→ Back to Home
AWS Security

AWS Strengthens Australian Government Cloud Security with Expanded IRAP Certification

Amazon Web Services (AWS) has announced the release of its latest Information Security Registered Assessors Program (IRAP) report, a Phase 1a full assessment, now accessible via AWS Artifact. This updated report, completed in June 2026 by an independent Australian Signals Directorate (ASD) certified IRAP assessor, significantly expands the scope of AWS services deemed compliant for handling Australian government data up to the PROTECTED classification level. Notably, four new services—Amazon Bedrock AgentCore, AWS Parallel Computing Service, AWS Resilience Hub, and AWS Security Incident Response—have been added, bringing the total number of PROTECTED-level assessed services to 167. This development is crucial for Australian government entities and their technology partners. It directly addresses the persistent challenge of demonstrating compliance with rigorous national security frameworks like the Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF). By expanding the range of services assessed at the PROTECTED level, AWS is enabling these organizations to migrate or build more complex and sensitive workloads in the cloud without incurring prohibitive assessment overheads. The inclusion of services like Amazon Bedrock AgentCore is particularly impactful, signaling AWS's commitment to supporting secure AI/ML initiatives within regulated environments, a growing area of concern for national security. This release fits squarely within the broader trend of major cloud providers continuously investing in hyper-localized compliance and governance offerings. As cloud adoption matures globally, governments and highly regulated industries demand assurances that cloud infrastructure meets their specific sovereign and industry-specific security requirements. AWS's ongoing IRAP assessments, alongside similar efforts for other regions and sectors (e.g., FedRAMP in the US, GDPR in Europe), underscore the shared responsibility model where the cloud provider handles the security *of* the cloud, while customers manage security *in* the cloud. This continuous expansion of certified services reduces the customer's burden of proof for the underlying infrastructure, allowing them to focus their resources on securing their applications and data. In practice, Australian government architects, security engineers, and compliance officers should immediately leverage the newly available IRAP report and accompanying documentation pack on AWS Artifact. This pack, developed in accordance with ACSC Cloud Security Guidance, includes updated versions of the AWS Consumer Guide and the "Reference Architectures for ISM PROTECTED Workloads in the AWS Cloud." These resources provide invaluable guidance for designing, implementing, and assessing secure cloud environments. Practitioners should review the newly added services to identify opportunities for modernizing existing workloads or launching new initiatives that previously faced compliance hurdles. Furthermore, understanding the updated guidance will help streamline internal audits and external assessments, ultimately accelerating the secure adoption of advanced AWS capabilities for critical government functions.
#compliance#security#aws#australia#government#irap#protected#artifact
Read original source