Skip to main content

RFFR

What is RFFR?

Right Fit For Risk

The accreditation approach used by Services Australia for providers that handle its data. It asks a provider to run an information security management system aligned to ISO/IEC 27001 and to the ASD Information Security Manual, scaled to the risk the provider carries.

What it asks for

An information security management system aligned to ISO/IEC 27001 and to the ASD Information Security Manual, scaled to the risk the provider carries rather than applied uniformly.

The "right fit" framing is deliberate: a small provider handling limited data is not expected to meet the same control depth as one handling sensitive records at scale.

Who encounters it

Providers delivering services to Services Australia, and their subcontractors. It is frequently the first formal accreditation regime a supplier meets, and the certification and evidence expectations are commonly underestimated.

See also

Search all glossary terms

O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.