Skip to content
Amar JanduArchitecture

Assurance

Standards & credentials

In critical infrastructure, a standard is only useful if it changes a design decision. Below is what each one means in the work: not a list of acronyms, but where it shows up in the architecture.

Credentials held

  • CISSP

    Certified Information Systems Security Professional

    ISC²

  • ISA/IEC 62443

    ISA/IEC 62443 Cybersecurity Expert

    ISA

  • AAISM

    Advanced in AI Security Management

    ISACA

  • TOGAF

    The Open Group Architecture Framework

    The Open Group

Industrial & operational technology

  • ISA/IEC 62443

    The international series for industrial automation and control system security.

    Zone and conduit design, security levels and Purdue model assessment for OT field networks, extended to AI/ML integration points, which are treated as new attack surfaces requiring explicit boundary controls.

  • NIST SP 800-82

    NIST's guide to operational technology security.

    Control tailoring for SCADA, EMS, DCS and AMI environments, where availability and determinism outrank confidentiality and a standard IT baseline would break the process it protects.

Energy sector & critical infrastructure

  • AESCSF

    The Australian Energy Sector Cyber Security Framework.

    Architecture decisions and control uplift aligned to AESCSF maturity requirements across energy market and grid operations systems.

  • SOCI Act

    Security of Critical Infrastructure Act 2018 and its risk management program obligations.

    Treated as a first-order design constraint for national critical infrastructure operators, alongside Black Start obligations and real-time availability requirements.

Australian Government

  • ISM

    The Australian Government Information Security Manual.

    Design authority across infrastructure and security domains aligned to ISM controls, with evidence pathways built for audit rather than assembled after it.

  • ASD Essential Eight

    ASD's baseline mitigation strategies.

    Compliance requirements carried across market systems and grid operations infrastructure, including OT-adjacent estates where standard implementations need adaptation.

  • IRAP

    The Infosec Registered Assessors Program.

    Alignment and audit survivability for regulated workloads across sovereign cloud and on-premises estates.

NIST

  • NIST CSF

    The NIST Cybersecurity Framework.

    Risk framing for executive and regulator-facing contexts, and a common language across IT, OT and cloud programmes.

  • NIST SP 800-53

    NIST's catalogue of security and privacy controls.

    Control baselines and traceability from architecture decisions through to implemented controls.

  • NIST SP 800-207

    NIST's zero trust architecture reference.

    Zero trust patterns applied across cloud, on-premises and OT/IT convergence boundaries, with explicit judgement about which principles survive contact with operational technology.

10 standards and frameworks, evidenced across the programme record.

Selected programs → Contact & verification →