Quest Assessed to PROTECTED Under IRAP

An agency evaluating an unassessed vendor platform typically runs its own security assessment before procurement can proceed. That process can take most of a year and cost six figures. Quest Software has achieved IRAP assessed status for two platforms, removing that step for Australian government buyers.

The assessment covers the Quest Trusted Data Management Platform and the Quest Security Management Platform. Both were assessed for PROTECTED workloads, covering the Official and PROTECTED classification levels required by the large majority of Commonwealth agencies.

The Infosec Registered Assessors Program is Australia's independent third-party assessment process. It evaluates a technology platform against the Australian Government's Information Security Manual, maintained by the Australian Signals Directorate.

Richard Kulkarni is head of APAC at Quest Software. He said many large Australian agencies already run Quest technology on-premises for Active Directory security monitoring, change auditing, recovery and governance.

"This IRAP assessed status doesn't introduce Quest to government, rather it extends a relationship that already exists into hybrid and cloud-first territory, with independent assurance attached," Mr Kulkarni said.

He described the environment agencies are working in. "The modernisation that agencies are embarking on rarely looks like a single clean lift-and-shift," Mr Kulkarni said. "It looks like Active Directory and Entra ID modernisation running alongside Machinery of Government changes, cybersecurity uplift programs, and legacy platform retirement, often at the same time."

What IRAP assessment means

IRAP assessed status means an independent assessor has evaluated the platforms against the Information Security Manual. It does not remove an agency's obligation to make its own risk decision, but it removes the evaluation work that would otherwise precede it.

Quest says the assessment covers the complete product in each case. That makes both platforms easier to evaluate, easier to procure, and easier for partners to include in high-assurance bids.

The company notes that identity remains one of the most targeted surfaces in government networks. Privileged access oversight now extends to non-human identities, a distinction that grows as agencies deploy automation and AI agents.

The Security Management Platform handles monitoring, auditing, recovery and privileged access oversight underpinning Essential Eight alignment and Zero Trust posture. Identity threat detection and response capabilities aim to contain compromised accounts before they spread across a hybrid directory estate. Automated recovery restores operations after an incident. Privileged access oversight extends to non-human identities.

The Trusted Data Management Platform covers discovery, governance, modelling and cataloguing. Its Automated Data Product Factory converts raw, siloed datasets into governed, reusable data products, with lineage, ownership and trust scoring built in. Quest says this takes days rather than months. The company positions this as giving data stewards a single auditable record of how a data product was built and who approved it for use.

The company positions governed data as a prerequisite rather than a follow-up task. As agencies stand up AI and analytics use cases on modernised infrastructure, Quest argues, governed data determines whether those use cases can be trusted.

www.quest.com