A plain guide to RFFR, ISO 27001, and cyber security for Australian service providers
Cyber security is not just an IT task. It is also a business duty. This is true for groups that deliver Australian Government programs. DEWR uses Right Fit For Risk (RFFR) to check that service providers keep data and systems safe.
RFFR is simple at its core. You must know your cyber risks. You must use controls that suit those risks. You must also show that the controls work. Your path will depend on your DEWR contract, services, systems, and risk level.
What is DEWR Right Fit For Risk?
RFFR is DEWR’s cyber security check for service providers. It also covers some outside IT systems. RFFR sits within the External Systems Assurance Framework, or ESAF. ESAF helps DEWR check data held outside its own systems.
RFFR is not one test or one checklist. It is an ongoing process. You may need an Information Security Management System, or ISMS. You may also need risk checks, security controls, proof, and regular reviews.
- Your team knows who owns each security task.
- You find and fix risks to people, systems, suppliers, and data.
- You use the right security controls.
- You manage security issues and system changes.
- You keep proof that your controls work.
Why service providers must prepare
RFFR may apply to service providers, some subcontractors, and some IT vendors. It can apply when a system links to DEWR. It can also apply when a system stores DEWR program data. Providers should make sure their rules, work steps, and security controls meet RFFR needs.
Not every provider has the same work to do. DEWR uses a risk-based approach. A low-risk provider may have fewer checks. A high-risk provider may need more proof. Each provider should confirm its category, tasks, dates, and contract terms with DEWR.
How does ISO 27001 help?
ISO/IEC 27001 is a global security standard. It helps you manage cyber risk. It also helps you set roles, write rules, check results, and improve over time.
RFFR and ISO 27001 are closely linked. But they are not the same. DEWR may ask for extra controls. These may come from the Australian Government security guide, known as the ISM. A basic ISO 27001 setup may not be enough.
Does every provider need ISO 27001 certification?
No. Some providers may use a self-assessment. Others may need an outside audit or ISO 27001 certificate. DEWR will set the level of proof. If you need a certificate, its scope must cover the right services, systems, data, and controls.
The scope is very important. A narrow certificate may not meet DEWR’s needs. Good planning can prevent extra work, delays, and audit issues.
What should you do now?
- Check your duties. Review your DEWR contract, category, and due dates.
- Name a leader. Give one person clear oversight of the work.
- Set the scope. List the people, sites, systems, suppliers, and data involved.
- Find the gaps. Compare your current setup with RFFR and ISO 27001.
- Collect proof. Keep records that show your controls work.
- Choose your path. Confirm if you need a self-check or an outside audit.
- Keep it current. Review risks, fixes, and changes each year.
Why choose Forde Consulting?
Forde Consulting helps with DEWR Right Fit For Risk and ISO 27001. We turn hard rules into clear tasks. We shape the work to suit your size, risks, systems, and contract.
- RFFR checks before you submit.
- ISO 27001 gap checks.
- ISMS setup and support.
- Scope and control lists.
- Risk checks and action plans.
- Policies, work steps, and audit proof.
- Internal audits and fix plans.
- Ongoing support for your team or MSP.
We do not give you generic templates. We explain what DEWR needs. We help you put useful controls in place. We also help you collect strong proof. This can reduce repeat work and make audits easier.
Make RFFR easier to manage
Do you deliver DEWR-funded services? Do you use an outside system for work or skills programs? If so, start early. Forde Consulting can check your current setup. We can find key gaps and build a clear plan. We can then help you get ready for RFFR or ISO 27001. Contact us to discuss the next step.