Gap🟠 HighContact reporting obligations under DSPF Principle 45 apply; no controlled WMS document captures foreign contact reporting procedure or register. DISP DSAP list maintained informally in DISP project. Severity High.
DSPF-A16.1-entry-gov-07— N/AN/A — Overseas Travel Register and pre/post-travel briefing records for cleared personnel are maintained in the DISP program (Overseas Travel Register SGR C3, AB644 forms, DISO G9; DSPF Control 16.1 para 71(f)) — not a WMS-library obligation.
DSPF-A16.1-entry-gov-08🟡 PartialGOV-POL-018
GOV-POL-006
[GOV-POL-016 §Organisational Context](/wms/GOV-POL-016#sOrganisational Context)
Insider threat training (def-pre-002-insider-threat-training.pptx) exists in DISP project but not as a controlled WMS programme. Add explicit insider threat procedure to WMS.
DSPF-A16.1-entry-gov-09🟡 PartialQHSE-MAN-001 §‘9.3’Annual DISP assurance cadence not tied to WMS management review or internal audit programme.
DSPF-A16.1-entry-gov-10🔴 Gap🟡 MediumChange-in-circumstance notification requirements not documented in any controlled WMS document. Similar to C16.1-ongoing-04 but here specifically covering ownership/financial/supply-chain/criminal-exposure triggers.
DSPF-A16.1-entry-gov-cso-so-01🟡 PartialQHSE-MAN-001 §‘7.2’Duplicate of C16.1-cso-02 and C16.1-so-03 — kept here for Annex A traceability.
DSPF-A16.1-entry-gov-cso-so-02🟡 PartialQHSE-MAN-001 §‘5.2’Competency demonstration typically via DISP Security Officer Training completion + ASR; not in WMS corpus.
DSPF-A16.1-entry-pers-01✅ FullHR-PRO-001
QHSE-MAN-001 §‘7.2’
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
DSPF-A16.1-entry-pers-02🟡 PartialQHSE-MAN-001 §‘7.2’HR procedures for on-boarding/ongoing/separation not in WMS corpus as controlled documents.
DSPF-A16.1-entry-pers-03🔴 Gap🟠 HighDSAP (Designated Security Assessed Positions) register not established as a controlled WMS document. Personnel file content is in HR system; DISP-specific DSAP categorisation not applied. Severity High — DISB may request.
DSPF-A16.1-entry-pers-04🔴 Gap🟡 MediumForeign national engagement reporting procedure not documented in WMS corpus.
DSPF-A16.1-entry-pers-05🟡 PartialQHSE-MAN-001 §‘7.2’Deliverable to DISB is typically the workforce screening procedure (HR-PRO-001, now live). A copy is not yet recorded as having been provided to Defence; coverage remains Partial pending evidence of provision.
DSPF-A16.1-entry-pers-cso-so-01✅ FullQHSE-MAN-001 §‘5.2’
DSPF-A16.1-entry-pers-cso-so-02🟡 PartialQHSE-MAN-001 §7.2.1Clearance status carried in DISP project (CSO/SO acknowledgement letters); not in WMS controlled document.
DSPF-A16.1-entry-phys-01🟡 PartialQHSE-MAN-001 §‘7.1’Physical Security Policy not in WMS corpus. DISP SPP (Security Policies and Procedures) exists in DISP project.
DSPF-A16.1-entry-phys-02🟡 PartialQHSE-MAN-001 §‘2.3’Facility ownership/lease register not maintained in WMS controlled document.
DSPF-A16.1-entry-cyber-01🟡 PartialTEC-POL-001
TEC-POL-002
E8 ML2 maturity posture documented in DISP project (e8_westlink-current-posture.md, e8_test_plan_ml2.md); DISP Cyber Security Questionnaire evidence not in WMS corpus. E8 vertical slice (deferred to ~22 Dec 2026 pre-ASR window per S1 plan) will provide row-level coverage.
DSPF-A16.1-entry-cyber-02— N/AN/A
DSPF-A16.1-L1-gov-01— N/AN/A
DSPF-A16.1-L1-gov-02— N/AN/A
DSPF-A16.1-L1-gov-03— N/AN/A
DSPF-A16.1-L1-pers-01— N/A[GOV-POL-016 §Organisational Context](/wms/GOV-POL-016#sOrganisational Context)N/A
DSPF-A16.1-L1-pers-02— N/AN/A
DSPF-A16.1-L1-phys-01— N/AN/A
DSPF-A16.1-L1-cyber-01— N/AN/A
DSPF-A16.1-L2-gov-01— N/AN/A
DSPF-A16.1-L2-phys-01— N/AN/A
DSPF-A16.1-L2-cyber-01— N/AN/A
DSPF-A16.1-L3-gov-01— N/AN/A
DSPF-A16.1-L3-phys-01— N/AN/A
DSPF-A16.1-L3-cyber-01— N/AN/A

Clause C16

IDCoverageEvidenceGapNotes
DSPF-C16.1-elig-01✅ FullQHSE-MAN-001 §‘1’
DSPF-C16.1-elig-02— N/AQHSE-MAN-001 §‘1’Solvency attestation is carried in ASIC extracts (DISP project reference/) rather than in the controlled WMS document corpus. Add annual solvency attestation to Security Governance Register (SGR) or equivalent controlled document.
DSPF-C16.1-elig-03— N/AN/A — Personnel clearance eligibility is managed in the DISP program (DSAP register + Baseline clearances for the CSO and 2 Security Officers + AGSVA myClearance verification) — not a WMS-library obligation.
DSPF-C16.1-elig-04— N/AN/A — Personnel clearance eligibility is managed in the DISP program (DSAP register + Baseline clearances + AGSVA myClearance verification) — not a WMS-library obligation.
DSPF-C16.1-elig-05🟡 PartialQHSE-MAN-001 §‘11.3’Aggregate requirement — coverage depends on per-domain Entry Level rows (A16.1-entry-gov-, A16.1-entry-pers-, A16.1-entry-phys-, A16.1-entry-cyber-) below.
DSPF-C16.1-app-01🔴 Gap🟡 MediumOperational practice exists (DISP@ mailbox on Australian-hosted tenancy) but not documented in controlled WMS documents. Add to TEC-POL-001 or Information Security Standard.
DSPF-C16.1-ongoing-01🟡 PartialQHSE-MAN-001 §‘11.3’
TEC-POL-001
Compliance commitment present in Manual §11.3; specific mechanism for tracking DSPF / PSPF / ISM updates and flowing into WMS procedures not documented beyond the general legal-register process in §6.1.3.
DSPF-C16.1-ongoing-02🟡 PartialQHSE-MAN-001 §‘10.1’
QHSE-PRO-001
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)
Security incident reporting pathway (internal reporting → SO → DISB via DISP Member Portal; timeframes per DSPF Control 77.1) not documented in a controlled WMS document. DEF-POL-001 likely covers this but is not in the WMS corpus.
DSPF-C16.1-ongoing-03✅ FullQHSE-MAN-001 §‘11.3’
DSPF-C16.1-ongoing-04🟡 PartialQHSE-MAN-001 §‘6.3’Change-in-circumstance notification to DISB (14 business days for CSO/SO changes, otherwise as they occur) not documented in a controlled WMS document. Add trigger to Management of Change or Security Governance procedure.
DSPF-C16.1-ongoing-05🟡 PartialQHSE-MAN-001 §‘9.3’Engagement with DISP assurance is operational but not tied to the WMS management review cycle or a controlled procedure.
DSPF-C16.1-ongoing-06🟡 PartialQHSE-MAN-001 §‘10.2’Recommendation tracking path from DISB assurance → corrective action register not documented.
DSPF-C16.1-cso-01✅ FullQHSE-MAN-001 §‘5.2’
TEC-PRO-001 §‘Responsibilities’
DSPF-C16.1-cso-02🟡 PartialQHSE-MAN-001 §‘7.2’Three-yearly DISP SO training cycle for CSO not tracked in controlled WMS document. Add to training register and/or Security Governance procedure.
DSPF-C16.1-cso-03🟡 PartialQHSE-MAN-001 §‘5.1’CSO accountabilities not captured in a controlled WMS document. disp_cso-so-responsibilities.md exists in DISP project but is not in WMS corpus.
DSPF-C16.1-so-01🟡 PartialQHSE-MAN-001 §7.2.1
TEC-PRO-001 §‘Responsibilities’
Personnel Security Clearance maintenance for SO not documented in WMS corpus. Entry Level requires Baseline minimum (per Annex A).
DSPF-C16.1-so-02— N/AN/A
DSPF-C16.1-so-03🟡 PartialQHSE-MAN-001 §‘7.2’SO training cycle not documented in WMS controlled document.
DSPF-C16.1-so-04🟡 PartialQHSE-MAN-001 §‘5.2’SO duties distributed across multiple DISP-project documents (SGR, SPP, SRA) but not in WMS corpus.
DSPF-C16.1-so-05🟡 PartialQHSE-MAN-001 §‘6.3’Specific 14-day notification timeframe not tracked as a WMS trigger.

Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.