
Defence Industry Security Program (DISP)
What is DISP?
The Defence Industry Security Program (DISP) is an Australian Government initiative designed to help industry partners meet Defence’s security requirements when delivering contracts or services involving sensitive or classified information, assets, or personnel. Administered by the Department of Defence under Control 16.1 of the Defence Security Principles Framework (DSPF), DISP ensures that Australian businesses can work securely and responsibly with Defence.
DISP members are assessed against protective security standards and are supported by Defence to develop appropriate policies, procedures, and capabilities in the areas of:
Governance • Personnel security • Physical security • Information Security
More Information: Membership Program Brochure (PDF, 482.56kb)
A Brief History of DISP
DISP was formalised to provide a structured, consistent approach to managing security risks across the Defence supply chain. It aligns with the Protective Security Policy Framework (PSPF) and reflects Defence’s growing need to partner with private industry while safeguarding national security.
Created to meet internal Defence needs, DISP was expanded to industry as Australia’s defence procurement programs and technology partnerships became more integrated with commercial entities. This expansion recognised that effective national security depends on the resilience of its entire ecosystem.
Why DISP Matters
To the Australian Government
DISP ensures the Government can confidently engage with external partners without compromising Defence missions or national interests, and is critical to:
-
Protecting classified information and Defence capability from espionage, cyber threats, and insider risks.
-
Ensuring that contractors and suppliers uphold security standards equivalent to Defence’s own.
-
Supporting Australia’s obligations under international defence and security partnerships.
-
Maintaining a secure, trusted and sovereign supply chain.
To Australian Organisations
DISP is essential for any business looking to work within the classified or secure Defence sector, especially as major Defence programs increasingly require DISP membership as a condition of engagement. It provides a clear, supported pathway for businesses to engage in classified or sensitive Defence work.
Our DISP Services
Sypha Security supports Australian organisations seeking to apply for DISP grants, implement the required governance frameworks and architect the technology ecosystem to achieve entry-level DISP membership.
1. DISP Readiness Assessment
We assess your business against the DISP requirements and provide:
-
A tailored gap analysis against the ASD Essential Eight or NIST SP 800-171
-
Develop a roadmap to achieve entry-level membership
-
Strategic alignment with the business strategy
2. DISP Implementation & Accreditation
We work with you to:
-
Develop compliant governance and risk frameworks
-
Implement personnel vetting and HR protocols
-
Design physical security measures
-
Strengthen your ICT and cybersecurity posture, aligned with the ASD Essential Eight or NIST SP 800-171
3. DISP Grant Application Support
Eligible organisations may access $10,000–$100,000 in government funding through the Defence Industry Development Grant – Security Stream. We offer:
-
End-to-end grant application assistance
-
Project planning and risk documentation
-
Budget preparation using official templates
-
Integration of DISP Maturity Action Plans or Audit Reports
4. Ongoing DISP Support
Post-membership, we provide:
-
Continuous compliance monitoring
-
Chief Security Officer (CSO) / Security Officer (SO) outsourcing service
-
CSO / SO mentoring, support or outsourced vCSO service
-
Support for DISP annual security reports, audits and recertification
Many organisations are not sufficiently resourced to undertake such a task.
Sypha Security has worked with many organisations to assist them with developing and implementing their cybersecurity strategy, PDSP and submitting their annual attestations.
All our consultants come from an IT technical background, have 20 years of experience in cybersecurity and have worked in many cybersecurity leadership positions across many public and private sectors.