Course Content
Understanding the Defence Industry Security Programming (DISP)
This topic explains the Defence Industry Security Program (DISP). Explains what DISP does for the industry and which entities may apply for DISP membership.
0/4
Conduct An Initial Review of a Cyber Security Questionnaire (CSQ)
During this topic you will be taught about the Cyber Security Questionnaire, and how to conduct an initial review of a submitted questionnaire.
0/4
Conduct A Quality Assurance (QA) Check of an Initial Assessment (IA)
During this topic you'll be taught how to carry out a Quality Assurance (QA) Check of an Initial Assessment (IA).
0/6
Entry Level Assessors Course
Please login for access. Login
About Lesson

In some circumstances, an entity may submit an action plan that is entirely unsuitable or lacks contextual information. It is important to ensure that the entity’s responses are verbose enough to make an informed decision regarding other cyber security hygiene.

No Response(s)

If an entity returns an action plan for which they’ve not provided a response for one or all recommendations, the submission may be rejected and the entity advised to resubmit.

Insufficient Information

If an entity returns an action plan for which they’ve not provided enough information, you may request that the entity provide further information.

Example: “We intend to use M365 to address application patching”

Why: “The intent to use M365 to address the control is insufficient. The entity must explain how they’re going to utilise M365.

Acceptable Example: “We intend to use Microsoft Endpoint Manager, through M365, to enforce application patching on all endpoints that are used to correspond with defence.”

Join the conversation