South Australia's Cabinet-approved cyber security framework, structured around four principles and four risk-based tiers, with annual attestation.
The South Australian Cyber Security Framework is the cyber security policy framework for the South Australian Government. It is Cabinet-approved and forms one part of the overarching South Australian Protective Security Policy Framework. It replaced the earlier Information Security Management Framework.
The SACSF is structured around four principles — governance, information security, personnel security and physical security — with a set of policy statements underpinning them. Agencies must address each policy statement during implementation.
What distinguishes it is the tiered model. Requirements are tiered across four levels, each adding more stringent controls commensurate with risk exposure. A tier one agency addresses the tier one expectations; a tier four agency is expected to consider the expectations of all four tiers. This is deliberately flexible — the framework is risk-based and does not treat every agency identically.
Accountability is explicit. Under Premier and Cabinet Circular 30, the agency Chief Executive, or equivalent accountable authority, is responsible for ensuring the agency meets its obligations.
The framework states plainly that it is not certifiable. It is not possible for agencies or associated entities, including vendors, to gain official certification simply by meeting SACSF requirements. Anyone offering you SACSF certification is selling something that does not exist.
As defined in section 3(1) of the Public Sector Act 2009, along with any other person or organisation generally subject to the discretion of a Minister or the Crown.
The framework requires cyber security requirements to be included in all agreements with suppliers, and agencies to have processes for assessing and managing the risks suppliers introduce. That makes supplier obligations contractual and specific.
Agencies may still need to refer to the previous version of the SACSF for transition and attestation purposes, which is worth checking before assuming which version binds you.
The annual attestation cycle for agencies, or a supplier agreement clause for vendors.
Tier selection first, because it determines how deep the requirements go.
Requirements are tiered across four levels, each adding more stringent controls commensurate with risk exposure. A tier one agency addresses tier one expectations; a tier four agency considers the expectations of all four tiers. Getting the tier right is the main scoping decision.
Each policy statement must be addressed as part of implementation, at the expectations applying to your tier.
Governance including accountability, strategic planning, assurance and review. Information security. Personnel suitability, screening and training. Physical security for people, information and assets.
Cyber security requirements must be included in all agreements with suppliers, with processes for assessing and managing the risks suppliers introduce.
The framework includes an audit and assurance policy statement, and agencies may still need to refer to earlier versions of the SACSF for transition and attestation purposes.
Agencies attest annually on maturity and alignment, including reporting against the Essential Eight.
Soveriq starts with tier determination, because a misjudged tier is either an unnecessary programme or an indefensible attestation. We then assess against the policy statements at the applicable tier expectations, build across all four principles, and prepare the annual attestation position.
For suppliers, we work from your agreement: the SACSF requires cyber security requirements in all supplier agreements, so your obligations are specific and contractual rather than general.
Being direct about certification. The framework states plainly that meeting SACSF requirements does not confer official certification, on agencies or on vendors. We say the same, and we would rather you hear it from us than pay someone for a certificate that carries no standing.
On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No, and the framework says so explicitly: it is not possible for agencies or associated entities, including vendors, to gain official certification simply by meeting SACSF requirements. Any provider offering you SACSF certification is selling something that does not exist. Be wary of it.
Tier selection is driven by risk exposure. A tier one agency addresses the tier one expectations; a tier four agency is expected to consider the expectations of all four tiers. Getting this right matters, because it determines the depth of controls you are held to.
Under Premier and Cabinet Circular 30, the agency Chief Executive — or the equivalent accountable authority responsible for the agency's operations — is responsible for ensuring the agency meets its obligations. This is not a matter that can be fully delegated to the security team.
The SACSF is Cabinet-approved and forms one part of the overarching South Australian Protective Security Policy Framework. The SAPSF covers personnel, physical and information security more broadly; the SACSF is the cyber component.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope