RFFR
What is RFFR?
Right Fit For Risk
The accreditation approach used by Services Australia for providers that handle its data. It asks a provider to run an information security management system aligned to ISO/IEC 27001 and to the ASD Information Security Manual, scaled to the risk the provider carries.
What it asks for
An information security management system aligned to ISO/IEC 27001 and to the ASD Information Security Manual, scaled to the risk the provider carries rather than applied uniformly.
The "right fit" framing is deliberate: a small provider handling limited data is not expected to meet the same control depth as one handling sensitive records at scale.
Who encounters it
Providers delivering services to Services Australia, and their subcontractors. It is frequently the first formal accreditation regime a supplier meets, and the certification and evidence expectations are commonly underestimated.
See also
- E8 Essential Eight Eight mitigation strategies published by the Australian Signals Directorate: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.