DDG Consulting

Australian Defence & government ICT

Cloud and Kubernetes platforms built against the Information Security Manual.

DDG Consulting is an Australian security engineering practice. We design and harden cloud and Kubernetes infrastructure to ISM controls, and prepare the assessment material and documentation a system needs before it can be authorised to operate. We run the same patterns in production ourselves — every control we recommend is one we operate.

At a glance

Based
Australia. Australian owned and operated.
Focus
Platform engineering, security observability, and ISM assessment and authorisation.
Frameworks
ISM · PSPF · DSPF · Essential Eight · ISO/IEC 27001
Stack
Kubernetes · FluxCD · Splunk · OpenTelemetry · Terraform · Ansible
Engagement
Fixed-scope projects, or ongoing advisory.

Reference platform

Evidence, not assertions.

Our own production environment is a GitOps-managed Kubernetes cluster engineered to ISM PROTECTED control patterns. The audit and logging pipeline below is running today — each stage is mapped to the ISM control it satisfies, and each is available as a deliverable on client systems.

Audit & logging pipeline — production Ingesting
Collect

OpenTelemetry Collector

Node-level agents and a cluster receiver capture workload logs, node and pod metrics, Kubernetes events, and the full API server audit trail.

ISM-0580ISM-1405
Transport

TLS to Splunk HEC

Telemetry travels over HTTP Event Collector with TLS issued by an internal cert-manager CA. Certificate verification is enforced — no skipped checks.

ISM-1984
Index

Splunk Enterprise

Operator-managed Splunk with dedicated indexes separating application logs, metrics and API audit events. Seven-year audit retention with SHA-256 data-integrity hashing for tamper evidence.

ISM-0859ISM-1815ISM-0585
Tier

SmartStore to S3

Warm and cold index data is offloaded to S3-compatible object storage, keeping long retention affordable without shortening the audit trail.

ISM-0859
Separation of duties Auditor / analyst / admin roles, declared as code

Least-privilege Splunk roles scope each user to only the indexes their duty requires. The audit trail is readable by the auditor role and no one else.

Deletion protection Delete capability stripped from every named user

No day-to-day account can purge indexed events. Destructive capability sits behind a sealed breakglass account whose every use is itself logged.

Change management Every change is a signed git commit

FluxCD reconciles the cluster from a git repository. Secrets are SOPS-encrypted at rest in git; history doubles as the change record for assessment evidence.

Why it matters for authorisation. Assessors ask for evidence: where the logs go, who can touch them, how long they are kept, and how you would know if they were altered. A platform built this way answers those questions from configuration files rather than assurances — and the same pipeline, roles and retention policy can be stood up on your system as part of an engagement.

The ISM six-step process

Authorisation under the ISM follows a defined six-step lifecycle. The steps below set out which parts we can support and which part rests with your organisation.

01 Supported

Define the system

Establishing the system boundary, its classification, the data it handles and the environment it runs in.

02 Supported

Select controls

Identifying the ISM controls that apply at the target classification and determining how each relates to the architecture.

03 Supported

Implement controls

Building and configuring the platform so that the selected controls are in place, enforced and documented.

04 Preparation

Assess controls

Self-assessment against the selected controls, remediation of identified gaps, and assembly of the supporting evidence.

05 Not in scope

Authorise the system

The authorising officer reviews the assessment, accepts the residual risk and grants authority to operate. This decision rests with your organisation.

06 Supported

Monitor the system

Ongoing monitoring, detection of configuration drift, and the reporting required to keep an authorisation current.

On step four. Where an independent security assessment is required, it must be carried out by an ASD-endorsed IRAP assessor. DDG Consulting is not an endorsed assessor and does not perform IRAP assessments. Our work is preparatory: identifying and closing gaps, writing the documentation, and assembling the evidence so the system is in a defensible state before the formal assessment begins.

Services

Platform engineering and system authorisation

The two are closely related in practice. A platform designed without reference to the ISM generally needs rework before it can be authorised, and documentation written separately from the build often fails to describe the system as it was actually deployed. We take on both so that the build and the paperwork stay consistent with each other.

01 — Platform engineering

Cloud and Kubernetes platform engineering

Design, build and hardening of production infrastructure, with ISM controls applied during the build rather than added afterwards. Delivered as declarative, version-controlled configuration your team can operate.

