Assurance
Standards & credentials
In critical infrastructure, a standard is only useful if it changes a design decision. Below is what each one means in the work: not a list of acronyms, but where it shows up in the architecture.
Credentials held
-
Certified Information Systems Security Professional
-
ISA/IEC 62443 Cybersecurity Expert
-
Advanced in AI Security Management
-
The Open Group Architecture Framework
Industrial & operational technology
-
ISA/IEC 62443
The international series for industrial automation and control system security.
Zone and conduit design, security levels and Purdue model assessment for OT field networks, extended to AI/ML integration points, which are treated as new attack surfaces requiring explicit boundary controls.
-
NIST SP 800-82
NIST's guide to operational technology security.
Control tailoring for SCADA, EMS, DCS and AMI environments, where availability and determinism outrank confidentiality and a standard IT baseline would break the process it protects.
Energy sector & critical infrastructure
-
AESCSF
The Australian Energy Sector Cyber Security Framework.
Architecture decisions and control uplift aligned to AESCSF maturity requirements across energy market and grid operations systems.
-
SOCI Act
Security of Critical Infrastructure Act 2018 and its risk management program obligations.
Treated as a first-order design constraint for national critical infrastructure operators, alongside Black Start obligations and real-time availability requirements.
Australian Government
-
ISM
The Australian Government Information Security Manual.
Design authority across infrastructure and security domains aligned to ISM controls, with evidence pathways built for audit rather than assembled after it.
-
ASD Essential Eight
ASD's baseline mitigation strategies.
Compliance requirements carried across market systems and grid operations infrastructure, including OT-adjacent estates where standard implementations need adaptation.
-
IRAP
The Infosec Registered Assessors Program.
Alignment and audit survivability for regulated workloads across sovereign cloud and on-premises estates.
NIST
-
NIST CSF
The NIST Cybersecurity Framework.
Risk framing for executive and regulator-facing contexts, and a common language across IT, OT and cloud programmes.
-
NIST SP 800-53
NIST's catalogue of security and privacy controls.
Control baselines and traceability from architecture decisions through to implemented controls.
-
NIST SP 800-207
NIST's zero trust architecture reference.
Zero trust patterns applied across cloud, on-premises and OT/IT convergence boundaries, with explicit judgement about which principles survive contact with operational technology.
10 standards and frameworks, evidenced across the programme record.