Queensland IS18 Assurance

Assurance Bureau delivers independent IS18 assurance audits and readiness support for Queensland government departments, statutory bodies, and other entities reporting under the Queensland Government Enterprise Architecture (QGEA). Whether the driver is the annual return, the accountable officer's attestation, audit and risk committee assurance, or preparation ahead of your next assessment, our work gives you a defensible, evidence-based picture of your ISMS and Essential Eight posture.

Assurance Bureau is led by a Principal Consultant who audits ISO/IEC 27001 on behalf of JAS-ANZ accredited certification bodies, assesses Essential Eight maturity against ACSC criteria, and is an ASD-endorsed IRAP Assessor. IS18 is built on exactly these elements, so your assurance is run with the same discipline certification bodies rely on. Our team has assessed Queensland public sector entities against IS18 and the supporting QGEA reporting templates.

What is IS18?

The Information and cyber security policy (IS18) is the QGEA policy that sets minimum information and cyber security requirements for Queensland Government agencies. The current version (v9.0.0, February 2025) requires agencies to:

  • Implement and operate an ISMS based on the current version of ISO/IEC 27001, covering services, information, application, and technology assets

  • Integrate information security risk into corporate governance and risk frameworks

  • Meet minimum security requirements, including implementing the ASD Essential Eight at target maturity levels selected on risk

  • Obtain security assurance for systems proportionate to their criticality, and run cyber incident simulations at least annually

  • Attest each year to the appropriateness of agency information security

For each financial year ending 30 June, the accountable officer endorses an information security annual return through the corporate audit and risk committee and submits it to the Cyber Security Unit by 30 September. The attestation is published in the agency's annual report and must cover the ISMS and acknowledge any approved maturity uplift plan.

Departments under the Public Sector Act 2022 must comply. Statutory bodies must have regard to the policy, and other entities, including local governments, are encouraged to apply it as better practice.

Why agencies seek independent IS18 assurance

The attestation carries the accountable officer's name, and audit and risk committees increasingly want independent evidence behind the endorsement rather than self-assessment alone. IS18 itself requires security assurance proportionate to system criticality, and independent assessment is the usual way that assurance is obtained for higher-criticality systems. An external assessment also gives your security team a graded, prioritised view of gaps before they surface in the return.

What we assess

  • The ISMS against IS18 policy requirements and ISO/IEC 27001

  • Essential Eight maturity against ACSC maturity level criteria, including the statements made in the annual return

  • Policies, procedures, and supporting control evidence, tested rather than accepted on policy statements alone

  • Findings reported by requirement and control domain, graded so remediation can be prioritised

  • Reporting aligned to QGEA templates and the annual return cycle

How an engagement works

Scope. We agree the entities and systems in scope, your Essential Eight target maturity levels, and the reporting your audit and risk committee needs.

Assess. We review documentation, configuration, and evidence across the IS18 requirements, validating that controls are implemented and operating rather than simply documented.

Report. You receive an assessment report stating your position against each requirement, Essential Eight maturity per strategy, and a remediation plan prioritised by risk and effort, ready to support the annual return and attestation.

Support. We remain available to clarify findings and guide remediation, so the report drives action rather than sitting on a shelf.

IS18 readiness and uplift

For agencies not yet ready for an assurance activity, we offer advisory support delivered separately from assessment work: gap analysis against IS18 requirements, ISMS design or uplift aligned to ISO/IEC 27001, risk management integration with corporate risk processes, and preparation for the annual return. Advisory and assurance services are scoped separately, and where we have provided advisory support, independence will be considered before any assurance engagement.

Important to understand

An IS18 assurance audit is an independent, point-in-time assessment. It is not a certification, and IS18 does not require your ISMS to be certified to ISO 27001. The attestation and any authorisation decisions remain the responsibility of your accountable officer. Our report is the evidence base that lets those decisions be made, and defended, with confidence.

Why Assurance Bureau

  • ISO/IEC 27001 Lead Auditor, auditing on behalf of JAS-ANZ accredited certification bodies, so the ISMS at the core of IS18 is assessed with certification-audit discipline

  • Essential Eight assessment experience against ACSC maturity criteria

  • ASD-endorsed IRAP Assessor with an active Australian Government NV1 security clearance

  • Experience assessing Queensland public sector entities against IS18 and QGEA reporting templates

  • Independent and vendor neutral, with no products to sell and no remediation agenda

  • Based in Brisbane, working with agencies across Queensland

Frequently asked questions

Does IS18 require ISO 27001 certification? No. IS18 requires an ISMS based on the current version of ISO 27001, not a certificate. Some agencies pursue certification for the discipline and external validation it brings, and we can advise on whether that is worth it for you.

How does the Essential Eight fit into IS18? Agencies must implement the Essential Eight at target maturity levels selected on risk, and maturity statements form part of the annual return. We assess maturity against the ACSC criteria as part of the engagement or as a standalone assessment.

When should we book an assessment? The annual return is due 30 September each year. Fieldwork takes several weeks and remediation takes longer, so agencies that assess in the first half of the calendar year get the most value from the findings.

Is the assessment remote or onsite? Most assessments are conducted remotely. For agencies in Brisbane and across South East Queensland, onsite work can be arranged where it adds value.

Can you help us fix what you find? We can provide readiness and uplift support, delivered separately from assurance work so independence is preserved. Where you want the same party to do neither, we can refer remediation to others.

Get in touch