  • GitOps delivery with FluxCD — the cluster reconciles from git, and git history becomes the auditable change record
  • Secrets encrypted in the repository with SOPS and age, decrypted only in-cluster at deploy time
  • Kubernetes hardening: RBAC, admission control, pod security standards and network policy, with policy-as-code enforcement via Kyverno
  • Certificate automation with cert-manager — public TLS via Let's Encrypt DNS-01 and an internal CA for service-to-service encryption
  • Bare-metal and edge patterns: K3s, MetalLB load balancing, ingress-nginx, automated DNS via external-dns
  • Identity-aware ingress: OAuth single sign-on enforced in front of web workloads via oauth2-proxy
  • Persistent storage with Longhorn distributed block storage and CSI volume snapshots
  • Backup and disaster recovery with VolSync and Kopia — scheduled, encrypted, deduplicated backups with tested restoration procedures
  • Node provisioning and SSH hardening automated with Ansible; AWS account structure, IAM and network segmentation through Terraform
  • Automated dependency currency via Renovate, so patching is a pull request rather than a project
02 — Authorisation

ISM assessment and authority to operate

Gap analysis, documentation and evidence for systems working towards authorisation at OFFICIAL, PROTECTED or above — grounded in operating these controls, not just writing about them.

  • Gap analysis against the current quarterly ISM release at the target classification
  • System Security Plan and the supporting control matrix, written from the system as deployed
  • Security Risk Management Plan, risk register and residual risk statements
  • Standard operating procedures — change management, incident response, patch management, backup and restore, access management, continuous monitoring, and logging and audit operations
  • Evidence libraries mapped control by control, drawn from live configuration rather than screenshots
  • Plan of Action and Milestones (POA&M) and remediation delivery where gaps are identified
  • Continuous monitoring and annual reporting to maintain an existing authorisation

Security observability with Splunk

Design and deployment of Splunk Enterprise on Kubernetes via the Splunk Operator, fed by OpenTelemetry collectors over TLS. Index separation for logs, metrics and audit events, long-term retention with integrity controls, SmartStore tiering to object storage, and role models that enforce separation of duties — plus the dashboards and review procedures to make the data usable.

DISP readiness and Essential Eight uplift

DISP membership is assessed across governance, personnel, physical and ICT security, with Essential Eight Maturity Level 2 generally expected in the cyber domain. We work on the ICT and cyber requirements, and can identify where gaps remain in the other domains.

IRAP pre-assessment

An assessment of the system against ISM controls ahead of a formal engagement, followed by remediation of what is found and preparation of the evidence an assessor will request.

Engagements

How engagements work

Scope and pricing

Each engagement begins with a scoping discussion, followed by a written statement of work covering the controls in scope, the deliverables, the timeline and the price. If the work turns out to be larger than anticipated, that is raised before it is undertaken.

Handover

Infrastructure is delivered as version-controlled code with written runbooks, and documentation is provided in a format your own team can maintain. The intention is that the work can be taken over internally once it is complete.

Specialist work

Some work sits outside what we do, including independent IRAP assessment, physical security and legal advice. Where that applies we will say so early, and can help you brief the relevant specialist.

Background

Experience behind the work

Certification
ISO/IEC 27001:2022 Lead Auditor, covering information security management system design, implementation and audit programme management in line with ISO/IEC 17021-1 and ISO 19011.
Sector
Delivery on regulated Australian Defence programs, including security hardening of delivered systems, security risk assessment and gap analysis, and handling of controlled technical data under Australian and United States export control obligations.
Platform and tooling
Kubernetes and K3s, FluxCD, Kyverno, Helm, Terraform, Ansible and AWX, AWS and EKS, Splunk Enterprise and the Splunk Operator for Kubernetes, OpenTelemetry, Prometheus, Grafana and Loki, Longhorn, VolSync and Kopia, SOPS, Linux, Python and Bash.
Security operations
Incident response, threat hunting and vulnerability assessment, including forensic review of compromised data following cyber security incidents. Design and operation of audit logging pipelines with long-term retention, integrity controls and separation-of-duties role models.

DDG Consulting is not an ASD-endorsed IRAP assessor and does not perform IRAP assessments. Authorisation decisions and the acceptance of residual risk rest with your organisation's authorising officer. The reference platform describes DDG's own environment; ISM control references indicate the controls the implementation addresses, not a formal assessment outcome. References to Defence programs describe professional experience only; no client, program or system is identified.

Contact

Enquiries

A short description of the system, its target classification and your timeframe is enough to begin. Initial discussions are at no cost, and we will say if the work is not a fit.