SACSF — South Australian Cyber Security Framework

South Australia's Cabinet-approved cyber security framework, structured around four principles and four risk-based tiers, with annual attestation.

Government of South Australia. Cabinet-approved and forming part of the South Australian Protective Security Policy Framework, with resources published through Security SA and the Department of Treasury and Finance.

What it is

The South Australian Cyber Security Framework is the cyber security policy framework for the South Australian Government. It is Cabinet-approved and forms one part of the overarching South Australian Protective Security Policy Framework. It replaced the earlier Information Security Management Framework.

The SACSF is structured around four principles — governance, information security, personnel security and physical security — with a set of policy statements underpinning them. Agencies must address each policy statement during implementation.

What distinguishes it is the tiered model. Requirements are tiered across four levels, each adding more stringent controls commensurate with risk exposure. A tier one agency addresses the tier one expectations; a tier four agency is expected to consider the expectations of all four tiers. This is deliberately flexible — the framework is risk-based and does not treat every agency identically.

Accountability is explicit. Under Premier and Cabinet Circular 30, the agency Chief Executive, or equivalent accountable authority, is responsible for ensuring the agency meets its obligations.

The framework states plainly that it is not certifiable. It is not possible for agencies or associated entities, including vendors, to gain official certification simply by meeting SACSF requirements. Anyone offering you SACSF certification is selling something that does not exist.

Who it's for

South Australian public sector agencies

As defined in section 3(1) of the Public Sector Act 2009, along with any other person or organisation generally subject to the discretion of a Minister or the Crown.

Suppliers and service providers to SA Government

The framework requires cyber security requirements to be included in all agreements with suppliers, and agencies to have processes for assessing and managing the risks suppliers introduce. That makes supplier obligations contractual and specific.

Agencies transitioning between framework versions

Agencies may still need to refer to the previous version of the SACSF for transition and attestation purposes, which is worth checking before assuming which version binds you.

What triggers the work

The annual attestation cycle for agencies, or a supplier agreement clause for vendors.

Why implement it

  • For agencies it is mandatory, Cabinet-approved, with the Chief Executive personally accountable under PC030.
  • The tiered model is proportionate. A small agency is not held to the controls expected of a tier four body, which makes the framework more workable than a flat mandate.
  • For suppliers it protects the contract. Because the framework requires cyber security terms in all supplier agreements, the obligation reaches vendors directly and specifically.
  • It covers more than cyber. Personnel and physical security sit inside the framework, so implementation addresses risks a purely technical programme would miss.
  • It aligns with what you may already hold. The governance and information security principles map closely onto ISO 27001, and the technical baseline runs through the Essential Eight.

How implementation works

Tier selection first, because it determines how deep the requirements go.

1. Determine your tier

Requirements are tiered across four levels, each adding more stringent controls commensurate with risk exposure. A tier one agency addresses tier one expectations; a tier four agency considers the expectations of all four tiers. Getting the tier right is the main scoping decision.

2. Assess against the policy statements

Each policy statement must be addressed as part of implementation, at the expectations applying to your tier.

3. Build across the four principles

Governance including accountability, strategic planning, assurance and review. Information security. Personnel suitability, screening and training. Physical security for people, information and assets.

4. Address supplier risk

Cyber security requirements must be included in all agreements with suppliers, with processes for assessing and managing the risks suppliers introduce.

5. Obtain assurance

The framework includes an audit and assurance policy statement, and agencies may still need to refer to earlier versions of the SACSF for transition and attestation purposes.

6. Attest annually

Agencies attest annually on maturity and alignment, including reporting against the Essential Eight.

How Soveriq helps

Soveriq starts with tier determination, because a misjudged tier is either an unnecessary programme or an indefensible attestation. We then assess against the policy statements at the applicable tier expectations, build across all four principles, and prepare the annual attestation position.

For suppliers, we work from your agreement: the SACSF requires cyber security requirements in all supplier agreements, so your obligations are specific and contractual rather than general.

Being direct about certification. The framework states plainly that meeting SACSF requirements does not confer official certification, on agencies or on vendors. We say the same, and we would rather you hear it from us than pay someone for a certificate that carries no standing.

On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What the engagement looks like

  • Module 01 — Gap analysis against the policy statements at your tier, or against the subset flowing to you by contract.
  • Module 02 — Build. Governance, information, personnel and physical security controls at the tier expectations that apply.
  • Module 03 — Internal review ahead of attestation, subject to the impartiality position above.
  • Module 04 — Representation where an agency client engages directly.
  • Module 05 — Continuous compliance across the annual attestation cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can we be certified against the SACSF?

No, and the framework says so explicitly: it is not possible for agencies or associated entities, including vendors, to gain official certification simply by meeting SACSF requirements. Any provider offering you SACSF certification is selling something that does not exist. Be wary of it.

What tier are we?

Tier selection is driven by risk exposure. A tier one agency addresses the tier one expectations; a tier four agency is expected to consider the expectations of all four tiers. Getting this right matters, because it determines the depth of controls you are held to.

Who is accountable?

Under Premier and Cabinet Circular 30, the agency Chief Executive — or the equivalent accountable authority responsible for the agency's operations — is responsible for ensuring the agency meets its obligations. This is not a matter that can be fully delegated to the security team.

How does the SACSF relate to the SAPSF?

The SACSF is Cabinet-approved and forms one part of the overarching South Australian Protective Security Policy Framework. The SAPSF covers personnel, physical and information security more broadly; the SACSF is the cyber component.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope