CybersecurityRegulation

RFFR ISM SoA

Right Fit for Risk Information Security Manual Statement of Applicability

The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.

Overview

The RFFR Statement of Applicability (SoA) serves as a key governance document within the Australian Government’s Right Fit for Risk cyber security accreditation program. Its purpose is to demonstrate how an organization applies relevant security controls, identifies exclusions, and justifies risk-based decisions in alignment with accreditation standards. The SoA is primarily intended for service providers seeking accreditation to deliver ICT services to government agencies, ensuring transparency and accountability in their cyber security posture.

This framework applies across sectors that interact with government systems, including ICT vendors, managed service providers, and organizations handling sensitive or official information. By requiring organizations to map controls against the Information Security Manual (ISM) and other ASD guidance, the SoA ensures consistency, comparability, and confidence in cyber risk management. Ultimately, it provides government agencies with assurance that accredited providers have implemented appropriate safeguards, while also enabling providers to clearly communicate their compliance and risk management approach.

Related in Cybersecurity

CybersecurityStandard

PPG 511 — Prudential Practice Guide 511 - Remuneration

Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.

Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009

View details
CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australian • v2 July 2018

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call