PSPF
Protective security as a baseline
The Protective Security Policy Framework sets how official information is handled and who is accountable for it. Delivery on the platform runs under your protective markings and records the controls that applied, so the baseline is evidenced rather than assumed.
ISM and Essential Eight
Controls assessed, not assumed
The Information Security Manual and the Essential Eight set the controls expected of government systems. Your security standards are written as rules the platform checks the work against, so the maturity you claim is the maturity that ran.
Hosting and data sovereignty
Onshore and Australian-controlled
Where data lives and who can reach it is a sovereignty question, not a hosting detail. Work runs in Australian-controlled environments with your data walled off from every other organisation, ready for IRAP-style assessment.
DSPF
Defence security principles
Defence industry work carries the obligations of the Defence Security Principles Framework. The same control problem holds: standards enforced as method, and a record you can produce. We frame it as that shared problem, not as defence experience we have not earned.