WA Government Cyber Security Policy

Western Australia's baseline cyber security policy for government entities, built on the Essential Eight, the Further Five, NIST CSF and the ASD ISM.

Government of Western Australia, through the Office of Digital Government within the Department of the Premier and Cabinet.

What it is

The WA Government Cyber Security Policy prescribes the baseline for cyber security capabilities and practices across the Western Australian Government. The current published version dates from 2024.

What distinguishes it from other state policies is how explicitly it borrows from established frameworks rather than inventing its own control set. It mandates the Essential Eight at Maturity Level One as a minimum, and integrates that with the NIST Cybersecurity Framework, the ASD Information Security Manual, and ASD's Further Five mitigation strategies — additional strategies beyond the eight.

Maturity Level One as the mandated floor is worth understanding correctly. It is a baseline, not a target. An entity holding significant personal information or operating critical services should be able to explain why Level One is where it stopped, because the policy is risk-based and the floor is a starting point rather than an answer.

Compliance is demonstrated through annual reporting rather than certification. There is no WA Cyber Security Policy certificate.

Who it's for

WA Government entities

Public sector entities to which the policy applies, for whom it sets the mandatory baseline and the annual reporting obligation.

Suppliers and service providers to WA Government

Where cyber security obligations flow down through contracts. As with every state framework, the binding document for a supplier is the contract rather than the policy itself.

Entities already working to NIST CSF or the ASD ISM

Because the policy integrates both, existing work under either maps across substantially rather than needing to be redone.

What triggers the work

The annual reporting cycle for entities, or a contract clause and assurance request for suppliers.

Why implement it

  • For in-scope entities it is the mandated baseline, with annual reporting attached.
  • The frameworks it borrows are portable. Because it builds on the Essential Eight, NIST CSF and the ISM rather than a bespoke control set, work done here transfers to other obligations.
  • The Further Five close real gaps. The additional strategies address attack paths the eight do not, and they are frequently overlooked precisely because they sit outside the familiar framing.
  • For suppliers it protects the contract, where flow-down obligations apply.
  • Maturity Level One is achievable. A lower mandated floor than several other jurisdictions makes the baseline realistic, which is a genuine advantage provided it is treated as a floor.

How implementation works

The policy is a baseline, so the first question is where you sit against it and the second is whether the baseline is sufficient for your risk.

1. Confirm scope and applicability

Establish which entities and systems the policy covers in your context, and where obligations flow to suppliers.

2. Assess against the baseline

Including current Essential Eight maturity, assessed against evidence rather than self-assertion. Maturity Level One is a floor, not a target for an entity holding significant sensitive information.

3. Address the Further Five

The additional mitigation strategies the policy incorporates alongside the eight. These are frequently overlooked because they sit outside the more familiar Essential Eight framing.

4. Align with NIST CSF and the ISM

The policy draws on both. Where an entity already works to the NIST Cybersecurity Framework or the ASD ISM, that work maps across rather than being duplicated.

5. Build governance and evidence

Roles, accountability and the records that make a reporting position defensible.

6. Report annually

Against the policy requirements, with the evidence to support the position taken.

How Soveriq helps

Soveriq assesses against the policy baseline using evidence rather than self-rating, covers the Further Five alongside the Essential Eight — which is the part most commonly missed — and maps existing NIST CSF or ISM work across instead of duplicating it.

For suppliers, we establish which obligations flow through your contract with a WA entity and build proportionate evidence.

We will also tell you plainly if Maturity Level One is not adequate for what you hold. A policy floor is not the same as an appropriate risk position, and treating it as one is how organisations end up compliant and breached.

On internal review. Where Soveriq has performed the uplift, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not approve reporting, does not speak for the Office of Digital Government, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the policy, including current Essential Eight and Further Five posture.
  • Module 02 — Build. Control implementation, governance and the evidence routines that support annual reporting.
  • Module 03 — Internal review ahead of reporting, subject to the impartiality position above.
  • Module 04 — Representation where an agency client engages directly.
  • Module 05 — Continuous compliance across the annual cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Is Maturity Level One really enough?

It is the policy baseline, not a ceiling. Whether it is enough depends on what the entity holds and what it is exposed to. An entity handling significant personal information with only Maturity Level One should be able to explain that decision, because the policy is risk-based and a baseline is a floor rather than an answer.

What are the Further Five?

Additional mitigation strategies beyond the eight, drawn from ASD's broader mitigation strategy guidance. WA's policy incorporates them alongside the Essential Eight, which is one of the ways it goes past a straight Essential Eight adoption.

How does the Essential Eight retirement affect this?

The policy references the Essential Eight, so as ASD moves to the Essentials series the WA policy will need to follow. Nothing changes immediately — the Essential Eight remains live — but entities should expect the reference to be updated in a future policy revision.

Does it apply to local government?

The policy is directed at WA public sector entities. Local government arrangements differ, and the practical answer for any specific body is in its own governing arrangements rather than the policy itself.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope