Australian Tax Office (ATO) Security Compliance - ISO/IEC 27001/27002/NIST Assessment - 03/05/2025 22:00 EDT

Job ID: 39372164

Budget: $250 – $750 AUD

Project Brief: DSP Security Compliance Support for ATO Self-Assessment
Project Name:
Digital Service Provider (DSP) Security Compliance Support Project (ISO/NIST-Based)
Support for ATO Self-Assessment and Documentation Preparation
Background:
We are Aupod, a SaaS platform providing tax services for individuals and small businesses in Australia. We are currently integrating with the ATO’s SBR systems (e.g., IITR 2025). As part of the ATO’s Digital Service Provider (DSP) Operational Security Framework, we are required to complete a security self-assessment and provide supporting documentation.

ATO accepts alignment with one of the following standards (without requiring formal certification):
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- NIST Cybersecurity Framework
Objectives:
- Complete the ATO DSP Operational Security Framework (Class B controls) self-assessment aligned with one of the accepted standards
- Prepare required supporting documentation (e.g., policy documents, architecture diagrams, configuration screenshots)
- Ensure the AWS-based deployment is compliant with ATO’s requirements
Tasks:
1. Security Controls Implementation and Mapping
• - Review all requirements under the ATO DSP Operational Security Framework
- Map our current architecture and practices against ISO 27001/27002 or NIST standards
- Provide gap analysis and improvement recommendations
2. Documentation and Evidence Preparation
• - Assist in preparing the following (in English):
• System Architecture Diagram
• Data Encryption Description (e.g., AWS KMS)
• Identity & Access Management (IAM/MFA) Policies
• Data Access Control Documents
• Audit & Logging Strategies (e.g., AWS CloudTrail)
• Incident Response Policy
• Role-based Responsibility Definitions (Data Collector / Validator / Provider / Transmitter)
3. ATO DSP Self-Assessment Questionnaire Support
• - Provide guidance for understanding and completing the ATO DSP Self-Assessment form (DOC format)
- Suggest responses to each question and help compile necessary evidence
Consultant Requirements:
- Familiar with at least one of the following frameworks: ISO/IEC 27001:2022, ISO/IEC 27002:2022, or NIST (formal certification not required)
- Experience with ATO Digital Service Provider compliance is a plus
- Strong familiarity with AWS security practices (IAM, KMS, CloudTrail, WAF, VPC, etc.)
- Proven experience in writing and organizing security compliance documentation