TAS-PSPF — Tasmanian Protective Security Policy Framework

Tasmania's protective security arrangements for government information, covering governance, information, personnel and physical security.

Tasmanian Government, through the Department of Premier and Cabinet.

What it is

Tasmania's protective security arrangements set the requirements for how Tasmanian Government agencies protect their information, people and assets. The framework follows the familiar protective security structure used across Australian jurisdictions — governance, information, personnel and physical security — and is administered through the Department of Premier and Cabinet.

In substance it covers what you would expect: identity and access management, with authorised personnel screened before access; resource management protecting business records and controlling physical access to information; and controls over the use of ICT. The Essential Eight serves as the common technical reference, as it does across every Australian jurisdiction.

A note on sourcing. Tasmania publishes less of its detailed security policy material publicly than New South Wales, Queensland or Victoria do. Much of the operational detail sits in agency-facing guidance rather than on a public website. That means anyone — including us — writing about Tasmanian requirements in general terms is working from a thinner published base than for the larger jurisdictions.

The practical consequence: for a supplier, the binding document is your contract, and the agency is the authority on what it requires. Do not build a programme against a general description of the framework, including this one.

This is not a certification scheme. There is no Tasmanian protective security certificate.

Who it's for

Tasmanian Government agencies

For whom the protective security requirements are mandatory policy administered through the Department of Premier and Cabinet.

Suppliers and service providers to Tasmanian Government

The larger group in practice. Obligations reach you through your contract, and the contract is where the specific requirements live.

Organisations handling Tasmanian Government information

Where personnel screening, access control and records handling obligations attach to the information rather than to the organisation generally.

What triggers the work

Almost always a contract clause and an assurance request from an agency client.

Why implement it

  • For agencies it is mandatory policy, covering the full protective security span rather than cyber alone.
  • For suppliers it protects the contract. Where security obligations flow down, failing to evidence them puts the engagement at risk — the same commercial dynamic as every other jurisdiction.
  • Personnel and physical security are in scope. A purely technical programme will not satisfy a framework built on four domains, and this is where suppliers most often fall short.
  • The work is portable. Because the structure mirrors the Commonwealth PSPF and other state frameworks, controls built for Tasmania largely serve elsewhere.
  • ISO 27001 does much of it. A functioning ISO 27001 management system covers a substantial share of the governance and information expectations.

How implementation works

1. Establish what actually binds you

For suppliers this is the single most important step, and it is a contract-reading exercise before it is a security exercise. Detailed Tasmanian requirements are not as publicly published as those of larger jurisdictions, so the specific obligations, artefacts and reporting formats come from the agency and the contract.

2. Assess across the security domains

Governance, information, personnel and physical security — the familiar protective security structure.

3. Build proportionate controls

Including identity and access management, personnel screening appropriate to the information handled, and resource and records management.

4. Address the technical baseline

The Essential Eight is the common technical reference across Australian jurisdictions and is the sensible baseline in the absence of a jurisdiction-specific alternative.

5. Evidence and report

In the form the agency requires, which is a question to ask early rather than discover late.

How Soveriq helps

Soveriq's approach here starts with a question rather than a framework: what does your contract actually require, and who at the agency confirms it. For Tasmanian engagements that step does more to control cost than anything else, because building against an assumed standard is how suppliers spend money on obligations they never had.

From there we assess across the protective security domains, build proportionate controls, and prepare evidence in the form the agency expects.

Where ISO 27001 is held, we map it across — it is usually the strongest starting position a supplier can bring.

Being straight about the limits. Tasmanian requirements are less publicly documented than those of NSW, Queensland or Victoria. We will tell you where we are working from published material and where we need the agency to confirm the requirement, rather than presenting assumption as fact.

On internal review. Where Soveriq has built your security framework, we provide readiness validation labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What the engagement looks like

  • Module 01 — Gap analysis against your contract obligations and the applicable Tasmanian requirements, starting with establishing what those are.
  • Module 02 — Build. Governance, information, personnel and physical security controls proportionate to what you hold.
  • Module 03 — Internal review, subject to the impartiality position above.
  • Module 04 — Representation where an agency client engages directly.
  • Module 05 — Continuous compliance.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Where do I find the actual requirements?

Detailed Tasmanian Government security policy material is largely published to agencies rather than publicly. For a supplier, the practical answer is your contract and the agency contact named in it. For an agency, it is your own policy library and the responsible area within the Department of Premier and Cabinet.

Is there a TAS-PSPF certificate?

No. Like the Commonwealth PSPF and every other Australian jurisdiction's protective security arrangements, this operates on self-assessment and internal assurance rather than third-party certification.

We hold ISO 27001. Does that cover us?

It does a large share of the work and is usually the strongest position a supplier can be in. It will not automatically satisfy jurisdiction-specific artefacts or reporting formats, but the underlying governance, risk and control expectations overlap heavily.

Is Tasmania's framework the same as the Commonwealth PSPF?

They share a lineage and a structure — governance, information, personnel and physical security — but they are separate instruments with separate governance. Do not assume a Commonwealth PSPF position transfers unexamined.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope