Government security standards, used when the agency is actually subject to them.
F Creative Studio 360 helps public bodies in any country measure controls against the standard their own government requires. NIST SP 800-53 and ISO/IEC 27001 are common baselines. A national manual is used only when that body is subject to it.
A public body inherits a named baseline.
Agencies do not get to invent the control set. In Australia, non-corporate Commonwealth entities work to the Protective Security Policy Framework and the Information Security Manual, including the Essential Eight where that framework requires it.
A city, a state body or a government in another country may be measured against NIST SP 800-53 or ISO/IEC 27001. F Creative Studio 360 assesses against the baseline you are actually required to use. We do not certify the agency.
- Maturity is the lowest strategy
- On the Essential Eight, the reported level is the level held across the strategies in scope, not the best one.
- The PSPF is not a worldwide law
- It is used for Australian government entities that are subject to it. It is not applied to a private company that merely sells to government, unless the contract says so.
- Evidence, not a slogan
- A control is described as it operates, with the owner and the gap.
- Implementation is optional
- The assessment can stop at the findings. Building the control is a separate, written piece of work.
What the assessment reads
The eight Essential Eight strategies are the technical core when that model is the one being measured.
- Patch applications and operating systems
- What is in the fleet, and what is outside the window the baseline expects.
- Accounts and applications
- Multi-factor authentication, admin privileges, application control and macro restrictions.
- Hardening and backups
- User-application hardening, and backups that can be restored.
- The wider framework
- ISM or PSPF governance around those strategies, or the equivalent baseline in another country.
How an engagement runs
The same shape works for a national agency or a local authority. The baseline changes with the mandate.
- 1
Name the mandate
Which body, which standard, and whether a contract has imported a government baseline.
- 2
Read the controls
Configuration and ownership, not a self-scored spreadsheet alone.
- 3
Score only what was seen
A strategy with no evidence is not given a level.
- 4
Hand back the gaps
In the order the baseline itself forces, where the lowest strategy sets the result.
What you receive
- A control review against the named government baseline.
- An Essential Eight view when that model is in scope, with the level held across the strategies.
- Owners for each gap.
- No certificate, and no claim that an auditor has accepted the result.
What this is not
This is not a penetration test. Authorised testing is a separate engagement. It is also not legal advice on whether a body is inside the PSPF.
Common questions
Can a company outside Australia use this?+
Yes. If your government or your contract names a baseline, we assess against that baseline. The ISM, the PSPF and the Essential Eight are used when they are the standard that applies, including for organisations anywhere that have chosen the Essential Eight as the model to be measured against.
Will you certify our maturity level?+
No. We record what was observed. A certification, where one exists, is issued by someone else.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Measure the baseline you are actually held to.
F Creative Studio 360 will look at the mandate and the systems, then say what the assessment includes.
