Australia IRAP and Essential Eight for Oracle Cloud Applications

November 22, 2023 |3 minutes read

Richard Wu
Senior Principal, Oracle SaaS Compliance

Oracle Cloud Applications have successfully completed the Information Security Registered Assessor Program (IRAP) assessment at the protected level in August 2023. This has been achieved along with the Essential Eight(E8) maturity, which demonstrates Oracle’s unwavering commitment to meeting the high standards of information security mandated by the Australian government.

The assessment was conducted by independent Australian Signals Directorate (ASD) certified IRAP assessors in alignment with the protected level of controls outlined in the Australian Government Information Security Manual (ISM). The list of in-scope services includes Oracle Fusion Applications Suite (HCM, SCM, ERP, Sales and Services), Oracle Enterprise Performance Management (EPM), Oracle B2C (Service Cloud) and Oracle Field Service (OFS).

The assessment report illustrates the effectiveness of the security controls that Oracle implemented. The consumer guidance provided in the report elucidate customers’ responsibilities to ensure that they use Oracle cloud services in accordance with the ASD/ACSC guidelines.

The Essential Eight maturity has been evaluated based on controls that are applicable to Oracle Cloud services. Customers are encouraged to leverage the report to ascertain their compliance responsibilities to this framework for utilizing Oracle cloud services. Moreover, we strongly recommend our customers to make reference to the “Essential Eight Explained” document published by ASD/ACSC for a comprehensive understanding of the applicability outlined in the report. It is worth noting that while the Essential Eight is “designed to protect organisations’ internet-connected information technology networks”, its complete applicability in specific cloud related scenarios may vary.

The continual achievement in IRAP and E8 framework aims at enhancing Oracle customers’ confidence and trust of using Oracle cloud services. The assessment report is available for customers to review and determine their compliance obligations within Australia IRAP and Essential Eight when utilizing Oracle cloud applications.

To access the Oracle Cloud Applications IRAP assessment report, customers are encouraged to reach out to their sales representatives and/or account managers. To learn more about Oracle Cloud compliance, please navigate to the compliance page on Oracle Cloud Compliance website.

sharon

Richard Wu

Senior Principal with over 15 years of experience in IT security compliance and audit. Richard manages Oracle Cloud compliance programs and initiatives for the Australia and New Zealand (ANZ) region, with extended support to the broader JAPAC (Japan and Asia-Pacific) region.