RFFR stands for Right Fit for Risk. RFFR was designed by the Department of Education, Skills and Employment (DESE) in late 2019. The initiative is a scheme targeted towards providers of contracted private employment services, who DESE engages with to assist job seekers for preparing and securing jobs. This scheme aims to ensure government owned data (including personal records of participants and other information) is safely held on the provider’s IT systems.
Under the Protective Security Policy Framework (PSPF) all Australian government departments are responsible for the protection of data entrusted to them. The department is accountable for ensuring that the contracted employment service providers used in the delivering of employment programs also comply with PSPF requirements.
The Right Fit for Risk requirements are based on the ISO 27001 standard as it is adaptable and well suited to small and medium sized organisations.
Historically, to gain certification as a preferred employment service provider to work with DESE, companies had to be IRAP assessed which was managed under the Pathway approach.
The experience using the Pathway approach indicated it was adversely impacted by:
So, with the birth of RFFR, it should reduce complexity and align with the level of risk for providers. It is more adaptable and better suited to the varying sizes of providers.
ESAF is the method DESE uses to gain assurance over provider’s IT systems. The ESAF was created to provide assurance for the department that the risk to their systems and confidential data stored outside of the department’s ICT environment is being managed responsibility.
Assurance areas:
At Sekuro, our trained Security Consultants will assist you in every step of the process, setting up your compliance framework, developing your SoA, assessing your information security risks, and guiding you through the implementation of the controls, by hosting workshops and transferring knowledge to your key stakeholders.
Our methodology includes identifying the strengths and weaknesses in your information security implementation and mapping them to your RFFR ISMS goals and compliance requirements.
Sekuro’s auditors will examine your systems and supporting documentation to ensure your organisation’s RFFR ISMS is compliant with ISO 27001.
Once the implementation requirements are met, your organisation can be certified via accredited external certification bodies.