Essential Eight, ISM, PSPF and NZISM Training

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our Essential Eight training, together with courses on the Information Security Manual (ISM), PSPF, APRA CPS 234 and CPS 230, the NZISM and the Protective Security Requirements, helps Australian and New Zealand organisations meet the cyber security frameworks their regulators and customers expect. SSC delivers these courses live online or on-site for government agencies, regulated entities and their suppliers.

Training session in an office overlooking a harbour city with a steel arch bridge at golden hour, representing cyber security compliance training in Australia
Australian and New Zealand frameworks share goals but differ in detail, and training should reflect that.

Courses at a glance

CourseTypical durationBest for
Essential Eight practitioner2 daysIT and security teams implementing or assessing the Essential Eight
ISM and IRAP readiness2 daysCloud and service providers, and agencies authorising systems
PSPF for security advisers1 dayCommonwealth entity security teams and contractors
APRA CPS 234 and CPS 2301 dayBanks, insurers and superannuation trustees, and their providers
NZISM and Protective Security Requirements2 daysNew Zealand agencies and their suppliers
Privacy Act and data breach response1 dayPrivacy, legal, security and communications teams in Australia or New Zealand
Board cyber security briefing2 to 3 hoursDirectors and executive teams

Essential Eight training

Laptop showing a circular gauge with eight glowing segments, representing Essential Eight maturity training
Each of the eight strategies is assessed separately, so maturity is only as strong as the weakest one.

The Essential Eight, published by the Australian Signals Directorate (ASD), is a set of eight mitigation strategies measured against a maturity model from level zero to level three: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Our practitioner course explains what each maturity level requires, how to test it, which evidence assessors expect, and how to plan uplift with limited budgets.

Australian Government and regulated sector courses

  • ISM and IRAP readiness: the structure of the ASD Information Security Manual, how it is updated, and how to prepare a system for an assessment by an ASD-endorsed IRAP assessor, including cloud services.
  • PSPF: the Protective Security Policy Framework administered by the Department of Home Affairs, including the current release, security governance, risk, information, technology, personnel and physical security, and annual reporting.
  • APRA CPS 234 and CPS 230: information security capability, control testing and the 72-hour incident notification under CPS 234, and critical operations, tolerance levels, material service providers and business continuity under CPS 230.
  • Privacy and breach response: the Notifiable Data Breaches scheme under Australia’s Privacy Act 1988, notifiable privacy breaches under New Zealand’s Privacy Act 2020, and running a breach assessment under time pressure.

New Zealand: NZISM and the Protective Security Requirements

Workshop in a timber-lined office with a view of green hills and a harbour, representing NZISM and PSR training in New Zealand
New Zealand agencies pass PSR and NZISM expectations on to the suppliers they rely on.

The New Zealand Information Security Manual (NZISM), published by the National Cyber Security Centre within the GCSB, sets the technical security baseline for government systems. The Protective Security Requirements (PSR) set the government’s expectations for security governance, personnel, information and physical security, with annual assurance reporting. Our course covers both, plus the Minimum Cyber Security Standards for agencies, and shows suppliers how to evidence alignment in tenders and contracts. Read more about ISO 27001 certification in New Zealand and cyber security for small business in New Zealand.

How the Australian and New Zealand framework training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who assess clients against the Essential Eight, the ISM, the PSPF, APRA standards and the NZISM, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Related: cyber security maturity assessment, Essential Eight compliance assessment, and the GRCLens Australia and New Zealand framework packs. See all training courses.

Frequently asked questions

The eight ASD mitigation strategies, what each maturity level from zero to three requires, how to test and evidence them, and how to plan uplift. It suits teams implementing the controls and those assessing them.

It is mandatory for non-corporate Commonwealth entities through the PSPF, which sets an expected maturity level, and it is widely required of suppliers and recommended for all Australian organisations.

Yes. The ISM and IRAP readiness course prepares your team for an assessment by an ASD-endorsed IRAP assessor. SSC trains and prepares; the assessment itself is performed by an endorsed assessor.

Yes. The APRA course covers CPS 234 information security and CPS 230 operational risk management, including critical operations, tolerance levels and material service providers.

Yes. The NZISM and PSR course covers the New Zealand Information Security Manual, the Protective Security Requirements and the Minimum Cyber Security Standards.

Plan Australian and New Zealand framework training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com